Courseiva

SC-200 Manage a security operations environment Practice Question

Your organization uses Microsoft Defender for Cloud to manage security posture. You need to assign a custom initiative to a specific management group to track compliance. Which two components must you create?

⚠ Common exam trap

Many candidates confuse Azure Blueprints (which also group resources) with policy initiatives, or they think a Log Analytics workspace is required to store compliance data, when in fact compliance data is stored and reported by Defender for Cloud itself without needing a separate workspace.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A policy definition and an initiative definition.

To track compliance for a custom initiative in Microsoft Defender for Cloud, you must first create a custom policy definition that specifies the rules or effects to enforce. Then, you must create an initiative definition (a group of policy definitions) that can be assigned to a management group. This assignment enables Defender for Cloud to evaluate resources against the custom initiative and report compliance.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    An Azure Blueprint and a role assignment.

    Why it's wrong here

    Azure Blueprints are deprecated in favor of deployment stacks, so they cannot be used to create a custom policy initiative. A custom initiative is a collection of policy definitions grouped at the Azure Policy layer, not a package of ARM templates and role assignments. Role assignments govern who can access resources but are not part of the initiative's JSON structure, making them unnecessary for defining an initiative. Thus, blueprints and role assignments are not the required components.

  • ✓

    A policy definition and an initiative definition.

    Why this is correct

    A custom policy initiative requires at least one policy definition and an initiative definition that references those policies. The initiative definition is a JSON document containing metadata, parameters, and an array of policy definition IDs, all grouped for a shared compliance goal. Without both elements, there is no logical grouping to assign or evaluate in Azure Policy. Therefore, this pair is the minimal and correct set of components needed to create a custom initiative.

  • ✗

    An Azure RBAC role and a Log Analytics workspace.

    Why it's wrong here

    An Azure RBAC role and a Log Analytics workspace relate to access control and data collection, respectively, not to compliance policy grouping. RBAC roles determine who can manage Azure resources, while a Log Analytics workspace stores logs and metrics; neither appears in a policy initiative's definition structure. You could assign an initiative that requires a workspace, but that would be a policy effect, not a prerequisite for building the initiative. Consequently, these are not needed to define a custom initiative.

  • ✗

    An Azure Monitor workbook and an alert rule.

    Why it's wrong here

    Azure Monitor workbooks provide interactive dashboards, and alert rules trigger notifications based on logs or metrics—these serve operational monitoring, not policy definition. A custom initiative's structure is purely policy-centric; workbooks and alerts cannot replace the policy definitions and initiative definition that encode compliance logic. While you could later build a workbook to visualize compliance results, it is an observability tool, not part of initiative creation. Hence, this pairing is incorrect for defining a custom policy initiative.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.