SC-200 Manage a security operations environment Practice Question
Your organization uses Microsoft Defender for Cloud with enhanced security features enabled. You need to ensure that all Azure subscriptions are covered by a single Defender for Cloud policy that enforces specific security standards. The policy must be automatically applied to new subscriptions. What should you do?
⚠ Common exam trap
Test-takers frequently think enabling the default Defender for Cloud policy (Option A) is sufficient for all subscriptions, but that only applies to the current subscription and does not enforce a custom standard or automatically cover new subscriptions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a custom policy initiative and assign it to the root management group.
Assigning a custom policy initiative to the root management group ensures that the policy is inherited by all subscriptions under that management group, including new subscriptions as they are added. This approach enforces consistent security standards across the entire Azure environment without requiring manual intervention for each subscription.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable the default Defender for Cloud policy from the Azure portal.
Why it's wrong here
The default Defender for Cloud policy is the built-in Microsoft cloud security benchmark initiative. It is assess-only in the portal and exclusively produces compliance results for Microsoft-defined controls, so it cannot represent or enforce your organization's custom regulatory requirements. Enabling it merely turns on evaluation against that fixed baseline, not against a custom standard.
- ✗
Manually assign the policy to each subscription using PowerShell.
Why it's wrong here
Using PowerShell to assign the same custom initiative individually to each subscription at the subscription scope is operationally brittle and does not scale. Azure Policy assignments are not inherited across sibling or future subscriptions, so every new subscription remains out of scope until an administrator manually assigns it again. This creates drift, inconsistent enforcement, and a high ongoing maintenance burden.
- ✓
Create a custom policy initiative and assign it to the root management group.
Why this is correct
Create a custom policy initiative—a group of custom policy definitions that expresses your organization's security requirements—and assign it at the root management group scope. Management-group assignments are inherited by every descendant management group and subscription, including subscriptions created later, giving tenant-wide enforcement from a single assignment. Defender for Cloud's regulatory compliance feature recognizes this custom initiative as a compliance standard and displays its results in the dashboard.
- ✗
Configure the security contact email for each subscription.
Why it's wrong here
Configuring a security contact email for each subscription only tells Defender for Cloud where to send alert notifications and the periodic email digest. It does not deploy, evaluate, or enforce any policy initiative, and it cannot affect the compliance posture of your resources. Even if set for every subscription, security contact settings never cause custom requirements to be assessed.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.