SC-900 Practice Question: Describe the concepts of security, compliance, and identity
A company uses Microsoft Defender for Cloud to secure its hybrid cloud environment. They need to continuously assess compliance with regulatory standards like ISO 27001 and receive recommendations for remediation. Which feature should they enable?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Defender for Cloud’s regulatory compliance dashboard
Microsoft Defender for Cloud's regulatory compliance dashboard provides continuous assessments against standards like ISO 27001 and offers recommendations. Secure Score is a security posture metric. Defender plans are for workload protection. Workload protections are specific to resources.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Defender for Cloud’s regulatory compliance dashboard
Why this is correct
Microsoft Defender for Cloud's regulatory compliance dashboard is specifically designed to help organizations meet various industry and regulatory standards. It continuously assesses the compliance posture of resources against built-in and custom compliance standards, such as Azure Security Benchmark, PCI DSS, ISO 27001, and HIPAA. The dashboard provides a centralized view of compliance status, offering actionable recommendations and remediation steps to address non-compliant controls and improve overall adherence to regulatory requirements. This direct alignment with compliance frameworks makes it the ideal tool for assessing regulatory posture.
- ✗
Microsoft Defender for Cloud Apps
Why it's wrong here
Microsoft Defender for Cloud Apps (MDCA) functions as a Cloud Access Security Broker (CASB), primarily focused on providing deep visibility, data travel control, and sophisticated threat protection across cloud applications. While it helps secure data and user activity within SaaS applications, its core purpose is not to directly assess an organization's adherence to specific regulatory compliance standards like PCI DSS or ISO 27001. Instead, it provides granular control and monitoring over cloud app usage, which can contribute to compliance but doesn't perform the assessment itself.
- ✗
Microsoft Defender for Identity
Why it's wrong here
Microsoft Defender for Identity (MDI) is a cloud-based security solution that leverages on-premises Active Directory signals to identify, detect, and investigate advanced threats, compromised identities, and malicious insider actions. Its primary role is to protect hybrid identity environments by monitoring user behavior and detecting anomalies indicative of attacks like pass-the-hash or Golden Ticket. While crucial for identity security, MDI does not offer capabilities for assessing an organization's overall regulatory compliance posture against standards like HIPAA or GDPR.
- ✗
Defender for Cloud’s Secure Score
Why it's wrong here
Microsoft Defender for Cloud's Secure Score is a dynamic measurement of an organization's security posture, providing a numerical representation of how well security controls are implemented. It aggregates security recommendations into a single score, helping prioritize actions to improve overall security. While a high Secure Score indicates strong security practices, it does not directly map to specific regulatory compliance standards or provide a dashboard for tracking adherence to frameworks like ISO 27001 or PCI DSS. Its focus is on general security hardening, not formal compliance assessment.
Go deeper
Related to this question
Learn chapter
Core Security Concepts
Key term
Microsoft Defender
Microsoft Defender is a suite of security products that protects devices, data, and identities from cyber threats like malware, phishing, and unauthorized access.
Key term
ISO 27001
ISO 27001 is an international standard that specifies the requirements for establishing, implementing, maintaining, and continually improving an information security management system (ISMS).
About these practice questions
This SC-900 question is part of Courseiva's 1,250-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.