SC-900 Practice Question: Describe the concepts of security, compliance, and identity
A company uses Microsoft Defender for Cloud to secure its hybrid cloud environment. They need to continuously assess compliance with regulatory standards like ISO 27001 and receive recommendations for remediation. Which feature should they enable?
⚠ Common exam trap
SC-900 often tests confusion between Secure Score (overall posture metric) and the regulatory compliance dashboard (standards-specific assessment) — candidates pick Secure Score thinking it covers compliance.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Defender for Cloud’s regulatory compliance dashboard
Microsoft Defender for Cloud's regulatory compliance dashboard continuously assesses resources against built-in or custom standards such as ISO 27001, PCI DSS, and NIST, showing compliance posture and providing remediation recommendations. This directly matches the requirement to assess compliance with regulatory standards and receive remediation guidance.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Defender for Cloud’s regulatory compliance dashboard
Why this is correct
Microsoft Defender for Cloud's regulatory compliance dashboard is specifically designed to help organizations meet various industry and regulatory standards. It continuously assesses the compliance posture of resources against built-in and custom compliance standards, such as Azure Security Benchmark, PCI DSS, ISO 27001, and HIPAA. The dashboard provides a centralized view of compliance status, offering actionable recommendations and remediation steps to address non-compliant controls and improve overall adherence to regulatory requirements. This direct alignment with compliance frameworks makes it the ideal tool for assessing regulatory posture.
- ✗
Microsoft Defender for Cloud Apps
Why it's wrong here
Microsoft Defender for Cloud Apps (MDCA) functions as a Cloud Access Security Broker (CASB), primarily focused on providing deep visibility, data travel control, and sophisticated threat protection across cloud applications. While it helps secure data and user activity within SaaS applications, its core purpose is not to directly assess an organization's adherence to specific regulatory compliance standards like PCI DSS or ISO 27001. Instead, it provides granular control and monitoring over cloud app usage, which can contribute to compliance but doesn't perform the assessment itself.
- ✗
Microsoft Defender for Identity
Why it's wrong here
Microsoft Defender for Identity (MDI) is a cloud-based security solution that leverages on-premises Active Directory signals to identify, detect, and investigate advanced threats, compromised identities, and malicious insider actions. Its primary role is to protect hybrid identity environments by monitoring user behavior and detecting anomalies indicative of attacks like pass-the-hash or Golden Ticket. While crucial for identity security, MDI does not offer capabilities for assessing an organization's overall regulatory compliance posture against standards like HIPAA or GDPR.
- ✗
Defender for Cloud’s Secure Score
Why it's wrong here
Microsoft Defender for Cloud's Secure Score is a dynamic measurement of an organization's security posture, providing a numerical representation of how well security controls are implemented. It aggregates security recommendations into a single score, helping prioritize actions to improve overall security. While a high Secure Score indicates strong security practices, it does not directly map to specific regulatory compliance standards or provide a dashboard for tracking adherence to frameworks like ISO 27001 or PCI DSS. Its focus is on general security hardening, not formal compliance assessment.
Go deeper
Related to this question
Learn chapter
Microsoft Defender XDR
Key term
ISO 27001
ISO 27001 is an international standard that specifies the requirements for establishing, implementing, maintaining, and continually improving an information security management system (ISMS).
Key term
General Data Protection Regulation
A European Union law that gives individuals control over their personal data and sets strict rules for how organizations collect, store, and process that data.
About these practice questions
This SC-900 question is part of Courseiva's 1,279-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.