A company uses Microsoft Defender for Cloud to improve their cloud security posture. They want to see an aggregated score that reflects how well their resources are protected against threats. Which feature in Defender for Cloud provides this?
The Security Score is a crucial feature within Microsoft Defender for Cloud that provides a quantifiable, aggregated metric reflecting an organization's overall security posture across its hybrid and multi-cloud environments. It is calculated based on the implementation status of security recommendations derived from continuous assessments against security benchmarks. This score helps prioritize security efforts by showing the potential impact of implementing specific recommendations on the overall security posture, enabling clear tracking of improvements over time.
Why this answer
The Security Score in Microsoft Defender for Cloud aggregates findings from security assessments and controls into a single percentage score, reflecting how well resources are protected against threats. It is based on the Secure Score algorithm, which calculates the ratio of passed controls to total controls, weighted by the potential impact of each control. This provides a unified, quantitative measure of cloud security posture.
Exam trap
The trap here is that candidates confuse the broader Cloud Security Posture Management (CSPM) capability with the specific Security Score feature, but CSPM is the umbrella term for posture management, while Security Score is the concrete metric that provides the aggregated score.
How to eliminate wrong answers
Option A is wrong because the Compliance dashboard maps security controls to regulatory standards (e.g., SOC 2, ISO 27001) and shows compliance status, not an aggregated threat protection score. Option C is wrong because Cloud Security Posture Management (CSPM) is the overarching capability that includes security assessments, hardening recommendations, and the Security Score; the question asks for the specific feature that provides the aggregated score, not the broader capability. Option D is wrong because Workload protections focus on advanced threat detection and response for specific workloads (e.g., servers, databases) using tools like Just-In-Time VM access and adaptive application controls, not an aggregated security score.