SC-900 Practice Question: Describe the capabilities of Microsoft security solutions
Your company uses Microsoft Defender for Cloud to secure multicloud workloads. You need to ensure that regulatory compliance frameworks (e.g., SOC 2, ISO 27001) are continuously assessed and any drift is reported. What should you implement?
⚠ Common exam trap
SC-900 often tests the confusion between Defender for Cloud's regulatory compliance dashboard and Azure Policy — candidates pick Azure Policy because it 'enforces compliance,' but only Defender for Cloud provides the framework-mapped continuous assessment view.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Regulatory compliance standards in Microsoft Defender for Cloud
Microsoft Defender for Cloud includes a Regulatory Compliance dashboard that continuously assesses resources against built-in standards such as SOC 2, ISO 27001, PCI DSS, and NIST. It surfaces compliance drift in real time and maps failing assessments to specific controls, which is exactly what continuous regulatory assessment requires.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Regulatory compliance standards in Microsoft Defender for Cloud
Why this is correct
Regulatory compliance standards in Microsoft Defender for Cloud provide continuous assessment of your cloud environment against a wide array of industry and regulatory benchmarks, such as ISO 27001, SOC 2, and PCI DSS. It automatically maps security recommendations to specific controls within these standards, offering a compliance score and detailed reports. This feature helps organizations understand their current compliance posture and provides actionable insights to remediate non-compliant resources, simplifying the audit preparation process.
- ✗
Microsoft Sentinel analytics rules
Why it's wrong here
Microsoft Sentinel analytics rules are designed for Security Information and Event Management (SIEM) and Security Orchestration, Automation, and Response (SOAR) capabilities. These rules identify threats, anomalies, and suspicious activities across an organization's digital estate by correlating logs and events from various sources. While critical for threat detection and incident response, Sentinel's primary function is not to directly assess or report against established regulatory compliance frameworks or provide a compliance score.
- ✗
Azure Policy initiatives
Why it's wrong here
Azure Policy initiatives are collections of Azure Policy definitions that enforce organizational standards and assess compliance for Azure resources at scale. They are instrumental for governance, ensuring resource configurations adhere to specified rules (e.g., requiring encryption or specific VM sizes). However, Azure Policy primarily focuses on enforcing technical configurations and auditing resource properties, rather than providing a comprehensive, high-level assessment and reporting framework against specific regulatory compliance standards like those offered by Defender for Cloud.
- ✗
Microsoft Defender for Cloud Apps session policies
Why it's wrong here
Microsoft Defender for Cloud Apps session policies, part of the Cloud Access Security Broker (CASB) capabilities, are used to monitor and control user activities within cloud applications in real-time. These policies can prevent data exfiltration, enforce 'protect' actions, or block specific activities within SaaS applications. While crucial for data protection and access control in cloud apps, their scope is focused on application usage and user behavior, not on assessing the overall infrastructure's adherence to broad regulatory compliance frameworks.
Go deeper
Related to this question
Learn chapter
Compliance Concepts
Key term
Defender for Cloud
Microsoft Defender for Cloud is a cloud security posture management (CSPM) and cloud workload protection platform (CWPP) that provides unified security management and threat protection across hybrid and multi-cloud environments.
Key term
ISO 27001
ISO 27001 is an international standard that specifies the requirements for establishing, implementing, maintaining, and continually improving an information security management system (ISMS).
About these practice questions
Courseiva writes every SC-900 question from scratch — 1,279 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.