This post is a part of the "SC-500: Implementing End-to-End Security Controls for Cloud and AI Workloads" Exam Prep Hub.
This topic falls under these sections:
Manage and monitor security posture (20–25%)
--> Manage security posture by using Defender for Cloud
--> Evaluate compliance against security frameworks by using Defender for Cloud
Note that there are 10 practice questions (with answers) at the end of each section to help you solidify your knowledge of the material. Also, there are 4 practice tests with 30 questions each available from the hub's main page below the exam topics section.
Introduction
Cloud security is not limited to protecting resources from attacks. Organizations must also demonstrate that their cloud environments are configured and operated in accordance with applicable security frameworks, industry standards, regulatory requirements, and organizational policies.
For example, an organization might need to evaluate its Azure environment against:
- Microsoft Cloud Security Benchmark (MCSB)
- NIST
- ISO 27001
- PCI DSS
- CIS Benchmarks
- SOC requirements
- HIPAA
- FedRAMP
- CMMC
- GDPR
- NIS2
- Other industry-specific or regional frameworks
Microsoft Defender for Cloud provides a Regulatory compliance experience that helps organizations assess their cloud resources against supported security standards, identify compliance gaps, investigate failing controls, remediate issues, and communicate compliance status.
For the SC-500 exam, it is important to understand the relationship between:
Security Standard → Compliance Control → Assessment → Recommendation → Remediation → Compliance Posture
1. What Is Regulatory Compliance?
Regulatory compliance is the process of ensuring that an organization satisfies applicable legal, regulatory, industry, and security requirements.
In cloud environments, compliance can involve requirements related to:
- Identity and access management
- Data protection
- Encryption
- Network security
- Logging and monitoring
- Vulnerability management
- Configuration management
- Incident response
- Business continuity
- Physical security
- Privacy
- Data retention
A security framework may contain hundreds of individual requirements.
Defender for Cloud helps organizations translate those requirements into technical security controls that can be evaluated against cloud resources.
2. Defender for Cloud Regulatory Compliance
The Regulatory compliance dashboard in Defender for Cloud provides an interactive view of compliance posture against assigned security standards.
The dashboard allows security teams to:
- View assigned standards
- Review compliance controls
- Identify failed assessments
- Investigate affected resources
- Review remediation recommendations
- Track compliance posture
- Generate compliance reports
- Monitor compliance over time
- Work with manual assessments and attestations
- Integrate compliance information with Microsoft Purview Compliance Manager
Microsoft describes security standards in Defender for Cloud as representations of industry standards, regulatory standards, and benchmarks.
3. Security Standards
A security standard represents a framework, benchmark, or regulatory requirement against which an environment can be evaluated.
Examples include:
| Category | Example |
|---|---|
| Security benchmark | Microsoft Cloud Security Benchmark |
| Industry benchmark | CIS |
| Security framework | NIST |
| International standard | ISO 27001 |
| Payment security | PCI DSS |
| Healthcare | HIPAA |
| Government | FedRAMP |
| Financial services | SWIFT |
| Privacy | GDPR |
| Cybersecurity regulation | NIS2 |
The exact standards available depend on the cloud environment and Microsoft’s current supported standards.
Current Defender for Cloud documentation lists standards including NIST CSF, NIST SP 800-53, PCI DSS, CIS, ISO 27001, HIPAA, FedRAMP, CMMC, GDPR, NIS2, DORA, and others across supported Azure, AWS, and GCP environments.
4. Microsoft Cloud Security Benchmark
The Microsoft Cloud Security Benchmark (MCSB) is particularly important for the SC-500 exam.
MCSB provides Microsoft security recommendations and technical guidance for cloud environments.
It covers security areas such as:
- Network security
- Identity management
- Privileged access
- Data protection
- Logging
- Incident response
- Vulnerability management
- Endpoint security
- Application security
- Cloud governance
When Defender for Cloud is enabled, the MCSB is automatically used as the default security benchmark for Azure environments.
Exam Tip
If a question asks which benchmark is automatically available when Defender for Cloud is enabled for Azure, think:
Microsoft Cloud Security Benchmark (MCSB).
5. Security Standards vs. Security Controls
A security standard is not simply one large requirement.
A standard is broken down into controls.
For example:
Security Standard | +--- Identity Control | +--- Network Security Control | +--- Data Protection Control | +--- Logging Control | +--- Vulnerability Control
Each control represents a logical group of related security requirements.
Defender for Cloud evaluates applicable resources against controls that can be assessed automatically.
6. Compliance Controls
A compliance control is a logical grouping of security requirements within a standard.
Controls can contain one or more security assessments or recommendations.
Conceptually:
PCI DSS | +--- Network Security | | | +--- Assessment | +--- Assessment | +--- Access Control | | | +--- Assessment | +--- Assessment | +--- Data Protection | +--- Assessment +--- Assessment
This hierarchy makes it easier to determine where an organization is meeting requirements and where gaps exist.
7. Assessments
An assessment determines whether a resource satisfies a particular security requirement.
For example, an assessment might determine whether:
- Storage data is encrypted
- Administrative access is restricted
- Network traffic is appropriately protected
- A VM has disk encryption enabled
- A resource has an insecure configuration
- Logging is configured
If a resource fails an automated assessment, Defender for Cloud can generate a security recommendation explaining what needs to be changed.
The relationship can therefore be thought of as:
Standard ↓Control ↓Assessment ↓Resource Evaluation ↓Pass / Fail / Unavailable
8. Compliance Assessment States
Defender for Cloud uses compliance assessment states to communicate whether resources satisfy a control.
The Regulatory compliance experience uses three important states:
Compliant
Resources in scope satisfy the applicable assessment.
Noncompliant
One or more resources do not satisfy the applicable requirement.
Unavailable
Defender for Cloud cannot automatically determine compliance for that control.
This distinction is important.
Unavailable does not necessarily mean noncompliant.
It means Defender for Cloud cannot automatically determine the compliance state for that control.
9. Why Some Controls Are Unavailable
Not every compliance requirement can be evaluated automatically.
Some requirements require:
- Human review
- Organizational documentation
- Policies
- Procedures
- Evidence
- Interviews
- Physical security verification
- Business processes
- External audit evidence
For example, a framework might require an organization to have a documented incident-response procedure.
Defender for Cloud cannot determine solely from Azure resource configuration whether that procedure exists and is being followed.
The control may therefore be unavailable for automatic assessment.
10. Automated vs. Manual Assessments
This distinction is particularly important for the SC-500 exam.
Automated assessment
Defender for Cloud can evaluate the requirement using available technical information.
Example:
Are storage accounts configured according to the required security configuration?
Defender for Cloud can inspect resource configuration and determine the result.
Manual assessment
The requirement requires customer input or evidence.
Example:
Does the organization maintain a documented security incident-response procedure?
A cloud platform cannot necessarily determine this automatically.
Manual assessments can require the organization to provide an attestation and evidence. Current Microsoft documentation explicitly supports manual attestation and evidence through the Regulatory compliance experience.
11. The Regulatory Compliance Dashboard
The Regulatory compliance dashboard is the central location for reviewing compliance posture.
Security teams can use it to:
- View assigned standards
- Review compliance scores/status
- Examine controls
- Identify failing assessments
- Investigate resources
- Review remediation actions
- Track compliance over time
- Generate reports
- Access audit-related reports
The dashboard provides an interactive overview of the organization’s compliance state.
12. Understanding the Compliance Dashboard
A simplified view of the workflow is:
Regulatory Compliance | +--- Standards | +--- Controls | +--- Assessments | +--- Resources | +--- Recommendations | +--- Remediation | +--- Reports
A security administrator can start at the standard level and drill down toward individual resources.
For example:
PCI DSS ↓Requirement / Control ↓Failed Assessment ↓Azure Resource ↓Security Recommendation ↓Remediation
13. Assigning a Compliance Standard
Organizations can assign supported regulatory compliance standards to applicable scopes.
The scope can include supported:
- Azure subscriptions
- AWS accounts
- GCP projects
Defender for Cloud uses Azure Policy initiatives to represent regulatory compliance standards and evaluates the selected scope against those standards.
Example
Suppose a company has an Azure subscription supporting a payment-processing application.
The company may choose to apply:
PCI DSS
to the appropriate scope.
Defender for Cloud can then assess applicable resources against the controls represented by that standard.
14. Why Scope Matters
Compliance assessments are performed against a defined scope.
For example:
Tenant | +--- Subscription A | | | +--- Production | +--- Subscription B | +--- Development
The organization might apply a compliance standard to only the production subscription.
This is important because compliance requirements may differ between environments.
For example:
- Production may contain regulated data.
- Development may contain synthetic data.
- A specific subscription may host payment-processing workloads.
- Another subscription may host unrelated applications.
Therefore, applying the correct standard to the correct scope is an important part of compliance management.
15. Security Policies and Azure Policy Initiatives
Defender for Cloud regulatory standards are closely related to Azure Policy.
A useful conceptual model is:
Regulatory Standard ↓Azure Policy Initiative ↓Policies / Controls ↓Resource Evaluation ↓Assessment Results
Microsoft documentation states that regulatory compliance standards in Defender for Cloud use Azure Policy initiatives.
This is an important SC-500 relationship.
Exam Tip
If a question asks what mechanism is used to represent regulatory compliance standards for assessment, remember:
Azure Policy initiatives.
16. Compliance Gaps
A compliance gap exists when a resource or configuration does not satisfy an applicable compliance requirement.
For example:
ISO 27001 | +--- Access Control | +--- PASS | +--- PASS | +--- FAIL | ↓ VM01 | ↓ Security Recommendation
The failing assessment tells the security administrator where attention is required.
17. Investigating a Compliance Gap
A typical investigation might follow this sequence:
Step 1
Open Regulatory compliance.
Step 2
Select the relevant standard.
Step 3
Select the control with a failing assessment.
Step 4
Review the affected resources.
Step 5
Review the associated security recommendation.
Step 6
Review remediation instructions.
Step 7
Remediate the resource.
Step 8
Wait for the assessment to run again.
Step 9
Confirm that the compliance status has improved.
This creates a continuous improvement cycle.
18. Compliance Recommendations
A failed compliance assessment frequently maps to a security recommendation.
For example:
Control:
Protect data at rest.
Assessment:
Storage resource does not meet encryption requirement.
Recommendation:
Configure the required encryption settings.
Remediation:
Modify the resource configuration.
This creates a practical relationship between compliance and security operations.
Compliance does not merely tell an organization:
“You failed.”
It can help explain:
“Here is the resource causing the problem and what you can do about it.”
19. Compliance Scores and Posture
The Regulatory compliance dashboard provides a way to monitor compliance posture.
For example:
PCI DSSPassed Controls: 82%Failed Controls: 18%
An organization can use this information to:
- Identify weak areas
- Prioritize remediation
- Communicate progress
- Track improvements
- Prepare for audits
However, a compliance percentage should not automatically be interpreted as a legal certification.
20. Defender for Cloud Does Not Make an Organization “Certified”
This is a critical concept.
Suppose Defender for Cloud shows:
ISO 27001 — 95% compliant
That does not automatically mean:
“The company is ISO 27001 certified.”
Similarly:
PCI DSS — 100% of automatically assessed controls passed
does not necessarily mean the organization has satisfied every PCI DSS obligation or received a formal certification/attestation from the appropriate authority.
Defender for Cloud provides assessment and posture-management capabilities.
Organizations may still need:
- Policies
- Procedures
- Evidence
- Manual attestations
- Independent audits
- External certification
- Other organizational controls
Exam Principle
Compliance tooling supports compliance; it does not automatically confer legal or regulatory certification.
21. Shared Responsibility
Cloud compliance must also be understood in the context of the shared responsibility model.
Microsoft is responsible for security aspects of the cloud platform that are under Microsoft’s control.
The customer remains responsible for many aspects of its own:
- Data
- Identities
- Configurations
- Applications
- Access
- Policies
- Processes
Therefore, passing a technical cloud assessment does not necessarily mean every organizational compliance requirement has been satisfied.
22. Microsoft Actions vs. Your Actions
The Regulatory compliance experience can help distinguish responsibilities associated with compliance.
For a selected control, the dashboard can provide information about:
Your Actions
Actions the customer needs to take to improve compliance.
Microsoft Actions
Actions Microsoft has taken to support compliance with the applicable standard.
This is particularly useful when communicating compliance responsibilities to auditors and stakeholders.
23. Manual Attestation
Manual assessments require customer participation.
A security administrator can provide:
- An attestation
- Supporting information
- Evidence
This allows the organization to document compliance for requirements that Defender for Cloud cannot technically evaluate on its own.
Conceptually:
Manual Control | ↓Customer Review | ↓Attestation | ↓Evidence | ↓Compliance Record
Example
A framework requires:
Security incidents must be reviewed according to a documented organizational process.
Defender for Cloud may not be able to prove that the organization follows the process.
The organization may therefore provide an attestation and supporting evidence.
24. Compliance Reporting
Organizations often need to communicate compliance posture to:
- Security leadership
- IT leadership
- Auditors
- Compliance officers
- Risk management teams
- Regulators
- Business stakeholders
Defender for Cloud supports reporting capabilities that can help communicate compliance status.
The Regulatory compliance dashboard can generate reports for a selected standard, including a summary of compliance status based on Defender for Cloud assessment data.
25. Compliance Over Time
Compliance is not a one-time activity.
A company might be compliant today and become noncompliant tomorrow because:
- A new resource is deployed.
- A configuration changes.
- A firewall rule is modified.
- A new identity receives excessive permissions.
- Encryption is disabled.
- A security policy changes.
- A new vulnerability is discovered.
Therefore:
Compliance must be continuously monitored.
Defender for Cloud’s compliance capabilities allow organizations to track their compliance posture over time.
26. Compliance Workbooks
Compliance information can also be presented through workbooks.
Workbooks can help security teams visualize and communicate information such as:
- Compliance trends
- Standard performance
- Control status
- Remediation progress
- Compliance changes over time
This can be particularly useful for executive reporting.
27. Microsoft Purview Compliance Manager Integration
Defender for Cloud compliance information can integrate with Microsoft Purview Compliance Manager.
This provides an opportunity to bring compliance information into a broader compliance-management experience.
Current Microsoft documentation states that compliance data from Defender for Cloud can be surfaced in Compliance Manager for the same standards, including standards monitoring supported AWS and GCP environments.
Think of the distinction this way:
Defender for Cloud
Cloud security posture and technical compliance assessment
Microsoft Purview Compliance Manager
Broader compliance-management experience across the organization’s digital estate
28. Compliance Reporting vs. Audit Reports
These concepts should not be confused.
Compliance status report
Communicates the organization’s current compliance posture based on Defender for Cloud assessment data.
Audit report
Provides Microsoft audit/certification documentation for applicable Microsoft services and standards.
An organization’s own compliance posture is not the same thing as Microsoft’s certification of its cloud services.
This distinction can matter when preparing evidence for auditors.
29. Compliance Assessment Refresh
After correcting a compliance issue, the dashboard may not immediately show the new result.
Defender for Cloud assessments run periodically.
Current Microsoft documentation states that compliance assessments run approximately every 12 hours for the applicable assessments.
Therefore, if an administrator fixes a resource and immediately checks the compliance dashboard, the old result may still be displayed.
Exam Scenario
A security engineer fixes a failed recommendation but the compliance dashboard still shows the resource as noncompliant.
What should the engineer consider?
The assessment may not have run again yet.
30. Automating Compliance Responses
Defender for Cloud supports workflow automation.
For example, an organization could configure an automation workflow that responds when a regulatory compliance assessment changes.
A Logic App can be used to perform actions such as:
- Sending notifications
- Triggering workflows
- Initiating downstream processes
- Alerting compliance personnel
Current Microsoft documentation specifically describes triggering Logic Apps when regulatory compliance assessments change state.
31. Compliance Across Multiple Clouds
Modern organizations often use:
- Azure
- AWS
- Google Cloud
Defender for Cloud can provide regulatory compliance visibility across supported multicloud environments.
This allows organizations to use a centralized security posture experience rather than maintaining completely separate compliance-management processes for each cloud.
Supported standards vary by cloud provider.
For example:
Microsoft Defender for Cloud | +------+------+ | | | Azure AWS GCP | | |Standards / Compliance Assessments
The specific standards available depend on the cloud provider and the current Defender for Cloud capabilities.
32. Custom Standards
Organizations may have security requirements that aren’t fully represented by a built-in regulatory standard.
Defender for Cloud supports custom standards and custom recommendations.
Custom recommendations can be created with organization-specific logic, including KQL-based evaluation, and can then be associated with custom standards.
Example
An organization might require:
All production storage resources must use a specific approved configuration.
If a built-in framework does not provide the exact requirement, the organization can create a custom recommendation and incorporate it into a custom standard.
33. Built-In Standards vs. Custom Standards
| Capability | Built-In Standard | Custom Standard |
|---|---|---|
| Based on recognized framework | Yes | Not necessarily |
| Microsoft-provided | Yes | Organization-defined |
| Standard controls included | Yes | Organization selects/defines |
| Custom organizational requirements | Limited | Strong |
| Useful for regulatory frameworks | Yes | Can supplement them |
| Can use custom recommendations | Not the primary purpose | Yes |
Custom standards are particularly useful when organizations need to enforce internal security requirements that aren’t adequately represented by an existing framework.
34. Example: PCI DSS Assessment
Consider a company processing credit-card transactions.
The organization assigns PCI DSS to the appropriate environment.
The resulting workflow might be:
PCI DSS | ↓Compliance Controls | ↓Azure Resources | ↓Assessments | +---- PASS | +---- FAIL | ↓ Recommendation | ↓ Remediation | ↓ Reassessment
The security team can then identify which controls are failing and which resources are responsible.
35. Example: ISO 27001 Assessment
Suppose an organization wants to evaluate its Azure environment against ISO 27001.
The organization can:
- Assign the appropriate standard.
- Review the Regulatory compliance dashboard.
- Examine the applicable controls.
- Identify failed assessments.
- Investigate affected resources.
- Remediate applicable technical issues.
- Provide manual evidence where required.
- Generate compliance reports.
- Track progress over time.
The process helps the organization identify technical gaps, but formal ISO certification involves additional organizational and audit requirements.
36. Example: NIST Assessment
Suppose an organization uses NIST as its security framework.
Defender for Cloud can help map technical cloud configurations and recommendations to the applicable supported NIST standard.
The security team can then determine:
- Which controls are passing
- Which controls are failing
- Which resources are affected
- Which recommendations need remediation
- Which controls require manual assessment
This provides a technical starting point for broader compliance activities.
37. Compliance vs. Security Posture
These concepts overlap but are not identical.
Security posture
Answers:
How secure is our environment?
Regulatory compliance
Answers:
How closely does our environment align with the requirements of a particular standard or framework?
For example, an organization could have:
- Strong security posture
- But not satisfy a particular regulatory requirement
Conversely, an organization could satisfy many technical controls in a framework while still having broader security risks that aren’t fully captured by that framework.
Therefore, organizations should manage both.
38. Compliance vs. Secure Score
Secure Score and Regulatory Compliance serve different purposes.
| Secure Score | Regulatory Compliance |
|---|---|
| Measures security posture | Measures alignment with a selected standard |
| Broad security recommendations | Framework-specific controls |
| Helps improve security posture | Helps evaluate compliance requirements |
| Not a certification | Not automatically a certification |
| Security-focused | Compliance/framework-focused |
Exam Tip
If the question mentions:
“Improve overall security posture”
think Secure Score.
If it mentions:
“Evaluate against PCI DSS, ISO, NIST, CIS, or another framework”
think Regulatory compliance.
39. Compliance vs. Defender for Cloud Recommendations
Security recommendations are often the technical mechanism through which compliance issues are addressed.
For example:
Compliance Requirement ↓Control ↓Failed Assessment ↓Security Recommendation ↓Remediation
This makes recommendations extremely important to compliance operations.
40. Common Mistakes
Mistake 1: Assuming a passing compliance score equals certification
A Defender for Cloud compliance result does not automatically constitute formal certification.
Mistake 2: Treating “Unavailable” as “Noncompliant”
Unavailable means Defender for Cloud cannot automatically determine the result.
Mistake 3: Assuming every control can be automated
Some controls require manual evidence or attestation.
Mistake 4: Forgetting the scope
Standards are assigned to specific scopes.
Always determine which subscription, account, project, or other supported scope is being assessed.
Mistake 5: Expecting remediation results immediately
Compliance assessments run periodically. Changes may not appear immediately.
Mistake 6: Confusing MCSB with a regulatory certification
MCSB is Microsoft’s cloud security benchmark. It is not itself a regulatory certification.
Mistake 7: Confusing compliance standards with individual policies
A standard represents a framework or benchmark containing multiple controls. Azure Policy initiatives are used to implement regulatory compliance standards for assessment.
Mistake 8: Assuming Microsoft is responsible for every compliance requirement
Cloud compliance follows a shared-responsibility model.
41. SC-500 Exam-Focused Comparison
| If the question asks about… | Think about… |
|---|---|
| Overall cloud security posture | Secure Score |
| A specific security weakness | Security recommendation |
| Evaluating against ISO, PCI DSS, NIST, CIS, etc. | Regulatory compliance |
| Default Azure security benchmark | MCSB |
| Logical grouping of related requirements | Compliance control |
| Technical evaluation of a control | Assessment |
| Cannot automatically determine compliance | Unavailable/manual assessment |
| Customer-provided evidence | Manual attestation |
| Applying a standard to a subscription | Assign compliance standard |
| Framework implementation mechanism | Azure Policy initiative |
| Fixing a failed technical assessment | Security recommendation/remediation |
| Communicating compliance posture | Compliance report/workbook |
| Broader compliance management | Microsoft Purview Compliance Manager |
| Automatic response to assessment changes | Workflow automation / Logic Apps |
| Organization-specific requirements | Custom standards/recommendations |
42. A Complete Compliance Management Workflow
The entire process can be summarized as:
SELECT STANDARD
|
v
DEFINE THE SCOPE
|
v
ASSESS RESOURCES
|
+----------+----------+
| |
PASS FAIL
| |
| v
| INVESTIGATE GAP
| |
| v
| REVIEW RECOMMENDATION
| |
| v
| REMEDIATE
| |
| v
| REASSESS
| |
+----------+----------+
|
v
MONITOR OVER TIME
|
v
REPORT COMPLIANCE
For controls that cannot be automatically evaluated:
Manual Control | vCustomer Review | vAttestation + Evidence | vCompliance Record
43. Key Takeaways
For the SC-500 exam, remember the following:
- Defender for Cloud provides a Regulatory compliance experience for evaluating cloud environments against supported standards and frameworks.
- A security standard represents a framework, benchmark, or regulatory requirement.
- Standards are divided into compliance controls.
- Controls are evaluated through assessments.
- Failed assessments can produce security recommendations.
- Security recommendations provide remediation guidance.
- MCSB is the default security benchmark for Azure when Defender for Cloud is enabled.
- Regulatory compliance standards use Azure Policy initiatives.
- Standards can be assigned to appropriate scopes such as Azure subscriptions and supported multicloud scopes.
- Some controls can be assessed automatically.
- Other controls require manual attestation and evidence.
- Unavailable does not mean noncompliant; it means Defender for Cloud cannot automatically determine the status.
- Compliance status can be investigated through the Regulatory compliance dashboard.
- Compliance reports can communicate assessment results to stakeholders.
- Compliance can be monitored over time rather than evaluated only once.
- Compliance assessment results may take time to update after remediation because assessments run periodically.
- Defender for Cloud compliance information can integrate with Microsoft Purview Compliance Manager.
- Workflow automation can trigger Logic Apps when compliance assessments change.
- Custom standards and recommendations can address organization-specific requirements.
- Passing Defender for Cloud assessments does not by itself constitute legal or regulatory certification.
Practice Exam Questions
Question 1
A security administrator wants to evaluate an Azure subscription against the requirements of a recognized security framework such as ISO 27001.
Which Microsoft Defender for Cloud capability should the administrator use?
A. Secure Score only
B. Cloud Security Explorer
C. Microsoft Defender Vulnerability Management
D. Regulatory compliance
Answer: D
Explanation
The Regulatory compliance experience is designed to evaluate cloud environments against supported security standards, regulatory standards, and benchmarks.
Secure Score is useful for evaluating overall security posture, but it does not replace framework-specific compliance assessment.
Question 2
An organization enables Microsoft Defender for Cloud on an Azure subscription. The security team wants to begin evaluating the environment against Microsoft’s default cloud security benchmark.
Which benchmark should the team expect?
A. PCI DSS
B. Microsoft Cloud Security Benchmark
C. ISO 27001
D. NIST SP 800-53
Answer: B
Explanation
The Microsoft Cloud Security Benchmark (MCSB) is the default security benchmark used for Azure when Defender for Cloud is enabled.
Other regulatory and industry standards can be added as appropriate.
Question 3
A compliance administrator selects a regulatory standard and wants to understand why several resources are reported as failing a particular requirement.
What should the administrator investigate first?
A. Microsoft Security Copilot
B. Secure Score history
C. The compliance control and its failing assessments
D. Azure Activity Log only
Answer: C
Explanation
The Regulatory compliance dashboard organizes standards into controls, which contain assessments.
The administrator can expand the applicable control, investigate failing assessments, identify affected resources, and review associated remediation guidance.
Question 4
A regulatory framework contains a requirement that an organization maintain a documented incident-response procedure. Defender for Cloud cannot determine automatically whether the organization has such a procedure.
How should this type of requirement be handled?
A. Mark the resource as vulnerable
B. Automatically pass the control
C. Disable the entire compliance standard
D. Use a manual assessment and provide appropriate attestation or evidence
Answer: D
Explanation
Not every compliance requirement can be evaluated from cloud resource configuration.
For requirements that cannot be automatically assessed, Defender for Cloud can use manual assessments, where the customer provides an attestation and supporting evidence.
An unavailable assessment should not automatically be interpreted as a failed assessment.
Question 5
An administrator fixes a resource that previously failed a compliance assessment. Immediately afterward, the Regulatory compliance dashboard still shows the resource as noncompliant.
What is the most likely explanation?
A. The compliance standard must always be deleted and reassigned
B. The assessment has not yet run again
C. Secure Score must reach 100 percent first
D. The resource must be moved to another subscription
Answer: B
Explanation
Defender for Cloud compliance assessments run periodically. Current Microsoft documentation indicates that applicable assessments run approximately every 12 hours.
Therefore, a remediation change may not be reflected immediately in the compliance dashboard.
Question 6
A company wants to apply a PCI DSS standard only to the Azure subscription hosting its payment-processing workloads.
What should the security administrator configure?
A. Assign the PCI DSS standard to the appropriate scope
B. Enable Microsoft Sentinel on every subscription
C. Increase the Secure Score target
D. Create a Microsoft Purview eDiscovery case
Answer: A
Explanation
Regulatory compliance standards can be assigned to appropriate scopes.
If only one subscription contains the applicable workload, the organization can apply the standard to that subscription rather than unnecessarily applying it to unrelated environments.
Question 7
Which technology mechanism is used to represent regulatory compliance standards for assessment in Microsoft Defender for Cloud?
A. Microsoft Sentinel analytics rules
B. Azure Monitor alerts
C. Azure Policy initiatives
D. Microsoft Entra Conditional Access policies
Answer: C
Explanation
Defender for Cloud regulatory compliance standards use Azure Policy initiatives.
These provide the policy structure used to evaluate applicable resources against the controls represented by the standard.
This is an important SC-500 distinction: Conditional Access is primarily an identity access-control mechanism, while Azure Policy initiatives are used for resource governance and compliance evaluation.
Question 8
A security administrator sees that a compliance control is displayed as unavailable rather than compliant or noncompliant.
What does this generally indicate?
A. The subscription has been compromised
B. The standard has been permanently disabled
C. The resource has failed the control
D. Defender for Cloud cannot automatically determine compliance for that control
Answer: D
Explanation
An unavailable control indicates that Defender for Cloud cannot automatically assess the requirement.
This is different from a noncompliant result.
Some controls require manual assessment, organizational evidence, or other information that cannot be determined from cloud resource configuration alone.
Question 9
An organization wants to provide executives with a summary of its current compliance posture against a selected security standard.
Which Defender for Cloud capability is most appropriate?
A. Compliance status reporting
B. Just-in-time VM access
C. Cloud Security Explorer
D. Network Security Groups
Answer: A
Explanation
The Regulatory compliance experience supports compliance reporting, including reports summarizing the organization’s current compliance status for a selected standard.
These reports can help communicate compliance posture to stakeholders and support audit activities.
The other options address unrelated security functions.
Question 10
A company wants Defender for Cloud to notify its compliance team when a regulatory compliance assessment changes state.
Which solution should the company use?
A. Azure Bastion
B. Logic Apps with Defender for Cloud workflow automation
C. Azure Firewall
D. Microsoft Entra PIM
Answer: B
Explanation
Defender for Cloud supports workflow automation that can respond to changes in regulatory compliance assessments.
A Logic App can be configured to perform downstream actions such as notifications or other workflow processing when the relevant Defender for Cloud event occurs.
Final SC-500 Exam Reminder
The most important mental model for this topic is:
Standard → Control → Assessment → Finding → Recommendation → Remediation → Reassessment
And remember these four distinctions:
MCSB
→ Microsoft’s cloud security benchmark
Regulatory Compliance
→ Evaluate your environment against a selected framework or standard
Security Recommendation
→ Identifies a technical security issue and provides remediation guidance
Manual Attestation
→ Used when Defender for Cloud cannot automatically determine whether a compliance requirement is satisfied
Finally, remember:
Defender for Cloud can help an organization measure, improve, and document its compliance posture, but a passing Defender for Cloud assessment does not by itself constitute formal regulatory certification.
Defender for Cloud can help an organization measure, improve, and document its compliance posture, but a passing Defender for Cloud assessment does not by itself constitute formal regulatory certification.
Go to the SC-500 Exam Prep Hub main page
