AZ-500 Question 215
Select 2You are responsible for ensuring your organization's Azure environment meets a specific regulatory compliance standard. After enabling the relevant regulatory standard in Microsoft Defender for Cloud, you notice several compliance controls are unmet. You plan to remediate these issues and improve your security posture. Which TWO actions should you take to effectively address the unmet controls and maintain compliance?
- A
Enable the relevant regulatory standard in the Regulatory compliance blade and create a policy assignment to remediate unmet controls automatically.
- B
Disable built-in compliance controls so that fewer controls must be met, thereby instantly raising your compliance score.
- C
Review each recommendation under the ‘Resource security hygiene’ section and apply or configure the recommended security solutions where appropriate.
- D
Ignore specific policy definitions in the regulatory standard and rely on manual tracking of compliance instead.
Show answer and explanation
Correct answers: A, C
Explanation
To effectively manage your security posture and align with a regulatory standard using Microsoft Defender for Cloud, you should: (1) enable the relevant regulatory standard and create or update a policy assignment targeting the resources within scope, and (2) regularly review the Defender for Cloud recommendations and apply the necessary configurations. This approach leverages built-in policies, automated remediation (where supported), and continuous compliance scanning. Refer to Microsoft’s Defender for Cloud documentation for up-to-date best practices on managing regulatory compliance and improving your overall security posture.
- A. Correct.
Correct. Enabling the relevant regulatory standard in Defender for Cloud and creating a policy assignment is a recommended approach. By applying policy assignments that target the relevant resources, you can remediate (often automatically) any non-compliant items and track their status in one place.
- B. Incorrect.
Incorrect. Simply disabling built-in compliance controls will make your environment appear compliant but does not address actual risks or meet real regulatory requirements. This is a common misconception and violates best practices.
- C. Correct.
Correct. Reviewing and acting on Defender for Cloud recommendations under 'Resource security hygiene' is essential for meeting compliance requirements and improving overall security posture. Each recommendation addresses a specific control, enabling you to achieve the required compliance level.
- D. Incorrect.
Incorrect. Ignoring policy definitions under a given regulatory standard prevents proper remediation efforts and could lead to missed vulnerabilities or gaps in security posture. Manual tracking is prone to oversight and does not leverage Defender for Cloud’s automation and continuous monitoring benefits.