AZ-500 exam dumps

AZ-500 practice question 220 of 273

Microsoft Azure Security Technologies. Associate level, Microsoft. Free question with the correct answer and a full explanation.

AZ-500 Question 220

Single answer

Your organization must comply with the PCI-DSS standard across multiple Azure subscriptions. You have enabled Microsoft Defender for Cloud, and you want to regularly track your compliance posture and view non-compliant resources. What is the most appropriate method to achieve this using Microsoft Defender for Cloud?

  1. A

    Enable the PCI-DSS built-in initiative at the subscription level through Microsoft Defender for Cloud and review compliance results under the regulatory compliance dashboard.

  2. B

    Enable the Azure Security Benchmark in Microsoft Defender for Cloud and expect it to automatically map to PCI-DSS controls.

  3. C

    Create a custom initiative for PCI-DSS in Azure Policy and assign it to individual resource groups for scanning.

  4. D

    Use Azure Resource Graph queries to fetch all resources with compliance status and generate PCI-DSS compliance reports on-demand.

Show answer and explanation

Correct answer: A

Explanation

Microsoft Defender for Cloud includes built-in regulatory compliance standards that map specific controls to your Azure resources. To measure and report on PCI-DSS compliance, you should assign the built-in PCI-DSS initiative at the subscription or management group level. This ensures that Microsoft Defender for Cloud continuously assesses your resources against the PCI-DSS controls and displays results in the regulatory compliance dashboard. Refer to 'Microsoft Defender for Cloud documentation, Regulatory compliance' for detailed guidance on setting up and viewing these compliance assessments.

  • A. Correct.

    Correct: Microsoft Defender for Cloud provides built-in initiatives (such as PCI-DSS) that can be assigned at a subscription or management group level. Once assigned, Defender for Cloud will assess resources against the framework and show the results in the regulatory compliance dashboard.

  • B. Incorrect.

    Incorrect: The Azure Security Benchmark is a separate framework. It does not automatically fulfill PCI-DSS requirements. Although it covers many security controls, it is not a replacement for specific PCI-DSS controls.

  • C. Incorrect.

    Incorrect: While you could create a custom initiative, Microsoft Defender for Cloud offers a built-in PCI-DSS initiative that is more efficient. Assigning it at the subscription (or management group) level ensures consistent coverage for all relevant resources without needing to repeat manual assignments.

  • D. Incorrect.

    Incorrect: Azure Resource Graph queries help you retrieve data about resources, but they do not provide out-of-the-box regulatory compliance mappings. For PCI-DSS compliance reporting, you should rely on Defender for Cloud’s integrated compliance features.

Timed practice exam

Take a AZ-500 practice test under exam conditions

70 questions in 100 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam