AZ-500 Question 220
Single answerYour organization must comply with the PCI-DSS standard across multiple Azure subscriptions. You have enabled Microsoft Defender for Cloud, and you want to regularly track your compliance posture and view non-compliant resources. What is the most appropriate method to achieve this using Microsoft Defender for Cloud?
- A
Enable the PCI-DSS built-in initiative at the subscription level through Microsoft Defender for Cloud and review compliance results under the regulatory compliance dashboard.
- B
Enable the Azure Security Benchmark in Microsoft Defender for Cloud and expect it to automatically map to PCI-DSS controls.
- C
Create a custom initiative for PCI-DSS in Azure Policy and assign it to individual resource groups for scanning.
- D
Use Azure Resource Graph queries to fetch all resources with compliance status and generate PCI-DSS compliance reports on-demand.
Show answer and explanation
Correct answer: A
Explanation
Microsoft Defender for Cloud includes built-in regulatory compliance standards that map specific controls to your Azure resources. To measure and report on PCI-DSS compliance, you should assign the built-in PCI-DSS initiative at the subscription or management group level. This ensures that Microsoft Defender for Cloud continuously assesses your resources against the PCI-DSS controls and displays results in the regulatory compliance dashboard. Refer to 'Microsoft Defender for Cloud documentation, Regulatory compliance' for detailed guidance on setting up and viewing these compliance assessments.
- A. Correct.
Correct: Microsoft Defender for Cloud provides built-in initiatives (such as PCI-DSS) that can be assigned at a subscription or management group level. Once assigned, Defender for Cloud will assess resources against the framework and show the results in the regulatory compliance dashboard.
- B. Incorrect.
Incorrect: The Azure Security Benchmark is a separate framework. It does not automatically fulfill PCI-DSS requirements. Although it covers many security controls, it is not a replacement for specific PCI-DSS controls.
- C. Incorrect.
Incorrect: While you could create a custom initiative, Microsoft Defender for Cloud offers a built-in PCI-DSS initiative that is more efficient. Assigning it at the subscription (or management group) level ensures consistent coverage for all relevant resources without needing to repeat manual assignments.
- D. Incorrect.
Incorrect: Azure Resource Graph queries help you retrieve data about resources, but they do not provide out-of-the-box regulatory compliance mappings. For PCI-DSS compliance reporting, you should rely on Defender for Cloud’s integrated compliance features.