AZ-500 Question 221
Select 2Your company wants to measure compliance with the NIST SP 800-53 security framework by using Microsoft Defender for Cloud. You have enabled the NIST SP 800-53 standard in the 'Regulatory compliance' settings. However, you notice that certain resources are missing from the compliance report. Which two actions should you take to ensure that all relevant resources are being evaluated for compliance in Microsoft Defender for Cloud?
- A
Assign the built-in NIST SP 800-53 policy initiative at the required subscription or management group scope.
- B
Manually trigger a custom scan from the 'Regulatory compliance' dashboard for each resource every 24 hours.
- C
Enable the appropriate Microsoft Defender plans (e.g., Defender for Servers) so that covered resources are included in compliance checks.
- D
Create a separate custom initiative for all NIST SP 800-53 controls and manually map them to resource types.
Show answer and explanation
Correct answers: A, C
Explanation
In Microsoft Defender for Cloud, simply enabling a regulatory standard in 'Regulatory compliance' does not automatically assign the built-in policy initiatives needed to assess your resources. You must assign the framework's corresponding initiative at the right scope and enable suitable Defender plans to evaluate all relevant resources. Refer to Microsoft Defender for Cloud's official documentation (https://learn.microsoft.com/azure/defender-for-cloud/) for detailed guidance on configuring multi-cloud and hybrid compliance, assigning policy initiatives, and enabling Defender for specific resource types.
- A. Correct.
Correct. Even if you have enabled the NIST SP 800-53 standard in Defender for Cloud, you must also assign the relevant built-in policy initiative at the correct scope (management group or subscription) so that Azure Policy can assess those resources.
- B. Incorrect.
Incorrect. Microsoft Defender for Cloud compliance checks run automatically; you don't need to manually trigger scans from the Compliance dashboard. Relying on a manual scan is impractical and not how Defender for Cloud is designed to run compliance evaluations.
- C. Correct.
Correct. For certain resource types (e.g., Azure VMs, servers), specific Defender for Cloud plans (like Microsoft Defender for Servers) need to be enabled. This ensures that these resources are actively monitored and included in compliance assessments.
- D. Incorrect.
Incorrect. While you can create custom initiatives, using the built-in standard and initiative assignments is generally preferred for comprehensive coverage. Creating a separate custom initiative for each control is more complex and unnecessary unless you have very specific custom requirements.