AZ-500 Question 222
Select 2Your organization wants to track compliance with ISO 27001 across all its Azure subscriptions using Microsoft Defender for Cloud. You enabled the ISO 27001 standard in the Regulatory compliance blade, but some subscriptions are not displaying any compliance data. Which two actions should you take to ensure all subscriptions are properly assessed and display compliance results? (Choose two.)
- A
Assign the built-in ISO 27001 initiative to every subscription or to the management group that contains these subscriptions.
- B
Create a brand-new custom compliance standard for ISO 27001 and directly add each subscription to this custom standard.
- C
Onboard each subscription to Microsoft Defender for Cloud with the default policies enabled.
- D
Enable Continuous Export in Microsoft Defender for Cloud to track all compliance data in an external workspace.
Show answer and explanation
Correct answers: A, C
Explanation
To assess compliance with ISO 27001 in Microsoft Defender for Cloud, you need to ensure that the ISO 27001 initiative is assigned to your subscriptions (or the management group containing them) and that each subscription is properly onboarded. By default, Defender for Cloud provides a built-in compliance standard for ISO 27001, so you don't need to create a custom standard. For more information, refer to the official Microsoft documentation on assigning regulatory compliance standards within the Microsoft Defender for Cloud Regulatory compliance dashboard.
- A. Correct.
Correct. Microsoft Defender for Cloud relies on Azure Policy initiatives to assess resources against security requirements. You must assign the built-in ISO 27001 initiative to the relevant subscriptions (either individually or through a management group) so that Defender for Cloud can systematically scan them against ISO 27001 controls.
- B. Incorrect.
Incorrect. Defender for Cloud already provides built-in support and a built-in initiative for ISO 27001. Creating a new custom standard is typically unnecessary unless you need specialized controls or a framework not provided out of the box.
- C. Correct.
Correct. Each Azure subscription must be onboarded to Defender for Cloud with default policies enabled (or at least the required security policies). Without this onboarding, Defender for Cloud cannot gather and display compliance results.
- D. Incorrect.
Incorrect. Continuous Export is useful for exporting Defender for Cloud recommendations and security alerts to external services but does not determine whether subscriptions are included in compliance assessments. It won't fix the issue of missing compliance data for certain subscriptions.