AZ-500 exam dumps

AZ-500 practice question 224 of 273

Microsoft Azure Security Technologies. Associate level, Microsoft. Free question with the correct answer and a full explanation.

AZ-500 Question 224

Select 2

You are a Security Engineer for an organization that must comply with a proprietary framework not included among the default compliance standards in Microsoft Defender for Cloud. You decide to create a custom compliance standard and want it to appear within the Regulatory compliance dashboard. Which TWO actions must you perform to ensure the custom standard is recognized and assessed by Microsoft Defender for Cloud?

  1. A

    Create a new Azure Policy initiative with the relevant controls and assign it to the target subscription or management group.

  2. B

    Enable the 'Unified compliance' feature in the Microsoft Defender for Cloud environment settings.

  3. C

    Activate the built-in 'NIST SP 800-53 R4' standard in Microsoft Defender for Cloud to automatically map your controls.

  4. D

    In Microsoft Defender for Cloud’s Environment settings, link your newly created initiative as a custom compliance standard under 'Manage compliance policies.'

  5. E

    Enable continuous export to a Log Analytics workspace so the custom compliance standard is detected and shown automatically.

Show answer and explanation

Correct answers: A, D

Explanation

To display a custom compliance standard in Microsoft Defender for Cloud, you need to create and assign a custom Azure Policy initiative. Then, under Environment settings, link that initiative as a custom compliance standard so it appears and is continuously assessed in the Regulatory compliance dashboard. Refer to Microsoft’s official documentation on creating and assigning Azure Policy initiatives and managing compliance standards in Defender for Cloud for more details.

  • A. Correct.

    Correct. Creating a new Azure Policy initiative that encapsulates the controls for your proprietary framework is essential. You must then assign it to the same scope (subscription or management group) for Microsoft Defender for Cloud to evaluate compliance.

  • B. Incorrect.

    Incorrect. There is no feature called 'Unified compliance' in this context. While Microsoft Defender for Cloud provides a Regulatory compliance dashboard, the concept of 'Unified compliance' is not a separate enablement toggle.

  • C. Incorrect.

    Incorrect. Activating a built-in standard (like NIST SP 800-53 R4) does not automatically map a proprietary framework. You must define a standalone initiative for your custom standard or use an existing initiative that aligns with your specific framework.

  • D. Correct.

    Correct. You must go into the Environment settings of Microsoft Defender for Cloud to associate your custom initiative with its compliance management. This action ensures your new standard is displayed and continuously assessed in the Regulatory compliance dashboard.

  • E. Incorrect.

    Incorrect. While continuous export to a Log Analytics workspace is useful for audit and reporting, it is not required for the Regulatory compliance dashboard to recognize your custom compliance standard.

Timed practice exam

Take a AZ-500 practice test under exam conditions

70 questions in 100 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam