nerdexam
Microsoft

AZ-500 · Question #230

You have an Azure environment. You need to identify any Azure configurations and workloads that are non-compliant with ISO 27001 standards. What should you use?

The correct answer is C. Azure Security Center. Explanation Azure Security Center (now called Microsoft Defender for Cloud) is the correct tool because it includes a Regulatory Compliance dashboard that continuously assesses your Azure configurations and workloads against industry standards and frameworks - including ISO…

Submitted by omar99· Mar 6, 2026Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel

Question

You have an Azure environment. You need to identify any Azure configurations and workloads that are non-compliant with ISO 27001 standards. What should you use?

Options

  • AAzure Sentinel
  • BAzure Active Directory (Azure AD) Identity Protection
  • CAzure Security Center
  • DAzure Advanced Threat Protection (ATP)

How the community answered

(35 responses)
  • A
    6% (2)
  • B
    3% (1)
  • C
    89% (31)
  • D
    3% (1)

Explanation

Explanation

Azure Security Center (now called Microsoft Defender for Cloud) is the correct tool because it includes a Regulatory Compliance dashboard that continuously assesses your Azure configurations and workloads against industry standards and frameworks - including ISO 27001 - and clearly flags any non-compliant resources with actionable recommendations.

Azure Sentinel (A) is a cloud-native SIEM (Security Information and Event Management) tool focused on threat detection, investigation, and response, not compliance assessment against regulatory standards. Azure AD Identity Protection (B) is specifically designed to detect and remediate identity-based risks (e.g., compromised user accounts), making it irrelevant to ISO 27001 configuration compliance. Azure Advanced Threat Protection (D) focuses on identifying advanced cyberattacks and insider threats, particularly in hybrid environments - it is a threat detection tool, not a compliance evaluation tool.

Memory Tip: Think of Security Center = Compliance HQ. It's your central command for checking how well your environment measures up against regulatory benchmarks like ISO 27001, NIST, and PCI-DSS. If a question asks about compliance assessment, Security Center is almost always the answer.

Topics

#Regulatory compliance#ISO 27001#Microsoft Defender for Cloud#Security posture

Community Discussion

No community discussion yet for this question.

Full AZ-500 Practice