nerdexam
Microsoft

AZ-500 · Question #401

You have an Azure environment. You need to identify any Azure configurations and workloads that are non-compliant with ISO 27001:2013 standards. What should you use?

The correct answer is B. Microsoft Defender for Cloud. To identify Azure configurations and workloads that are non-compliant with ISO 27001:2013 standards, you should use a service designed for security posture management and regulatory compliance assessment.

Submitted by suresh_in· Mar 6, 2026Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel

Question

You have an Azure environment. You need to identify any Azure configurations and workloads that are non-compliant with ISO 27001:2013 standards. What should you use?

Options

  • AAzure Active Directory (Azure AD) Identity Protection
  • BMicrosoft Defender for Cloud
  • CMicrosoft Defender for Identity
  • DMicrosoft Sentinel

How the community answered

(36 responses)
  • A
    6% (2)
  • B
    92% (33)
  • D
    3% (1)

Why each option

To identify Azure configurations and workloads that are non-compliant with ISO 27001:2013 standards, you should use a service designed for security posture management and regulatory compliance assessment.

AAzure Active Directory (Azure AD) Identity Protection

Azure Active Directory Identity Protection focuses on detecting and remediating identity-based risks, not on assessing the compliance of general Azure configurations or workloads against regulatory standards.

BMicrosoft Defender for CloudCorrect

Microsoft Defender for Cloud provides a regulatory compliance dashboard that offers built-in initiatives for standards like ISO 27001:2013. This service continuously assesses your Azure resources against these benchmarks, identifies non-compliant configurations, and provides actionable recommendations to improve your security posture and meet compliance requirements.

CMicrosoft Defender for Identity

Microsoft Defender for Identity monitors identity activities in hybrid environments to detect advanced threats, rather than auditing cloud resource configurations for regulatory compliance.

DMicrosoft Sentinel

Microsoft Sentinel is a SIEM/SOAR solution primarily used for security information and event management, threat detection, investigation, and response, not for continuous regulatory compliance assessment of infrastructure.

Concept tested: Azure regulatory compliance and security posture

Source: https://learn.microsoft.com/azure/defender-for-cloud/regulatory-compliance-dashboard

Community Discussion

No community discussion yet for this question.

Full AZ-500 Practice