nerdexam
Microsoft

SC-100 · Question #130

Your company has an Azure subscription that has enhanced security enabled for Microsoft Defender for Cloud. The company signs a contract with the United States government. You need to review the…

The correct answer is B. From Azure Policy, assign a built-in initiative that has a scope of the subscription. To review NIST 800-53 compliance, you must first assign the built-in NIST SP 800-53 policy initiative at the subscription scope via Azure Policy. An initiative groups related policies together to evaluate compliance against the full regulatory standard.

Design security operations, identity, and compliance capabilities

Question

Your company has an Azure subscription that has enhanced security enabled for Microsoft Defender for Cloud. The company signs a contract with the United States government. You need to review the current subscription for NIST 800-53 compliance. What should you do first?

Options

  • AFrom Defender for Cloud, enable Defender for Cloud plans.
  • BFrom Azure Policy, assign a built-in initiative that has a scope of the subscription.
  • CFrom Microsoft Defender for Cloud Apps, create an access policy for cloud applications.
  • DFrom Azure Policy, assign a built-in policy definition that has a scope of the subscription.

How the community answered

(23 responses)
  • A
    4% (1)
  • B
    78% (18)
  • C
    13% (3)
  • D
    4% (1)

Why each option

To review NIST 800-53 compliance, you must first assign the built-in NIST SP 800-53 policy initiative at the subscription scope via Azure Policy. An initiative groups related policies together to evaluate compliance against the full regulatory standard.

AFrom Defender for Cloud, enable Defender for Cloud plans.

Defender for Cloud enhanced security plans are already enabled per the scenario, so enabling plans again is redundant and is not the required first step for compliance review.

BFrom Azure Policy, assign a built-in initiative that has a scope of the subscription.Correct

Azure Policy includes a built-in initiative for NIST SP 800-53 that bundles hundreds of individual policy definitions into a single compliance assessment. Assigning this initiative at the subscription scope enables Defender for Cloud's regulatory compliance dashboard to evaluate and report on NIST 800-53 posture. An initiative - not a single policy definition - is required because NIST 800-53 encompasses many distinct controls.

CFrom Microsoft Defender for Cloud Apps, create an access policy for cloud applications.

Microsoft Defender for Cloud Apps access policies govern access to SaaS cloud applications and do not assess or enforce NIST 800-53 compliance on Azure subscription resources.

DFrom Azure Policy, assign a built-in policy definition that has a scope of the subscription.

A single built-in policy definition covers only one specific control, whereas NIST 800-53 requires an initiative (a collection of many policies) to assess the full regulatory control set.

Concept tested: Assigning regulatory compliance initiatives in Azure Policy

Source: https://learn.microsoft.com/en-us/azure/governance/policy/samples/nist-sp-800-53-r5

Topics

#Azure Policy#Regulatory Compliance#NIST 800-53#Microsoft Defender for Cloud

Community Discussion

No community discussion yet for this question.

Full SC-100 Practice