nerdexam
Microsoft

SC-100 · Question #177

Your company has an Azure subscription that has enhanced security enabled for Microsoft Defender for Cloud. The company signs a contract with the United States government. You need to review the…

The correct answer is A. From Defender for Cloud, add a regulatory compliance standard. Before NIST 800-53 compliance data is visible in Defender for Cloud, the standard must be explicitly added to the regulatory compliance dashboard so its controls can be mapped and assessed.

Design security operations, identity, and compliance capabilities

Question

Your company has an Azure subscription that has enhanced security enabled for Microsoft Defender for Cloud. The company signs a contract with the United States government. You need to review the current subscription for NIST 800-53 compliance. What should you do first?

Options

  • AFrom Defender for Cloud, add a regulatory compliance standard.
  • BFrom Azure Policy, assign a built-in policy definition that has a scope of the subscription.
  • CFrom Defender for Cloud, review the Azure security baseline for audit report.
  • DFrom Microsoft Defender for Cloud Apps, create an access policy for cloud applications.

How the community answered

(23 responses)
  • A
    74% (17)
  • B
    4% (1)
  • C
    4% (1)
  • D
    17% (4)

Why each option

Before NIST 800-53 compliance data is visible in Defender for Cloud, the standard must be explicitly added to the regulatory compliance dashboard so its controls can be mapped and assessed.

AFrom Defender for Cloud, add a regulatory compliance standard.Correct

Defender for Cloud's regulatory compliance dashboard allows administrators to add industry and government frameworks including NIST SP 800-53. Once added, Defender for Cloud maps existing resource assessments to NIST control requirements and surfaces a pass/fail view of the subscription's compliance posture, which is the prerequisite step before any meaningful review can begin.

BFrom Azure Policy, assign a built-in policy definition that has a scope of the subscription.

Assigning a built-in Azure Policy definition can enforce individual policy rules but does not produce the unified NIST 800-53 control mapping and compliance score view that the regulatory compliance dashboard provides.

CFrom Defender for Cloud, review the Azure security baseline for audit report.

The Azure security baseline audit report in Defender for Cloud covers Microsoft's own benchmark controls and is not equivalent to a NIST 800-53 compliance assessment.

DFrom Microsoft Defender for Cloud Apps, create an access policy for cloud applications.

Defender for Cloud Apps access policies govern real-time session-level access to cloud applications and are unrelated to evaluating infrastructure compliance against a regulatory framework.

Concept tested: Adding regulatory compliance standards in Defender for Cloud

Source: https://learn.microsoft.com/en-us/azure/defender-for-cloud/regulatory-compliance-dashboard

Topics

#Regulatory Compliance#Defender for Cloud#NIST 800-53#Compliance Assessment

Community Discussion

No community discussion yet for this question.

Full SC-100 Practice