SC-200 · Question #316
You have an Azure subscription named Sub1 that uses Microsoft Defender for Cloud. You need to assign the PCI DSS 4.0 initiative to Sub1 and have the initiative displayed in the Defender for Cloud…
The correct answer is B. Enable the Cloud Security Posture Management (CSPM) plan for the subscription. To assign the PCI DSS 4.0 initiative and access additional regulatory standards in Microsoft Defender for Cloud, the Cloud Security Posture Management (CSPM) plan must first be enabled for the subscription.
Question
You have an Azure subscription named Sub1 that uses Microsoft Defender for Cloud. You need to assign the PCI DSS 4.0 initiative to Sub1 and have the initiative displayed in the Defender for Cloud Regulatory compliance dashboard. From Security policies in the Environment settings, you discover that the option to add more industry and regulatory standards is unavailable. What should you do first?
Options
- AConfigure the Continuous export settings for Log Analytics.
- BEnable the Cloud Security Posture Management (CSPM) plan for the subscription.
- CConfigure the Continuous export settings for Azure Event Hubs.
- DDisable the Microsoft Cloud Security Benchmark (MCSB) assignment.
How the community answered
(33 responses)- A3% (1)
- B73% (24)
- C18% (6)
- D6% (2)
Why each option
To assign the PCI DSS 4.0 initiative and access additional regulatory standards in Microsoft Defender for Cloud, the Cloud Security Posture Management (CSPM) plan must first be enabled for the subscription.
Enabling the Cloud Security Posture Management (CSPM) plan for the subscription is a prerequisite for extending regulatory compliance capabilities in Microsoft Defender for Cloud. Without an enabled CSPM plan, advanced regulatory standards like PCI DSS 4.0 cannot be added or displayed in the compliance dashboard, as these features are part of the enhanced security offerings.
Disabling the Microsoft Cloud Security Benchmark (MCSB) assignment would remove a baseline standard, but it would not enable the ability to add *other* industry and regulatory standards, which requires an enhanced plan.
Concept tested: Defender for Cloud Regulatory Compliance prerequisites
Source: https://learn.microsoft.com/en-us/azure/defender-for-cloud/enable-enhanced-security
Community Discussion
No community discussion yet for this question.