Microsoft Certified: Azure Security Engineer AssociateManage security operationsHard
A global organization uses Microsoft Defender for Cloud to manage its security posture across multiple Azure subscriptions and AWS accounts. They need to ensure that their custom regulatory compliance standards, which include specific controls not covered by default standards, are continuously assessed. What is the most efficient way to incorporate these custom standards into Defender for Cloud?
- ACreate a custom regulatory compliance standard within Defender for Cloud.
- BManually check resources against custom standards.
- CCreate a custom policy initiative in Azure Policy and assign it.
- DExport Defender for Cloud recommendations and analyze them externally.
Show answer & explanationAnswer & explanation
Correct answer: A. Create a custom regulatory compliance standard within Defender for Cloud.
Microsoft Defender for Cloud allows creating custom regulatory compliance standards by importing existing Azure Policy initiatives. This directly integrates custom controls into the Defender for Cloud compliance dashboard.
Why the other options are wrong
- B. Manual checks are inefficient and do not provide continuous assessment or integration with Defender for Cloud.
- C. While a custom policy initiative is a component, it needs to be integrated into Defender for Cloud as a custom regulatory standard for unified reporting.
- D. Exporting and analyzing externally lacks the continuous, integrated assessment and reporting capabilities of Defender for Cloud.
Defender for Cloud Custom Compliance
Microsoft Defender for Cloud enables organizations to define and assess custom regulatory compliance standards by integrating custom Azure Policy initiatives directly into its compliance dashboard.
- Extends Defender for Cloud's compliance capabilities.
- Integrates custom Azure Policy initiatives.
- Provides unified reporting with built-in standards.
Memory trick: Custom standards let you 'write' your own rules.