Microsoft Certified: Azure Security Engineer AssociateManage security operationsMedium

A financial institution requires strict compliance with PCI DSS for its Azure-hosted payment processing applications. They use Azure Security Center (now Microsoft Defender for Cloud) to monitor their environment. To demonstrate compliance, they need to regularly assess their resources against the PCI DSS standard and generate reports. Which Security Center feature should be configured for this purpose?

  1. AFile Integrity Monitoring
  2. BRegulatory Compliance dashboard
  3. CJust-in-Time VM access
  4. DAdaptive Application Controls
Show answer & explanation

Correct answer: B. Regulatory Compliance dashboard

The Regulatory Compliance dashboard in Microsoft Defender for Cloud allows organizations to monitor their compliance against various regulatory standards, including PCI DSS, Azure Security Benchmark, and ISO 27001. It provides a compliance score and detailed reports.

Why the other options are wrong

  • A. File Integrity Monitoring detects changes to critical files but doesn't provide a holistic compliance report against standards.
  • C. Just-in-Time VM access reduces attack surface by limiting port access, not for compliance reporting.
  • D. Adaptive Application Controls help control which applications can run on VMs, not for overall compliance reporting.

Defender for Cloud Regulatory Compliance

The Regulatory Compliance dashboard in Microsoft Defender for Cloud provides a centralized view of an organization's compliance posture against various industry standards and regulatory benchmarks. It assesses resource configurations and provides actionable recommendations to improve compliance.

  • Monitors compliance against standards (e.g., PCI DSS, ISO 27001).
  • Provides a compliance score.
  • Offers detailed reports and recommendations.
  • Integrates with Azure Policy for enforcement.

Memory trick: Regulate your cloud with a dashboard for compliance checks.

More Manage security operations questions