Microsoft Certified: DevOps Engineer ExpertDevelop a security and compliance planHard
A highly regulated organization needs to ensure that all Azure resources are provisioned according to strict internal security baselines and external compliance standards (e.g., ISO 27001, HIPAA). They want to prevent non-compliant resources from being deployed and automatically remediate any deviations from the baseline. Which Azure service should be used to achieve this proactive compliance enforcement?
- AAzure Monitor
- BAzure Security Center (now Defender for Cloud)
- CAzure Policy
- DAzure Advisor
Show answer & explanationAnswer & explanation
Correct answer: C. Azure Policy
Azure Policy is specifically designed for proactive compliance enforcement. It allows organizations to define policies that audit, enforce, and automatically remediate resource configurations, ensuring that all deployed resources adhere to specified security baselines and compliance standards. This includes preventing non-compliant deployments and fixing deviations.
Why the other options are wrong
- A. Azure Monitor is for collecting, analyzing, and acting on telemetry data, not for proactive policy enforcement on resource deployments.
- B. Azure Security Center (Defender for Cloud) provides security posture management and threat protection, and it uses Azure Policy for some of its recommendations, but Azure Policy itself is the enforcement engine for 'preventing non-compliant resources from being deployed' and 'automatically remediating deviations'.
- D. Azure Advisor provides recommendations for optimizing Azure resources, but it doesn't enforce or remediate compliance automatically.
Azure Policy for Compliance
A service that enables organizations to define and apply rules (policies) to Azure resources to enforce organizational standards, assess compliance, and automatically remediate non-compliant resources.
- Proactive enforcement (prevent, audit, remediate).
- Ensures adherence to security baselines and compliance standards.
- Applies at management group, subscription, or resource group scope.
Memory trick: Azure Policy 'Sets the Rules' to 'Keep Everything in Line'.