A custom Microsoft Defender for Cloud recommendation is created from an Azure Policy definition that emits the recommendation with a custom severity
You have an Azure subscription that uses Microsoft Defender for Cloud. You need to add a custom security recommendation to Defender for Cloud. The recommendation must be assigned the custom severity rating of the subscription. What should you create?
Community Votes
100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Defender for Cloud recommendations are surfaced through Azure Policy; to add a new custom recommendation you author a policy definition, not an exemption, initiative, or assignment. The severity is set on the policy definition.
Custom Defender for Cloud recommendations are backed by Azure Policy. You create a policy definition (typically from the 'Configure a custom recommendation' template) that evaluates your environment and emits a recommendation carrying the custom severity you assign at the subscription scope.
People pick 'initiative definition' or 'assignment', but a custom recommendation is the policy definition itself; initiatives group policies and assignments apply them, neither creates a new recommendation type.
Community Discussion (5 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Microsoft Defender for Cloud builds its recommendations on Azure Policy. Adding a custom recommendation means creating a policy definition (from the custom-recommendation template) that produces the recommendation and carries your chosen custom severity rating. (Option C)Why the Other Options Are Wrong
- Option A (Exemption) excludes a resource from an existing policy; it does not create a recommendation.
- Option B (Initiative definition) groups existing policy definitions but does not itself define a new recommendation.
- Option D (Assignment) applies an existing policy/initiative to a scope; it does not author a new recommendation.