Using Azure Policy to maintain MCSB compliance for deployed App Services

Design solutions for regulatory compliance
Answer Correct answer: C — Azure Policy defines and enforces MCSB compliance rules and reports status for deployed App Services.

You have an Azure subscription. You plan to deploy Azure App Services apps by using Azure DevOps. You need to recommend a solution to ensure that deployed apps maintain compliance with Microsoft cloud security benchmark (MCSB) recommendations. What should you include in the recommendation?

  1. DevOps security in Microsoft Defender for Cloud
  2. Microsoft Defender for App Service
  3. Azure Policy Correct Answer
  4. a branch policy in Azure DevOps

Community Votes

C
100%

100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Azure Policy enforces and audits MCSB compliance across resources including App Services; Defender for App Service is workload protection, DevOps security focuses on code pipelines, and a branch policy governs source control, not runtime MCSB compliance.

To ensure Azure App Services deployed via Azure DevOps remain compliant with Microsoft Cloud Security Benchmark (MCSB) recommendations, use Azure Policy, which defines and enforces compliance rules across resources and reports status.

Choosing a branch policy in Azure DevOps (D) — it controls code/branch rules but does not enforce or report MCSB compliance of the deployed App Service resources.

Community Discussion (4 comments)

RoboCock 👍 1 Selected: C
To ensure that deployed Azure App Services apps maintain compliance with Microsoft Cloud Security Benchmark (MCSB) recommendations, I recommend using Azure Policy. Azure Policy allows you to define and enforce compliance rules across your resources, including Azure App Services. It integrates with Microsoft Defender for Cloud to monitor compliance and provides detailed insights into security baselines.
424ede1 👍 2 Selected: C
Azure Policy https://learn.microsoft.com/en-us/security/benchmark/azure/baselines/app-service-security-baseline
Ali96 👍 2 Selected: C
Azure Policy allows you to enforce rules and guidelines to ensure that deployed apps and resources maintain compliance with Microsoft Cloud Security Benchmark (MCSB) recommendations
676ae1a 👍 2 Selected: C
Respuesta correcta

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Azure Policy lets you define and enforce compliance rules across your resources, including Azure App Services, and integrates with Microsoft Defender for Cloud to monitor adherence to Microsoft Cloud Security Benchmark (MCSB) recommendations, ensuring deployed apps stay compliant.

Why the Other Options Are Wrong

DevOps security in Defender for Cloud (A) focuses on code/pipeline risk, not resource compliance. Defender for App Service (B) provides workload threat protection, not MCSB policy enforcement. A branch policy in Azure DevOps (D) governs source control, not the compliance of deployed resources.

Community Comment Notes

The community favored C (100 votes). Comments cite the App Service security baseline and note that Azure Policy enforces MCSB recommendations across App Services and reports compliance status.

Official Reference

Related Analysis

Practice All SC-100 Questions

Access 110 questions with complete answers and detailed explanations.

View Full SC-100 Practice Test →

← Back to SC-100 Study Guide