Enabling the Defender for Cloud CSPM plan so regulatory compliance standards can be added

Topic 5
Answer Correct answer: B — Enabling the CSPM plan unlocks the ability to add regulatory compliance standards such as PCI DSS 4.0.

You have an Azure subscription named Sub1 that uses Microsoft Defender for Cloud. You need to assign the PCI DSS 4.0 initiative to Sub1 and have the initiative displayed in the Defender for Cloud Regulatory compliance dashboard. From Security policies in the Environment settings, you discover that the option to add more industry and regulatory standards is unavailable. What should you do first?

  1. Configure the Continuous export settings for Log Analytics.
  2. Enable the Cloud Security Posture Management (CSPM) plan for the subscription. Correct Answer
  3. Configure the Continuous export settings for Azure Event Hubs.
  4. Disable the Microsoft Cloud Security Benchmark (MCSB) assignment.

Community Votes

B
100%

100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Regulatory compliance initiatives in Defender for Cloud are a feature of the CSPM plan; without CSPM enabled, the control to add industry and regulatory standards is greyed out, so enabling CSPM is the prerequisite first step.

To assign the PCI DSS 4.0 initiative in Defender for Cloud, the option to add standards is unavailable until the Cloud Security Posture Management (CSPM) plan is enabled for the subscription, which unlocks regulatory compliance assessments.

Configuring continuous export or disabling the Microsoft Cloud Security Benchmark — neither enables the add-standards control; the blocker is the missing CSPM plan, not export or the existing MCSB assignment.

Community Discussion (4 comments)

sapphire 👍 1 Selected: B
correct answer
talosDevbot 👍 2 Selected: B
Enable the Defender CSPM plan for the Regulatory Compliance Assessments feature B
g_man_rap 👍 2 Selected: B
Option B: Enable the Cloud Security Posture Management (CSPM) plan for the subscription. Correct. The Cloud Security Posture Management (CSPM) plan in Microsoft Defender for Cloud includes features like regulatory compliance tracking. If the CSPM plan is not enabled, you won't have access to add or manage regulatory compliance initiatives, which is why the option is unavailable in your current settings.
rsanx42 👍 3 Selected: B
B. Enable CSPM https://learn.microsoft.com/en-us/azure/defender-for-cloud/concept-cloud-security-posture-management

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

In Microsoft Defender for Cloud, adding and managing regulatory compliance standards (such as PCI DSS 4.0) requires the Cloud Security Posture Management (CSPM) plan to be enabled on the subscription. When CSPM is not enabled, the option to add more industry and regulatory standards is unavailable, so enabling CSPM is the correct first step.

Why the Other Options Are Wrong

Continuous export to Log Analytics (A) or Event Hubs (C) is for streaming alerts/assessments out of Defender for Cloud, not for enabling compliance standards. Disabling the Microsoft Cloud Security Benchmark assignment (D) does not unlock the add-standards control.

Community Comment Notes

The community is unanimous (B 100). rsanx42, talosDevbot, and g_man_rap cite the CSPM concept documentation, confirming that enabling the CSPM plan is required before regulatory compliance initiatives can be added.

Official Reference

Related Analysis

Practice All SC-200 Questions

Access 80 questions with complete answers and detailed explanations.

View Full SC-200 Practice Test →

← Back to SC-200 Study Guide