Enabling the Defender for Cloud CSPM plan so regulatory compliance standards can be added
You have an Azure subscription named Sub1 that uses Microsoft Defender for Cloud. You need to assign the PCI DSS 4.0 initiative to Sub1 and have the initiative displayed in the Defender for Cloud Regulatory compliance dashboard. From Security policies in the Environment settings, you discover that the option to add more industry and regulatory standards is unavailable. What should you do first?
Community Votes
100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Regulatory compliance initiatives in Defender for Cloud are a feature of the CSPM plan; without CSPM enabled, the control to add industry and regulatory standards is greyed out, so enabling CSPM is the prerequisite first step.
To assign the PCI DSS 4.0 initiative in Defender for Cloud, the option to add standards is unavailable until the Cloud Security Posture Management (CSPM) plan is enabled for the subscription, which unlocks regulatory compliance assessments.
Configuring continuous export or disabling the Microsoft Cloud Security Benchmark — neither enables the add-standards control; the blocker is the missing CSPM plan, not export or the existing MCSB assignment.
Community Discussion (4 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
In Microsoft Defender for Cloud, adding and managing regulatory compliance standards (such as PCI DSS 4.0) requires the Cloud Security Posture Management (CSPM) plan to be enabled on the subscription. When CSPM is not enabled, the option to add more industry and regulatory standards is unavailable, so enabling CSPM is the correct first step.Why the Other Options Are Wrong
Continuous export to Log Analytics (A) or Event Hubs (C) is for streaming alerts/assessments out of Defender for Cloud, not for enabling compliance standards. Disabling the Microsoft Cloud Security Benchmark assignment (D) does not unlock the add-standards control.Community Comment Notes
The community is unanimous (B 100). rsanx42, talosDevbot, and g_man_rap cite the CSPM concept documentation, confirming that enabling the CSPM plan is required before regulatory compliance initiatives can be added.Official Reference
Related Analysis
Practice All SC-200 Questions
Access 80 questions with complete answers and detailed explanations.
View Full SC-200 Practice Test →