An architect wants the security governance design to measure the Azure estate against a consistent, Microsoft-authored set of security controls that map to industry frameworks, and to surface where the environment falls short so teams can remediate. Which combination correctly identifies the benchmark and the service that assesses the estate against it?
- AThe Azure Well-Architected Framework, assessed continuously by Microsoft Sentinel analytics rules that score the estate against each pillar.
- BThe Microsoft cloud security benchmark, assessed by Microsoft Purview, which scores the estate against the benchmark and recommends data-protection remediations.
- CThe Microsoft cloud security benchmark, assessed by Microsoft Defender for Cloud, which evaluates the estate against the benchmark controls and reports gaps through secure score. Correct
- DThe enterprise access model, assessed by Microsoft Entra Privileged Identity Management, which scores the estate against the model and reports privileged-access gaps.
Why A is wrong: The Well-Architected Framework is real guidance and Microsoft Sentinel is a real service, so the pairing is tempting, but the framework is a workload design review rather than a control benchmark and Sentinel is a security information and event management tool, so neither role fits.
Why B is wrong: Naming the correct benchmark makes this tempting, but Microsoft Purview governs data classification, compliance and information protection rather than evaluating cloud workload security posture, so it is the wrong assessing service.
Why C is correct: The Microsoft cloud security benchmark is the Microsoft-authored control set mapped to industry frameworks, and Microsoft Defender for Cloud assesses the estate against it and surfaces shortfalls through secure score, which exactly matches the requirement.
Why D is wrong: The enterprise access model and Privileged Identity Management are genuine privileged-access design tools and sound authoritative, but the model addresses administrative tiers rather than a broad control benchmark, so this pairing does not satisfy the requirement.