A financial regulator requires the organisation to demonstrate continuous, control-mapped compliance against a named security standard across two estates at once: its Azure and multicloud infrastructure, and its Microsoft 365 collaboration platform, each shown as a scored posture against the standard's controls. The architect must pick the design surfaces that satisfy this assurance for both estates. Which TWO design choices together meet the requirement? Select TWO.
- AAdd the standard to the Microsoft Defender for Cloud regulatory compliance dashboard so its controls are continuously assessed against the live configuration of the Azure and multicloud infrastructure and scored. Correct
- BStream the Azure activity log and Microsoft 365 audit log into Microsoft Sentinel and build a workbook that visualises how often each of the standard's controls is breached over time.
- CBuild a Microsoft Purview Compliance Manager assessment for the standard so its Microsoft 365 controls each carry an owner, test evidence, and a contribution to a tracked compliance score for the collaboration platform. Correct
- DAssign one Azure Policy initiative containing every control in the standard and treat the resulting policy compliance percentage as the single posture score covering both the infrastructure and the Microsoft 365 estate.
Why A is correct: The Microsoft Defender for Cloud regulatory compliance dashboard maps a standard's controls to continuous assessments of live cloud resource configuration and produces a per-control score, which satisfies the infrastructure half of the regulator's assurance need.
Why B is wrong: Microsoft Sentinel can visualise control breaches in a workbook and is tempting for unified reporting, but a SIEM dashboard counts events rather than maintaining an authoritative control-mapped compliance score for either estate, so it does not deliver the scored posture required.
Why C is correct: A Microsoft Purview Compliance Manager assessment turns the standard's Microsoft 365 controls into owned, evidence-backed improvement actions with a tracked score, which satisfies the collaboration-platform half of the regulator's control-mapped assurance need.
Why D is wrong: An Azure Policy initiative scores Azure resource settings and underpins the dashboard, which makes it a plausible single answer, but it neither assesses Microsoft 365 collaboration controls nor presents the standard's controls as a regulatory posture, so it covers only part of one estate.