A lock-authority compliance review shows an Azure Policy initiative at 60 percent compliant, and a reviewer treats that figure as Microsoft Defender for Cloud Secure Score. How should the security engineer interpret the initiative percentage?
Select an answer to reveal the explanation.
Short Explanation
That 60 percent is Policy’s report card on the assignment, not Defender’s Secure Score. One meter tracks compliant versus non-compliant resources; the other scores security recommendations. Don’t mash the dials together when the auditor asks.
Full Explanation
Azure Policy compliance describes resource state against assigned policies and initiatives, including compliant, non-compliant, exempt, and conflicting outcomes. Microsoft Defender for Cloud Secure Score measures progress against security recommendations and is a separate posture meter. Confusing the two leads reviewers to report the wrong control family. AZ-500 expects engineers to read Policy compliance on the assignment itself rather than treating it as Secure Score.