A PCI assessor needs evidence for the cardholder lock-lab subscriptions. Which Defender for Cloud capability should the engineer open first?
Select an answer to reveal the explanation.
Short Explanation
The assessor wants a mapped control report, not a homemade diagram or a cost invoice. Open Defender for Cloud regulatory compliance for PCI-DSS and hand over the evidence pack from that dashboard.
Full Explanation
Microsoft Defender for Cloud regulatory compliance maps frameworks such as PCI-DSS, ISO 27001, NIST SP 800-53, CIS, SOC, and HIPAA to Azure resource assessments and reports. That dashboard is the intended evidence surface for assess-against-framework tasks. Sentinel rules, cost exports, and threat-modeling diagrams do not replace the regulatory compliance report.