The board adopted CIS Azure Foundations for the lock-lab subscriptions. What should the engineer do in Microsoft Defender for Cloud?
Select an answer to reveal the explanation.
Short Explanation
CIS is already on the shelf as a built-in standard—turn it on for the lock-lab subscriptions. Do not retype CIS into homemade JSON or file a Sentinel ticket hoping someone else flips the switch.
Full Explanation
Managing compliance standards in Defender for Cloud includes adding or enabling built-in standards such as CIS, PCI, or NIST on the target subscriptions. Rebuilding CIS as custom JSON is unnecessary for a built-in standard. MCSB typically remains the default posture benchmark and should not be dropped solely to “simplify” the view.