A security engineer is implementing Microsoft Defender for Cloud's governance capabilities to track remediation of AI security recommendations. The CISO wants to assign owners to each AI-related recommendation and track remediation within a 30-day SLA. Which Defender for Cloud feature provides this governance workflow?
Select an answer to reveal the explanation.
Short Explanation and Infographic
Here's the deal — a is correct because Microsoft Defender for Cloud governance rules allow administrators to assign specific recommendations to named owners with defined remediation due dates (SLA periods). The governance feature tracks assignment status, sends reminder notifications, and provides executive reporting on remediation progress, making it the native tool for this requirement.
Full explanation below image
Full Explanation
A is correct because Microsoft Defender for Cloud governance rules allow administrators to assign specific recommendations to named owners with defined remediation due dates (SLA periods). The governance feature tracks assignment status, sends reminder notifications, and provides executive reporting on remediation progress, making it the native tool for this requirement. B is incorrect because Azure Policy compliance dashboards show compliance status against policy assignments but do not provide an owner assignment and SLA tracking workflow for individual security recommendations. C is incorrect because Sentinel workbooks can visualize data from Defender for Cloud but require custom development to track recommendation resolution times; the native governance rules feature is purpose-built for this. D is incorrect because Azure DevOps work items integration for Defender for Cloud recommendations requires custom configuration and is a development workflow tool, not the native governance tracking mechanism.