Your subscription shows a Secure Score of 35% in Microsoft Defender for Cloud with dozens of recommendations. Several recommendations don’t apply to a specific resource group that hosts third‑party appliances. You must rapidly raise the Secure Score by fixing items at scale and prevent non‑applicable recommendations in that resource group from impacting the score. What should you do? (Choose two)
Choose an answer
Tap an option to check your answer.
Correct answer: Use the Fix action on applicable recommendations to trigger Azure Policy DeployIfNotExists remediation at the selected scope., Create an exemption for the non‑applicable recommendation at the resource group scope using a Waiver (with optional expiration) so it no longer affects Secure Score..
Why this is the answer
To rapidly improve Secure Score, you should leverage the "Fix" action. This action, available for many recommendations in Microsoft Defender for Cloud, triggers Azure Policy DeployIfNotExists remediation, which can automatically resolve security issues across multiple resources, effectively addressing items at scale. For recommendations that are not applicable to the third-party appliances in a specific resource group, creating an exemption with a "Waiver" at the resource group scope is the correct approach. This prevents those non-applicable recommendations from negatively impacting the Secure Score without requiring you to actually fix them. Disabling the built-in security initiative is too broad and would remove all security monitoring. Workflow automation for emails doesn't directly fix issues or impact Secure Score. Moving resources to another subscription is a workaround, not a direct solution for managing recommendations within the existing environment.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed