Microsoft Security Operations Analyst Associate SC-200 Practice Question

You manage an Azure subscription that contains a Log Analytics workspace connected to Microsoft Sentinel. A new SOC analyst requires access to investigate incidents, change their status or severity, assign them to other analysts, and manually run any automation playbooks already linked to the incidents. The analyst must not be able to create or modify analytics rules, workbooks, new playbooks, or any other workspace configuration. Which Azure built-in role should you assign to the analyst at the resource-group scope to meet these requirements while following the principle of least privilege?

  • Microsoft Sentinel Responder

  • Security Admin

  • Microsoft Sentinel Reader

  • Microsoft Sentinel Contributor

Microsoft Security Operations Analyst Associate SC-200
Manage a security operations environment
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot