Microsoft Security Operations Analyst Associate SC-200 Practice Question
Your Azure subscription contains a resource group named RG-SecOps. Microsoft Sentinel is enabled on a Log Analytics workspace named SecWork located in RG-SecOps. A security operations (SOC) team named Tier1 must be able to:
View and investigate all incidents in Microsoft Sentinel.
Change an incident's status, owner, or severity.
Manually run existing playbooks that are attached to incidents. The team must NOT be able to edit analytics rules, onboard new data connectors, or change Microsoft Sentinel settings. Which Azure RBAC role assignment provides Tier1 with the least-privilege access required to meet the requirements?
Assign the Microsoft Sentinel Reader role on the SecWork workspace.
Assign the Microsoft Sentinel Contributor role on the SecWork workspace.
Assign the Microsoft Sentinel Responder role on the SecWork workspace and the Logic App Contributor role on RG-SecOps.
The Microsoft Sentinel Responder role allows analysts to view incidents and make basic changes such as updating status, owner, severity, and adding comments or tags. It does not permit modification of analytics rules or connector configurations. To manually run an existing playbook that is linked to an incident, the analyst also needs permission to execute the Logic App. The Logic App Contributor role on the resource group that hosts the playbook grants that permission without allowing the user to create or delete other Azure resources. The other options either do not provide the ability to update incidents or run playbooks (Reader), grant greater-than-necessary privileges to Sentinel configuration (Sentinel Contributor or Azure Contributor), or fail to provide playbook execution rights.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is the Microsoft Sentinel Responder role and why is it key for SOC teams?
Open an interactive chat with Bash
What does the Logic App Contributor role allow, and why is it needed to run playbooks?
Open an interactive chat with Bash
What are the risks of assigning broader roles, such as Sentinel Contributor or Azure Contributor?
Open an interactive chat with Bash
Microsoft Security Operations Analyst Associate SC-200
Manage a security operations environment
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .