Microsoft Security, Compliance, and Identity Fundamentals SC-900 Practice Question
A company's security analyst must investigate sign-ins, Conditional Access policy results, and risk detections in the Microsoft Entra admin center but must not be able to modify any settings or reset passwords. Which built-in Microsoft Entra role should you assign to the analyst to meet the requirement while following the principle of least privilege?
The Security Reader role grants read-only access to security-related information in Microsoft Entra ID, including sign-in logs, Conditional Access insights, and Identity Protection risk reports. It does not allow the holder to change policies, manage users, or perform administrative actions, satisfying the requirement.
The Security Operator role allows additional actions such as dismissing or resolving alerts, so it offers more permissions than needed.
Global Reader provides read-only access to all directory settings across Microsoft 365, which exceeds the scope of the analyst's duties and violates least-privilege principles.
Conditional Access Administrator can create or modify Conditional Access policies, which conflicts with the requirement to prevent changes. Therefore, Security Reader is the most appropriate choice.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What does the Security Reader role allow you to do?
Open an interactive chat with Bash
What’s the difference between Security Reader and Security Operator roles?
Open an interactive chat with Bash
Why does the Global Reader role violate least-privilege principles here?
Open an interactive chat with Bash
Microsoft Security, Compliance, and Identity Fundamentals SC-900
Describe the capabilities of Microsoft Entra
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .