Question 811 of 1,639
Manage a security operations environmenthardMultiple SelectObjective-mapped

Quick Answer

The answer is Security Administrator, Security Reader, and Security Operator. Security Administrator is the correct primary role because it grants full access to incident management features in Microsoft Defender XDR, including investigating, responding to, and resolving incidents, without requiring global admin permissions. Security Reader provides read-only visibility into incidents and alerts, while Security Operator offers a middle ground with the ability to manage and triage incidents but not modify security settings. On the SC-200 exam, this tests your understanding of the principle of least privilege within Microsoft 365 Defender’s RBAC model—a common trap is confusing Security Reader with Security Operator, as both can view incidents but only the latter can take actions like closing or classifying them. Remember the memory tip: “Reader reads, Operator acts, Admin owns” to quickly recall the escalation of permissions for delegated incident management tasks.

SC-200 Manage a security operations environment Practice Question

This SC-200 practice question tests your understanding of manage a security operations environment. This is a configuration task: choose the command set that satisfies every stated requirement. Small differences — like 'secret' vs 'password' or 'transport input ssh' vs 'all' — change whether the answer is correct. After answering, compare your reasoning against the explanation and wrong-answer breakdown below. Once you have made your selection, read the full explanation to reinforce the concept and understand why each distractor is designed to mislead on exam day.

Your organization uses Microsoft Defender XDR. You need to delegate incident management tasks to a team of analysts without granting full global admin permissions. Which THREE roles in Microsoft 365 Defender should you assign?

Question 1hardmulti select
Full question →

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Security Administrator

Security Administrator is correct because this role in Microsoft 365 Defender provides full access to incident management features, including the ability to investigate, respond to, and resolve incidents, while not granting full global admin permissions. It allows analysts to manage alerts, perform advanced hunting, and configure security settings within the Defender portal, making it suitable for delegated incident management tasks.

Key principle: Answer the scenario, not the keyword: identify the specific constraint before choosing the most familiar-sounding option.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Security Administrator

    Why this is correct

    Can manage security settings and incidents.

    Related concept

    Read the scenario before looking for a memorised answer.

  • Security Operator

    Why this is correct

    Can manage incidents and alerts.

    Related concept

    Read the scenario before looking for a memorised answer.

  • Security Analyst

    Why it's wrong here

    Not a built-in role in Defender XDR; use Security Operator instead.

  • Security Reader

    Why this is correct

    Provides read-only access to incidents.

    Related concept

    Read the scenario before looking for a memorised answer.

  • Compliance Administrator

    Why it's wrong here

    Focuses on compliance, not incident management.

Common exam traps

Common exam trap: answer the scenario, not the keyword

The trap here is that candidates may confuse the non-existent 'Security Analyst' role with the actual 'Security Operator' role, or incorrectly assume that 'Compliance Administrator' includes incident management permissions due to overlapping security and compliance concepts.

Detailed technical explanation

How to think about this question

In Microsoft 365 Defender, role-based access control (RBAC) is managed through Azure AD roles, where Security Administrator and Security Operator have specific permissions for incident management, while Security Reader provides read-only access to incidents and alerts. The Security Operator role, for example, allows viewing and managing incidents but not modifying security policies, which is a key distinction for delegation without full admin rights. In a real-world scenario, assigning Security Reader to junior analysts enables them to monitor incidents without making changes, while Security Administrator handles response actions.

KKey Concepts to Remember

  • Read the scenario before looking for a memorised answer.
  • Find the constraint that changes the correct option.
  • Eliminate answers that are true in general but not in this case.

TExam Day Tips

  • Watch for words such as best, first, most likely and least administrative effort.
  • Review why wrong options are wrong, not only why the correct option is correct.

Key takeaway

Answer the scenario, not the keyword: identify the specific constraint before choosing the most familiar-sounding option.

Real-world example

How this comes up in practice

A company's IT admin needs to give a contractor read-only access to production logs without sharing account credentials. Using role-based access control (RBAC) and temporary scoped permissions — not a permanent shared password — is the correct pattern. Questions like this test whether you can apply least-privilege access across cloud identity services.

What to study next

Got this wrong? Here's your next step.

Identify which exam domain this question belongs to, review the core concept, then practise similar questions from the same domain.

Related practice questions

Related SC-200 practice-question pages

Use these pages to review the topic behind this question. This is how one missed question becomes focused revision.

Practice this exam

Start a free SC-200 practice session

Short sessions build daily habit. Longer sessions build exam-day stamina. Try a timed session to simulate real conditions.

FAQ

Questions learners often ask

What does this SC-200 question test?

Manage a security operations environment — This question tests Manage a security operations environment — Read the scenario before looking for a memorised answer..

What is the correct answer to this question?

The correct answer is: Security Administrator — Security Administrator is correct because this role in Microsoft 365 Defender provides full access to incident management features, including the ability to investigate, respond to, and resolve incidents, while not granting full global admin permissions. It allows analysts to manage alerts, perform advanced hunting, and configure security settings within the Defender portal, making it suitable for delegated incident management tasks.

What should I do if I get this SC-200 question wrong?

Identify which exam domain this question belongs to, review the core concept, then practise similar questions from the same domain.

What is the key concept behind this question?

Read the scenario before looking for a memorised answer.

About these practice questions

Courseiva creates original exam-style practice questions with explanations and wrong-answer analysis. It does not publish real exam questions, exam dumps, or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more ways this is tested on SC-200

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Your organization uses Microsoft Defender XDR (formerly Microsoft 365 Defender). You need to configure role-based access control (RBAC) for the security team. Which TWO built-in roles can be assigned in Microsoft 365 Defender to manage incidents and alerts?

easy
  • A.Global Administrator
  • B.Compliance Administrator
  • C.Security Operator
  • D.Security Administrator
  • E.Security Reader

Why C: Option A and B are correct as these roles can manage incidents and alerts. Option C is wrong because Security Reader is read-only. Option D is wrong because Compliance Administrator manages compliance. Option E is wrong because Global Administrator is too broad.

Last reviewed: Jun 25, 2026

Question Discussion

Share a tip, memory trick, or ask about the reasoning behind this question. Do not post real exam questions, leaked content, braindumps, or copyrighted exam material. Comments are moderated and may be removed without notice.

Loading comments…

Sign in to join the discussion.

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.