Courseiva

SC-200 Manage a security operations environment Practice Question

Which THREE permissions are required for a user to manage Microsoft Sentinel playbooks using Azure Logic Apps? (Choose three.)

⚠ Common exam trap

Watch out — candidates often assume Global Administrator is needed for any automation in Sentinel, but Microsoft specifically scopes playbook management to resource group-level Contributor roles to enforce least privilege and avoid granting tenant-wide admin rights.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Microsoft Sentinel Contributor

Microsoft Sentinel Contributor is required because it grants the necessary permissions to create, update, and delete playbooks within Microsoft Sentinel, which are built on Azure Logic Apps. This role allows the user to manage playbooks as part of the security operations environment, including assigning playbooks to automation rules and incident triggers.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Microsoft Sentinel Contributor

    Why this is correct

    Microsoft Sentinel Contributor is the primary role required to interact with Sentinel playbooks through the portal, APIs, or automation rules. It grants the ability to read and trigger playbooks, as well as view and manage Sentinel incidents and analytics rules. Without this role, the user would not be able to attach playbooks to detections or manually run them from the Sentinel interface, even if they have access to the underlying Logic App.

  • ✓

    Log Analytics Contributor

    Why this is correct

    Log Analytics Contributor provides the necessary access to the Log Analytics workspace that Microsoft Sentinel uses to store and query security data. Playbook actions often rely on workspace data, and this role allows the user to read and write to the workspace, create saved searches, and manage data collection rules. It ensures the user can execute Log Analytics queries and retrieve context needed for playbook logic, which is a prerequisite for managing playbooks effectively.

  • ✗

    Global Administrator in Microsoft Entra ID

    Why it's wrong here

    Global Administrator in Microsoft Entra ID is an extremely privileged directory-wide role that grants control over all Azure resources, user identities, and security settings across the entire tenant. It is not required for managing Sentinel playbooks because playbook operations are scoped to specific Sentinel workspaces, Log Analytics workspaces, and resource groups containing Logic Apps. Assigning this role for playbook management violates the principle of least privilege and introduces a significant security risk, as compromised accounts would have full tenant access.

  • ✗

    Reader on the Logic App

    Why it's wrong here

    The Reader role on the Logic App only allows viewing the Logic App's definition, trigger history, and run logs, but it does not permit any modification or execution control. To manage a playbook, the user must be able to edit the workflow, enable or disable triggers, and change parameters, which requires at least Contributor level access to the Logic App itself or its containing resource group. Therefore, Reader access is insufficient because it cannot perform the management actions that the task demands.

  • ✓

    Contributor on the resource group containing the Logic App

    Why this is correct

    Contributor on the resource group that contains the Logic App grants full management rights to all resources within that group, including the ability to create, edit, delete, and trigger Logic Apps. Since Microsoft Sentinel playbooks are built on Logic Apps, this permission is essential for authoring new playbooks, modifying existing workflow definitions, and setting up connectors. It also enables the user to manage role assignments on the Logic App if necessary, providing a broad but appropriately scoped level of control over the playbook infrastructure.

About these practice questions

This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.