Courseiva

SC-200 Manage a security operations environment Practice Question

Which TWO actions require the Global Administrator role in Microsoft 365?

⚠ Common exam trap

Test-takers frequently confuse 'tenant-wide settings' with workload-specific configurations, assuming that any security or compliance task requires Global Administrator, when in fact Microsoft has delegated many such tasks to specialized roles like Security Administrator or Compliance Administrator.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure tenant-wide settings in Microsoft 365

Configuring tenant-wide settings in Microsoft 365 requires the Global Administrator role because these settings affect the entire organization, including security, compliance, and user management. Only the Global Administrator has the broadest permissions to modify such high-level configurations, as defined by Microsoft's role-based access control (RBAC) model.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create a data loss prevention (DLP) policy in Microsoft Purview

    Why it's wrong here

    Creating a data loss prevention (DLP) policy in Microsoft Purview does not require the Global Administrator role; the Compliance Administrator role has sufficient permissions to create and manage DLP policies. DLP policies are scoped to the compliance and information protection administration area, so a user with Compliance Admin rights can define policy rules, conditions, and actions without broader tenant-wide administrative privileges.

  • ✗

    Create a custom role in Microsoft Defender XDR

    Why it's wrong here

    Creating a custom role in Microsoft Defender XDR falls under the Security Administrator role's responsibilities, not Global Admin. Security Administrators can define custom roles within the Defender RBAC model to grant granular permissions for threat protection features. This is a security-specific configuration that does not require the tenant-wide scope of Global Administrator.

  • ✗

    View the Microsoft 365 Defender incident queue

    Why it's wrong here

    Viewing the Microsoft 365 Defender incident queue is a read-only task that the Security Reader role is explicitly designed for. Security Readers have access to incident details, alerts, and threat analytics without needing the ability to modify settings. The Global Administrator role is not required to view incidents; it is a privileged role for changes, not for basic visibility.

  • ✓

    Configure tenant-wide settings in Microsoft 365

    Why this is correct

    Configuring tenant-wide settings in Microsoft 365 requires the Global Administrator role because these settings affect the entire organization, such as organizational profile, privacy preferences, and integration options. Only Global Administrators have the necessary authorization to modify settings that apply to all users and services across the tenant, ensuring central control and compliance with organizational governance.

  • ✓

    Manage roles and administrators in Microsoft Entra ID

    Why this is correct

    Managing roles and administrators in Microsoft Entra ID is a core Global Administrator function because it controls delegation of administrative permissions across the tenant. Only Global Administrators can assign privileged roles like Global Admin, Security Admin, or Compliance Admin to other users. This ensures that the ability to grant or revoke administrative access remains centralized and tightly controlled.

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.