SC-200 Manage a security operations environment Practice Question
Which TWO are required to enable Microsoft Sentinel to use AI-generated incident summaries?
⚠ Common exam trap
Candidates often assume a separate Azure OpenAI service or premium Log Analytics tier is needed, but Microsoft Copilot for Security is a standalone licensed service that handles AI processing without requiring those additional resources.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The Security Reader role assigned to the user
Microsoft Sentinel's AI-generated incident summaries require Microsoft Copilot for Security to be enabled, as this feature leverages Copilot's natural language processing capabilities to summarize incidents. Additionally, the user must have the Security Reader role assigned to access and view these summaries within Sentinel, ensuring proper permissions for security data.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The Security Reader role assigned to the user
Why this is correct
The Security Reader role is a least-privilege RBAC role that grants read-only access to Microsoft Sentinel resources, including incidents, alerts, and the AI-generated summaries. Without this role, Microsoft Copilot for Security may be enabled, but the user will see an authorization error rather than the Copilot-derived narrative in the incident pane. This role is required at minimum to retrieve incident details that Copilot's summarization pipeline consumes and displays.
- ✓
Microsoft Copilot for Security enabled
Why this is correct
Microsoft Copilot for Security is the native Microsoft-managed service that generates AI incident summaries inside Sentinel by synthesizing the incident's alerts, entities, and analytics rules into plain-language text. Enabling and licensing Copilot for Security is a hard prerequisite because the summarization feature is not built into Sentinel's core engine; it relies on Copilot's dedicated AI backend. Without this enablement, the incident summary blade shows no AI narrative regardless of the user's permissions.
- ✗
An Azure OpenAI service instance deployed
Why it's wrong here
Azure OpenAI is not required because Microsoft Copilot for Security is a multi-tenant SaaS offering that runs its own preconfigured AI models on Microsoft's infrastructure. Customers do not need to deploy an Azure OpenAI instance, create an OpenAI resource, or manage model endpoints to get AI incident summaries. The only scenario where Azure OpenAI might appear is if an organization builds a custom bring-your-own-model integration, but that is not part of the standard Copilot for Security enablement path.
- ✗
A Log Analytics workspace with a premium pricing tier
Why it's wrong here
The Log Analytics workspace tier is irrelevant to Copilot's AI summaries; the feature works identically on pay-as-you-go and commitment-tier workspaces because the summary generation is driven by Copilot's capacity units, not by workspace SKU or ingestion volume. The workspace stores the underlying security data, but its pricing tier does not gate the Copilot integration. In fact, the cost of AI summaries is metered through Copilot's own license, not through Log Analytics charges.
- ✗
A Power BI Pro license
Why it's wrong here
Power BI Pro is entirely unrelated to Microsoft Sentinel's incident summaries because Power BI is a separate business intelligence service used for custom dashboards and data visualizations outside the security operations workflow. Sentinel provides its own workbooks and the built-in incident pane for presenting security data, so no Power BI licensing or integration is needed. Confusing Power BI here likely stems from thinking all Microsoft analytics features require it, but Sentinel's AI summaries are delivered inline in the portal.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.