Courseiva

SC-200 Manage a security operations environment Practice Question

Which TWO permissions are required to create and manage automation rules in Microsoft Sentinel?

⚠ Common exam trap

The trap is confusing the Microsoft Sentinel Automation Contributor role with the ability to author automation rules. Automation Contributor is for allowing the Microsoft Sentinel service to run playbooks, not for creating or managing automation rules. The roles that allow a user to create and manage automation rules are Microsoft Sentinel Contributor and Microsoft Sentinel Responder.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Microsoft Sentinel Responder

Microsoft Sentinel Contributor (E) is correct because it grants full management of Microsoft Sentinel resources, including creating, editing, and deleting automation rules. Microsoft Sentinel Responder (C) is also correct because it can manage incidents, run playbooks, and create and edit automation rules. Microsoft Sentinel Automation Contributor (B) is not sufficient for a user to create or manage automation rules; it is used to allow the Microsoft Sentinel service to run playbooks triggered by automation rules. Microsoft Sentinel Reader (A) only allows viewing data and incidents, so it cannot create or modify automation rules. Log Analytics Contributor (D) manages the underlying Log Analytics workspace but does not grant the Sentinel-specific permissions needed for automation rules.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Microsoft Sentinel Reader

    Why it's wrong here

    Read-only.

  • ✗

    Microsoft Sentinel Automation Contributor

    Why it's wrong here

    Specifically for automation rules.

  • ✓

    Microsoft Sentinel Responder

    Why this is correct

    Cannot manage automation rules.

  • ✗

    Log Analytics Contributor

    Why it's wrong here

    Does not include Sentinel automation rule management.

  • ✓

    Microsoft Sentinel Contributor

    Why this is correct

    Full access to Sentinel including automation rules.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.