SC-200 Manage a security operations environment Practice Question
Which TWO permissions are required to create and manage automation rules in Microsoft Sentinel?
⚠ Common exam trap
The trap is confusing the Microsoft Sentinel Automation Contributor role with the ability to author automation rules. Automation Contributor is for allowing the Microsoft Sentinel service to run playbooks, not for creating or managing automation rules. The roles that allow a user to create and manage automation rules are Microsoft Sentinel Contributor and Microsoft Sentinel Responder.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Sentinel Responder
Microsoft Sentinel Contributor (E) is correct because it grants full management of Microsoft Sentinel resources, including creating, editing, and deleting automation rules. Microsoft Sentinel Responder (C) is also correct because it can manage incidents, run playbooks, and create and edit automation rules. Microsoft Sentinel Automation Contributor (B) is not sufficient for a user to create or manage automation rules; it is used to allow the Microsoft Sentinel service to run playbooks triggered by automation rules. Microsoft Sentinel Reader (A) only allows viewing data and incidents, so it cannot create or modify automation rules. Log Analytics Contributor (D) manages the underlying Log Analytics workspace but does not grant the Sentinel-specific permissions needed for automation rules.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Microsoft Sentinel Reader
Why it's wrong here
Read-only.
- ✗
Microsoft Sentinel Automation Contributor
Why it's wrong here
Specifically for automation rules.
- ✓
Microsoft Sentinel Responder
Why this is correct
Cannot manage automation rules.
- ✗
Log Analytics Contributor
Why it's wrong here
Does not include Sentinel automation rule management.
- ✓
Microsoft Sentinel Contributor
Why this is correct
Full access to Sentinel including automation rules.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.