Courseiva

SC-200 Manage a security operations environment Practice Question

Which TWO roles are included in Microsoft Sentinel built-in roles? (Choose two.)

⚠ Common exam trap

Test-takers frequently confuse the 'Operator' role name with a valid built-in role, or assume 'Administrator' is a built-in role when the correct term is 'Contributor', leading them to select incorrect options that sound plausible but do not exist in Sentinel's RBAC model.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Microsoft Sentinel Responder

Microsoft Sentinel Responder is a built-in role that grants permissions to respond to incidents, including the ability to update incidents, dismiss alerts, and take response actions. This role is designed for security operations center (SOC) analysts who need to triage and remediate threats without full administrative access.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Microsoft Sentinel Responder

    Why this is correct

    Microsoft Sentinel Responder is a built-in role intended for security operations analysts who need to triage and manage incidents. It grants permissions to view and act on incidents, including changing their status, assigning ownership, and adding comments, while deliberately excluding write access to Sentinel configuration such as analytics rules or data connectors. This role supports day-to-day incident response without enabling broad changes to the Sentinel environment.

  • ✗

    Microsoft Sentinel Administrator

    Why it's wrong here

    No built-in role named 'Microsoft Sentinel Administrator' exists; the highest built-in role is Microsoft Sentinel Contributor, which provides full read-write permissions across Sentinel resources, including analytics rules, watchlists, and playbooks. The term 'Administrator' might be misconstrued from Azure RBAC's Owner or Contributor levels, but Sentinel's predefined roles are limited to Reader, Responder, and Contributor. Choosing this role would be incorrect because it is not a valid, predefined Sentinel RBAC role.

  • ✓

    Microsoft Sentinel Reader

    Why this is correct

    Microsoft Sentinel Reader is a built-in role that offers read-only access to all Sentinel resources, including incidents, workbooks, analytics rules, and threat intelligence. Users with this role can view and search data, analyze incidents, and review configuration, but they cannot make any changes, such as modifying rules or updating incident status. This role is ideal for auditors, viewers, and stakeholders who need visibility without operational control.

  • ✗

    Microsoft Sentinel Operator

    Why it's wrong here

    There is no predefined RBAC role called 'Microsoft Sentinel Operator' within Sentinel's built-in role catalog. The closest custom capability might be an operational role, but Sentinel's built-in roles are strictly limited to Reader, Responder, and Contributor, with optional Playbook Operator for running playbooks only. Consequently, this option is incorrect because the role does not exist in Azure's built-in Sentinel role definitions.

  • ✗

    Global Administrator

    Why it's wrong here

    Global Administrator is a Microsoft Entra ID (formerly Azure AD) role that grants tenant-wide control over identity, security, and all Azure resources, but it is not a built-in Sentinel role. While a Global Administrator can access Sentinel by being explicitly assigned a Sentinel role or through Microsoft Entra ID permissions, the role itself does not appear in Sentinel's RBAC role list. Since it is a tenant-level identity role, it is not one of the two correct Sentinel-specific built-in roles.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.