SC-200 Manage a security operations environment Practice Question
Which TWO roles can be used to manage Microsoft Sentinel? (Choose two.)
⚠ Common exam trap
Watch out — candidates often confuse Microsoft Entra ID roles (like Global Administrator or Security Reader) with Sentinel-specific RBAC roles, assuming that broad administrative roles automatically grant Sentinel management capabilities, when in fact Sentinel requires dedicated roles scoped to the Log Analytics workspace.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Sentinel Responder
Microsoft Sentinel Contributor (Option E) is a built-in Azure RBAC role that grants full permissions to create and manage Sentinel resources, including data connectors, analytics rules, and workbooks. Microsoft Sentinel Responder (Option B) is a dedicated role that allows users to manage incidents, perform investigations, and respond to threats without having full write access to the Sentinel workspace. Both roles are specifically designed for managing Microsoft Sentinel operations.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Compliance Administrator
Why it's wrong here
Compliance Administrator is an Microsoft Entra ID administrative role focused on regulatory compliance, data retention, and device compliance policies. It grants no specific permissions to Microsoft Sentinel resources, so it cannot view or manage incidents, playbooks, or analytics rules. Even though it provides broad Microsoft Entra ID management, it is not a Sentinel RBAC role and is therefore ineligible for this task.
- ✓
Microsoft Sentinel Responder
Why this is correct
Microsoft Sentinel Responder is one of the two built-in Sentinel-specific roles that can manage the day-to-day operational tasks within the product. It allows the assigned user to view and manage incidents, triage alerts, and execute playbooks when responding to threats, while intentionally omitting resource-creation permissions. This makes it the appropriate role for security operations analysts who need to act on active detections without reconfiguring the overall Sentinel environment.
- ✗
Security Reader
Why it's wrong here
Security Reader is a read-only role that applies across Microsoft security services, including Microsoft Sentinel. A user with this role can view Sentinel data such as incidents, workbooks, and threat intelligence, but cannot modify, create, or delete any resources, nor can they run playbooks or change incident states. Because the question asks for roles that can manage Sentinel, this role lacks the required write and action permissions.
- ✗
Global Administrator
Why it's wrong here
Global Administrator is a high-privileged Microsoft Entra ID role with unrestricted access to all management features across the tenant, including Sentinel by inheritance. However, it is not a Sentinel-specific role and granting it solely for Sentinel management violates least-privilege security principles. While a Global Administrator would technically be able to perform Sentinel operations, it is not the intended or correct answer because Sentinel offers dedicated, scoped roles for this purpose.
- ✓
Microsoft Sentinel Contributor
Why this is correct
Microsoft Sentinel Contributor is the second Sentinel-specific built-in role, providing full management capabilities for the Sentinel workspace. It can create and update data connectors, analytics rules, workbooks, and automation resources, and it also has the ability to manage incidents. Unlike the Responder role, Contributor is intended for administrators and engineers who configure and maintain the Sentinel environment, not just respond to incidents.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.