SC-200 Manage a security operations environment Practice Question
You are a security analyst for a multinational company with Microsoft Sentinel deployed in a central workspace. You need to grant a team of analysts in the European branch the ability to view incidents and run queries, but they should not be able to modify analytics rules or data connectors. The team already has Microsoft Sentinel Reader role assigned. However, they report that they cannot run KQL queries in the Logs blade. You need to provide the minimum additional permissions. What should you do?
⚠ Common exam trap
Candidates often assume the Microsoft Sentinel Reader role is sufficient for all read operations, but they overlook that running KQL queries in the Logs blade requires separate Log Analytics read permissions, which is a common cross-service dependency tested in SC-200.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Assign the Log Analytics Reader role to the team on the Sentinel workspace.
The Microsoft Sentinel Reader role grants read access to Sentinel data, including incidents, but does not include the ability to run KQL queries in the Logs blade because that requires read permissions on the underlying Log Analytics workspace. The Log Analytics Reader role provides the necessary read access to log data and the ability to execute queries without granting write permissions to analytics rules or data connectors, fulfilling the requirement with minimal privileges.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Assign the Log Analytics Contributor role to the team on the Sentinel workspace.
Why it's wrong here
Assigning the Log Analytics Contributor role grants full read and write access to the workspace, including the ability to create saved searches, modify alert rules, and delete data. A threat-hunting team only needs to execute read-only KQL queries, so this role exceeds least-privilege requirements and introduces unnecessary risk to workspace configuration and log integrity. The team should not receive any write-level permissions in the Log Analytics workspace simply to run queries.
- ✗
Assign the Microsoft Sentinel Contributor role to the team on the Sentinel workspace.
Why it's wrong here
The Microsoft Sentinel Contributor role is intended for administrators who manage Sentinel itself, such as creating and modifying analytics rules, workbooks, automation playbooks, and data connectors. Although it includes read access, its core purpose is administrative control, not ad-hoc query execution. Granting this role to the hunting team would allow them to change detection rules and connector settings, which should remain restricted to security operations administrators. This role is therefore too broad for read-only threat hunting.
- ✓
Assign the Log Analytics Reader role to the team on the Sentinel workspace.
Why this is correct
The Log Analytics Reader role grants the ability to read all data in the Log Analytics workspace and, crucially, to execute KQL queries against that data. Because Microsoft Sentinel stores its security logs in a Log Analytics workspace, this role provides exactly the query capability the hunting team needs. It is a read-only role that does not allow modifications to the workspace or its settings, making it the least-privileged assignment that satisfies the requirement.
- ✗
Assign the Reader role to the team on the Sentinel workspace.
Why it's wrong here
The Azure Reader role is a generic RBAC role that provides read-only access to Azure resources but does not include the specific action required to run Log Analytics queries. The team already has the Sentinel Reader role, which gives visibility into Sentinel resources like incidents and workbooks but not the ability to execute KQL over workspace logs. Assigning the Reader role again would be redundant and still would not enable the necessary workspace query permission. The correct addition is Log Analytics Reader, which grants the specific Microsoft.OperationalInsights/workspaces/query/read action.
Go deeper
Related to this question
About these practice questions
This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.