Courseiva

SC-200 Manage a security operations environment Practice Question

You are configuring automated responses in Microsoft Sentinel. You have created an automation rule that runs a playbook when an incident is created. The playbook performs actions in Microsoft Entra ID and Microsoft Defender for Cloud. However, the playbook fails with a permissions error. What should you do?

⚠ Common exam trap

Many exam-takers confuse enabling the managed identity feature (Option B) with actually assigning the necessary RBAC roles to that identity, assuming the setting alone grants permissions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Assign the managed identity of the playbook the required roles in Microsoft Entra ID and Defender for Cloud.

The playbook fails with a permissions error because it uses a managed identity to authenticate to Microsoft Entra ID and Microsoft Defender for Cloud, but that identity has not been granted the necessary Azure RBAC roles (e.g., Security Reader, Security Admin) on the target resources. Assigning the required roles to the managed identity directly resolves the authorization failure.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Assign the managed identity of the playbook the required roles in Microsoft Entra ID and Defender for Cloud.

    Why this is correct

    The playbook runs under its own system-assigned managed identity in Microsoft Entra ID rather than under a user account. For automated responses to succeed, that identity must be explicitly assigned Azure RBAC roles—such as Security Reader or Security Admin on the relevant subscriptions/resource groups—and matching roles in Defender for Cloud. Without these assignments, the Logic App's API calls to fetch alerts or trigger actions are denied, causing the automation rule to fail.

  • ✗

    Enable 'Allow playbooks to use managed identity' in the Sentinel settings.

    Why it's wrong here

    Sentinel has a tenant-level toggle that permits playbooks to authenticate via managed identity, but this setting merely authorizes the use of managed identity as an authentication method. It does not grant that identity any actual permissions on Microsoft Entra ID or Defender for Cloud resources. If the managed identity lacks role assignments, enabling this toggle alone will not resolve the failure—the root cause is missing permissions, not the toggle being off.

  • ✗

    Configure the Microsoft Entra ID connector in Sentinel with delegated permissions.

    Why it's wrong here

    The Microsoft Entra ID connector in Sentinel is a data connector used to ingest sign-in and audit logs into the workspace, and its delegated permissions handle log collection only. Playbook execution does not use this connector; instead, the Logic App authenticates directly with its managed identity when calling Microsoft Graph or Defender for Cloud APIs. Configuring delegated permissions on this connector has no effect on the permissions available to the playbook at runtime.

  • ✗

    Grant the security analyst's account Contributor permissions on the automation rule.

    Why it's wrong here

    Automation rules are triggered by Sentinel and invoke the playbook, but the playbook's actions run under the Logic App's managed identity, not under the security analyst's account. Granting Contributor on the automation rule only affects the analyst's ability to modify and manage that rule, not the runtime privileges of the playbook. The managed identity itself still requires role assignments to execute actions in Microsoft Entra ID and Defender for Cloud, so this action does not address the failure.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.