SC-200 Manage a security operations environment Practice Question
You are configuring automated responses in Microsoft Sentinel. You have created an automation rule that runs a playbook when an incident is created. The playbook performs actions in Microsoft Entra ID and Microsoft Defender for Cloud. However, the playbook fails with a permissions error. What should you do?
⚠ Common exam trap
Many exam-takers confuse enabling the managed identity feature (Option B) with actually assigning the necessary RBAC roles to that identity, assuming the setting alone grants permissions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Assign the managed identity of the playbook the required roles in Microsoft Entra ID and Defender for Cloud.
The playbook fails with a permissions error because it uses a managed identity to authenticate to Microsoft Entra ID and Microsoft Defender for Cloud, but that identity has not been granted the necessary Azure RBAC roles (e.g., Security Reader, Security Admin) on the target resources. Assigning the required roles to the managed identity directly resolves the authorization failure.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Assign the managed identity of the playbook the required roles in Microsoft Entra ID and Defender for Cloud.
Why this is correct
The playbook runs under its own system-assigned managed identity in Microsoft Entra ID rather than under a user account. For automated responses to succeed, that identity must be explicitly assigned Azure RBAC roles—such as Security Reader or Security Admin on the relevant subscriptions/resource groups—and matching roles in Defender for Cloud. Without these assignments, the Logic App's API calls to fetch alerts or trigger actions are denied, causing the automation rule to fail.
- ✗
Enable 'Allow playbooks to use managed identity' in the Sentinel settings.
Why it's wrong here
Sentinel has a tenant-level toggle that permits playbooks to authenticate via managed identity, but this setting merely authorizes the use of managed identity as an authentication method. It does not grant that identity any actual permissions on Microsoft Entra ID or Defender for Cloud resources. If the managed identity lacks role assignments, enabling this toggle alone will not resolve the failure—the root cause is missing permissions, not the toggle being off.
- ✗
Configure the Microsoft Entra ID connector in Sentinel with delegated permissions.
Why it's wrong here
The Microsoft Entra ID connector in Sentinel is a data connector used to ingest sign-in and audit logs into the workspace, and its delegated permissions handle log collection only. Playbook execution does not use this connector; instead, the Logic App authenticates directly with its managed identity when calling Microsoft Graph or Defender for Cloud APIs. Configuring delegated permissions on this connector has no effect on the permissions available to the playbook at runtime.
- ✗
Grant the security analyst's account Contributor permissions on the automation rule.
Why it's wrong here
Automation rules are triggered by Sentinel and invoke the playbook, but the playbook's actions run under the Logic App's managed identity, not under the security analyst's account. Granting Contributor on the automation rule only affects the analyst's ability to modify and manage that rule, not the runtime privileges of the playbook. The managed identity itself still requires role assignments to execute actions in Microsoft Entra ID and Defender for Cloud, so this action does not address the failure.
Visual reference
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
About these practice questions
This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.