SC-200 Manage a security operations environment Practice Question
Your company uses Microsoft Defender XDR. The security team needs to restrict access to the Microsoft Defender portal so that only analysts in the 'Security Operations' group can view incidents. What is the most efficient way to achieve this?
⚠ Common exam trap
Test-takers frequently confuse Microsoft Entra ID roles (like Security Reader) with Defender portal RBAC roles, or assume Conditional Access can control data-level permissions, when in fact only custom Defender roles can restrict incident viewing to a specific group without granting broader privileges.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a custom role in the Microsoft Defender portal with permissions to view incidents and assign it to the Security Operations group.
Microsoft Defender XDR uses role-based access control (RBAC) within the portal itself. Creating a custom role with permissions to view incidents and assigning it to the Security Operations group directly controls access to incident data without affecting broader Microsoft Entra ID roles or requiring Conditional Access policies. This is the most efficient method as it scopes permissions precisely to the Defender portal's incident management functionality.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Assign the Security Operations group the Defender for Endpoint administrator role.
Why it's wrong here
The Defender for Endpoint administrator role is workload-scoped to Microsoft Defender for Endpoint and does not extend to the full Microsoft Defender XDR incident queue. Assigning it would grant broad endpoint management and response capabilities, including isolation and AV policy changes, which exceeds the least-privilege requirement of simply viewing incidents. It also lacks the unified incident-reading permissions needed across email, identity, and cloud apps in Defender XDR.
- ✗
Configure Conditional Access policy to allow only Security Operations group to sign in to the Defender portal.
Why it's wrong here
Conditional Access policies operate at the authentication and session layer, controlling who can sign in and under what conditions (MFA, device compliance, location). They do not govern what a signed-in user is authorized to see inside the Microsoft Defender portal; that is determined by role-based access control. Even if only the Security Operations group could sign in, all other users would still have their existing default permissions, and the group would still lack a scoped role to view incidents. Thus, this approach solves access, not authorization.
- ✗
Assign the Security Operations group the Security Reader role in Microsoft Entra ID.
Why it's wrong here
Security Reader in Microsoft Entra ID is a broad, read-only role that spans many security workloads in the tenant, including Microsoft Defender, Microsoft Purview, and Azure Security Center. It provides more than just incident viewing and is not scoped to the Microsoft Defender portal or to the data the Security Operations team needs. Because it is a global role, assigning it would expose the group to security configuration and telemetry across unrelated services, violating least privilege and making incident handling unnecessarily noisy.
- ✓
Create a custom role in the Microsoft Defender portal with permissions to view incidents and assign it to the Security Operations group.
Why this is correct
Microsoft Defender XDR supports custom roles created in the portal with granular permissions, such as the specific 'View incidents' permission under the Security operations category. Assigning that custom role to the Security Operations group grants them exactly the read-only incident access they need without broadening to endpoint management or unrelated security workloads. This is the precise, least-privilege approach and aligns with Defender XDR's unified RBAC model for isolated access to alert and incident data.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.