Courseiva

SC-200 Manage a security operations environment Practice Question

Your company uses Microsoft Sentinel to monitor security events. You have configured a daily email report that summarizes the top 10 incidents from the past 24 hours. The report is sent using a Logic App playbook triggered by a scheduled query. Recently, the report has stopped being delivered. You check the Logic App run history and see that the last run failed with an HTTP 403 error when connecting to the Microsoft Sentinel API. The Logic App uses a managed identity for authentication. What is the most likely cause of the failure?

⚠ Common exam trap

Test-takers frequently confuse an HTTP 403 (forbidden/permissions) with an HTTP 401 (unauthenticated) or assume the managed identity itself is broken, when in fact the identity is valid but lacks the required RBAC role on the Sentinel workspace.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The managed identity does not have the required permissions on the Sentinel workspace.

The HTTP 403 error indicates a permissions failure when the Logic App attempted to call the Microsoft Sentinel API. Since the Logic App uses a managed identity for authentication, the most likely cause is that the managed identity lacks the necessary role assignments on the Sentinel workspace, such as 'Microsoft Sentinel Contributor' or 'Microsoft Sentinel Reader', which are required to query incidents via the API.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The managed identity does not have the required permissions on the Sentinel workspace.

    Why this is correct

    The managed identity must be assigned the Sentinel Reader RBAC role on the target Log Analytics workspace (or its resource group). Without this role, the Microsoft Sentinel connector in the Logic App returns an authorization error when attempting to read incidents or execute a query, even though the Logic App trigger ran successfully. Permissions are not automatically granted to the managed identity's service principal; they must be explicitly assigned via Azure RBAC.

  • ✗

    The managed identity's client ID has changed.

    Why it's wrong here

    A managed identity's client ID is a stable, immutable GUID that is assigned when the identity is created. For a system-assigned identity it remains constant for the lifetime of the Logic App, and for a user-assigned identity it persists until the identity is explicitly deleted. Azure does not rotate or alter the client ID, so a change would be an external administrative event that would break all authentication, not merely cause a permissions error in the Sentinel workspace.

  • ✗

    The Logic App is not connected to Microsoft Entra ID.

    Why it's wrong here

    A managed identity is by definition a service principal within Microsoft Entra ID, so the Logic App's authentication to Entra ID is inherently present. The failure occurs at the authorization layer: although the identity authenticates successfully, Azure RBAC rejects the request because the required Sentinel Reader role is missing on the workspace. Thus, the issue is not a missing Entra ID connection but the lack of role assignment for that authenticated service principal.

  • ✗

    The scheduled query is no longer running.

    Why it's wrong here

    The scheduled query is the trigger source for the Logic App, and the run history already shows that the Logic App was triggered. If the query had stopped running, no new trigger records would appear at all, so this cannot be the cause of a failure that happens during the playbook execution. The error is occurring in the action step after the trigger, specifically when the Logic App uses its managed identity to call the Microsoft Sentinel API.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.