Courseiva

SC-200 Manage a security operations environment Practice Question

Your organization uses Microsoft Defender for Identity. You need to create a role that allows analysts to view security alerts but not modify them. Which built-in role should you assign?

⚠ Common exam trap

Many candidates confuse Security Reader with Security Administrator, assuming the 'Administrator' suffix implies broader access, but the key distinction is that Security Reader is the only built-in role that provides read-only access to security alerts without modification rights.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Security Reader

The Security Reader role (D) is the correct choice because it provides read-only access to security-related features in Microsoft 365 Defender, including the ability to view security alerts from Microsoft Defender for Identity without the ability to modify or respond to them. This aligns directly with the requirement to allow analysts to view alerts but not modify them, as the role grants no write permissions to security configurations or alert states.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Security Administrator

    Why it's wrong here

    Security Administrator can modify security settings and manage alerts, but the requirement is only to view Defender for Identity alerts. This role grants write access to security configurations, making it overly permissive and not aligned with the least-privilege principle for read-only alert viewing.

  • ✗

    Compliance Administrator

    Why it's wrong here

    Compliance Administrator is designed for managing compliance-related features like eDiscovery, retention policies, and data classification. It does not include permissions to access Microsoft Defender for Identity's security alerts, so it cannot fulfill the requirement of viewing these alerts.

  • ✗

    Global Administrator

    Why it's wrong here

    Global Administrator has unrestricted access to all Microsoft 365 services, including Defender for Identity, but assigning this role for merely viewing security alerts violates least-privilege. It grants far more control than needed, including the ability to change identity protection settings and manage other critical services.

  • ✓

    Security Reader

    Why this is correct

    Security Reader provides read-only access to security alerts and reports across Microsoft 365 services, including Microsoft Defender for Identity. This role allows users to view and investigate identity-based alerts without the ability to modify settings, making it the correct minimum-permission role for this task.

About these practice questions

This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.