Courseiva

SC-200 Manage a security operations environment Practice Question

Your organization uses Microsoft Defender XDR (formerly Microsoft 365 Defender). You need to configure role-based access control (RBAC) for the security team. Which TWO built-in roles can be assigned in Microsoft 365 Defender to manage incidents and alerts?

⚠ Common exam trap

A common mix-up: candidates confuse Security Reader (read-only) with Security Operator (read-write for incidents/alerts), or assume Global Administrator is required for incident management, when in fact Security Operator and Security Administrator are the correct roles with the necessary permissions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Security Operator

Security Operator and Security Administrator are the two built-in roles in Microsoft 365 Defender that include permissions to manage incidents and alerts. Security Operator can view and respond to incidents and alerts, while Security Administrator has full access to all security features, including the ability to edit policies and manage incidents. These roles are specifically designed for security operations tasks within Defender XDR.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Global Administrator

    Why it's wrong here

    Global Administrator is technically able to access Microsoft 365 Defender because it holds full control over all Microsoft Entra ID and workload settings, but it is grossly over-privileged for incident response. Using this role violates least-privilege principles, exposes the entire tenant to risk if credentials are compromised, and is explicitly discouraged for security operations. Its breadth of permissions is not needed to triage or mitigate alerts, making it an inappropriate and dangerous choice.

  • ✗

    Compliance Administrator

    Why it's wrong here

    Compliance Administrator is scoped exclusively to regulatory and compliance capabilities such as data lifecycle management, retention policies, and audit log configuration. This role has no granted permissions to view, triage, or modify security incidents or alerts inside Microsoft 365 Defender. Since the task requires hands-on incident response actions, this role is functionally irrelevant and cannot accomplish the objective.

  • ✓

    Security Operator

    Why this is correct

    Security Operator is purpose-built for tier-1 incident response within Microsoft 365 Defender. It can view active incidents, modify their status, assign them to analysts, and perform basic response actions like isolating devices or blocking senders—without granting broader administrative control over security policies or identity management. This role provides the exact permissions required for day-to-day alert handling while adhering to least privilege, making it the correct answer.

  • ✓

    Security Administrator

    Why this is correct

    Security Administrator is a valid and correct choice for managing incidents and alerts, as it inherits all Security Operator permissions and can additionally manage security policies, edit security settings, and configure protection rules. However, it is broader than necessary for routine incident response tasks. While not wrong, it introduces extra permissions that an organization should avoid granting when a more scoped Security Operator role will suffice.

  • ✗

    Security Reader

    Why it's wrong here

    Security Reader provides read-only visibility into incidents, alerts, and security-related policies, meaning it cannot perform any modification, status change, assignment, or response action. This role is useful for reporting and auditing but fails to meet the requirement to actively manage and respond to security incidents. Without write capabilities, it is fundamentally unsuitable for incident response work.

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.