SC-200 Manage a security operations environment Practice Question
Your organization uses Microsoft Defender XDR (formerly Microsoft 365 Defender). You need to configure role-based access control (RBAC) for the security team. Which TWO built-in roles can be assigned in Microsoft 365 Defender to manage incidents and alerts?
⚠ Common exam trap
A common mix-up: candidates confuse Security Reader (read-only) with Security Operator (read-write for incidents/alerts), or assume Global Administrator is required for incident management, when in fact Security Operator and Security Administrator are the correct roles with the necessary permissions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Security Operator
Security Operator and Security Administrator are the two built-in roles in Microsoft 365 Defender that include permissions to manage incidents and alerts. Security Operator can view and respond to incidents and alerts, while Security Administrator has full access to all security features, including the ability to edit policies and manage incidents. These roles are specifically designed for security operations tasks within Defender XDR.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Global Administrator
Why it's wrong here
Global Administrator is technically able to access Microsoft 365 Defender because it holds full control over all Microsoft Entra ID and workload settings, but it is grossly over-privileged for incident response. Using this role violates least-privilege principles, exposes the entire tenant to risk if credentials are compromised, and is explicitly discouraged for security operations. Its breadth of permissions is not needed to triage or mitigate alerts, making it an inappropriate and dangerous choice.
- ✗
Compliance Administrator
Why it's wrong here
Compliance Administrator is scoped exclusively to regulatory and compliance capabilities such as data lifecycle management, retention policies, and audit log configuration. This role has no granted permissions to view, triage, or modify security incidents or alerts inside Microsoft 365 Defender. Since the task requires hands-on incident response actions, this role is functionally irrelevant and cannot accomplish the objective.
- ✓
Security Operator
Why this is correct
Security Operator is purpose-built for tier-1 incident response within Microsoft 365 Defender. It can view active incidents, modify their status, assign them to analysts, and perform basic response actions like isolating devices or blocking senders—without granting broader administrative control over security policies or identity management. This role provides the exact permissions required for day-to-day alert handling while adhering to least privilege, making it the correct answer.
- ✓
Security Administrator
Why this is correct
Security Administrator is a valid and correct choice for managing incidents and alerts, as it inherits all Security Operator permissions and can additionally manage security policies, edit security settings, and configure protection rules. However, it is broader than necessary for routine incident response tasks. While not wrong, it introduces extra permissions that an organization should avoid granting when a more scoped Security Operator role will suffice.
- ✗
Security Reader
Why it's wrong here
Security Reader provides read-only visibility into incidents, alerts, and security-related policies, meaning it cannot perform any modification, status change, assignment, or response action. This role is useful for reporting and auditing but fails to meet the requirement to actively manage and respond to security incidents. Without write capabilities, it is fundamentally unsuitable for incident response work.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.