- A
Security Administrator
Can manage security settings and incidents.
- B
Security Operator
Can manage incidents and alerts.
- C
Security Analyst
Why wrong: Not a built-in role in Defender XDR; use Security Operator instead.
- D
Security Reader
Provides read-only access to incidents.
- E
Compliance Administrator
Why wrong: Focuses on compliance, not incident management.
Quick Answer
The answer is Security Administrator, Security Reader, and Security Operator. Security Administrator is the correct primary role because it grants full access to incident management features in Microsoft Defender XDR, including investigating, responding to, and resolving incidents, without requiring global admin permissions. Security Reader provides read-only visibility into incidents and alerts, while Security Operator offers a middle ground with the ability to manage and triage incidents but not modify security settings. On the SC-200 exam, this tests your understanding of the principle of least privilege within Microsoft 365 Defender’s RBAC model—a common trap is confusing Security Reader with Security Operator, as both can view incidents but only the latter can take actions like closing or classifying them. Remember the memory tip: “Reader reads, Operator acts, Admin owns” to quickly recall the escalation of permissions for delegated incident management tasks.
SC-200 Manage a security operations environment Practice Question
This SC-200 practice question tests your understanding of manage a security operations environment. This is a configuration task: choose the command set that satisfies every stated requirement. Small differences — like 'secret' vs 'password' or 'transport input ssh' vs 'all' — change whether the answer is correct. After answering, compare your reasoning against the explanation and wrong-answer breakdown below. Once you have made your selection, read the full explanation to reinforce the concept and understand why each distractor is designed to mislead on exam day.
Your organization uses Microsoft Defender XDR. You need to delegate incident management tasks to a team of analysts without granting full global admin permissions. Which THREE roles in Microsoft 365 Defender should you assign?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
Security Administrator
Security Administrator is correct because this role in Microsoft 365 Defender provides full access to incident management features, including the ability to investigate, respond to, and resolve incidents, while not granting full global admin permissions. It allows analysts to manage alerts, perform advanced hunting, and configure security settings within the Defender portal, making it suitable for delegated incident management tasks.
Key principle: Answer the scenario, not the keyword: identify the specific constraint before choosing the most familiar-sounding option.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Security Administrator
Why this is correct
Can manage security settings and incidents.
Related concept
Read the scenario before looking for a memorised answer.
- ✓
Security Operator
Why this is correct
Can manage incidents and alerts.
Related concept
Read the scenario before looking for a memorised answer.
- ✗
Security Analyst
Why it's wrong here
Not a built-in role in Defender XDR; use Security Operator instead.
- ✓
Security Reader
Why this is correct
Provides read-only access to incidents.
Related concept
Read the scenario before looking for a memorised answer.
- ✗
Compliance Administrator
Why it's wrong here
Focuses on compliance, not incident management.
Common exam traps
Common exam trap: answer the scenario, not the keyword
The trap here is that candidates may confuse the non-existent 'Security Analyst' role with the actual 'Security Operator' role, or incorrectly assume that 'Compliance Administrator' includes incident management permissions due to overlapping security and compliance concepts.
Detailed technical explanation
How to think about this question
In Microsoft 365 Defender, role-based access control (RBAC) is managed through Azure AD roles, where Security Administrator and Security Operator have specific permissions for incident management, while Security Reader provides read-only access to incidents and alerts. The Security Operator role, for example, allows viewing and managing incidents but not modifying security policies, which is a key distinction for delegation without full admin rights. In a real-world scenario, assigning Security Reader to junior analysts enables them to monitor incidents without making changes, while Security Administrator handles response actions.
KKey Concepts to Remember
- Read the scenario before looking for a memorised answer.
- Find the constraint that changes the correct option.
- Eliminate answers that are true in general but not in this case.
TExam Day Tips
- Watch for words such as best, first, most likely and least administrative effort.
- Review why wrong options are wrong, not only why the correct option is correct.
Key takeaway
Answer the scenario, not the keyword: identify the specific constraint before choosing the most familiar-sounding option.
Real-world example
How this comes up in practice
A company's IT admin needs to give a contractor read-only access to production logs without sharing account credentials. Using role-based access control (RBAC) and temporary scoped permissions — not a permanent shared password — is the correct pattern. Questions like this test whether you can apply least-privilege access across cloud identity services.
What to study next
Got this wrong? Here's your next step.
Identify which exam domain this question belongs to, review the core concept, then practise similar questions from the same domain.
- →
Manage a security operations environment — study guide chapter
Learn the concepts, then practise the questions
- →
Manage a security operations environment practice questions
Targeted practice on this topic area only
- →
All SC-200 questions
1,639 questions across all exam domains
- →
Microsoft Security Operations Analyst SC-200 study guide
Full concept coverage aligned to exam objectives
- →
SC-200 practice test guide
How to use practice tests most effectively before exam day
Related practice questions
Related SC-200 practice-question pages
Use these pages to review the topic behind this question. This is how one missed question becomes focused revision.
Manage a security operations environment practice questions
Practise SC-200 questions linked to Manage a security operations environment.
Respond to security incidents practice questions
Practise SC-200 questions linked to Respond to security incidents.
Perform threat hunting practice questions
Practise SC-200 questions linked to Perform threat hunting.
Mitigate threats using Microsoft Defender XDR practice questions
Practise SC-200 questions linked to Mitigate threats using Microsoft Defender XDR.
Mitigate threats using Microsoft Defender for Cloud practice questions
Practise SC-200 questions linked to Mitigate threats using Microsoft Defender for Cloud.
Mitigate threats using Microsoft Sentinel practice questions
Practise SC-200 questions linked to Mitigate threats using Microsoft Sentinel.
SC-200 fundamentals practice questions
Practise SC-200 questions linked to SC-200 fundamentals.
SC-200 scenario practice questions
Practise SC-200 questions linked to SC-200 scenario.
SC-200 troubleshooting practice questions
Practise SC-200 questions linked to SC-200 troubleshooting.
Practice this exam
Start a free SC-200 practice session
Short sessions build daily habit. Longer sessions build exam-day stamina. Try a timed session to simulate real conditions.
FAQ
Questions learners often ask
What does this SC-200 question test?
Manage a security operations environment — This question tests Manage a security operations environment — Read the scenario before looking for a memorised answer..
What is the correct answer to this question?
The correct answer is: Security Administrator — Security Administrator is correct because this role in Microsoft 365 Defender provides full access to incident management features, including the ability to investigate, respond to, and resolve incidents, while not granting full global admin permissions. It allows analysts to manage alerts, perform advanced hunting, and configure security settings within the Defender portal, making it suitable for delegated incident management tasks.
What should I do if I get this SC-200 question wrong?
Identify which exam domain this question belongs to, review the core concept, then practise similar questions from the same domain.
What is the key concept behind this question?
Read the scenario before looking for a memorised answer.
About these practice questions
Courseiva creates original exam-style practice questions with explanations and wrong-answer analysis. It does not publish real exam questions, exam dumps, or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more ways this is tested on SC-200
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Your organization uses Microsoft Defender XDR (formerly Microsoft 365 Defender). You need to configure role-based access control (RBAC) for the security team. Which TWO built-in roles can be assigned in Microsoft 365 Defender to manage incidents and alerts?
easy- A.Global Administrator
- B.Compliance Administrator
- ✓ C.Security Operator
- ✓ D.Security Administrator
- E.Security Reader
Why C: Option A and B are correct as these roles can manage incidents and alerts. Option C is wrong because Security Reader is read-only. Option D is wrong because Compliance Administrator manages compliance. Option E is wrong because Global Administrator is too broad.
Last reviewed: Jun 25, 2026
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.
Question Discussion
Share a tip, memory trick, or ask about the reasoning behind this question. Do not post real exam questions, leaked content, braindumps, or copyrighted exam material. Comments are moderated and may be removed without notice.
Sign in to join the discussion.