Courseiva

SC-200 Manage a security operations environment Practice Question

Your organization uses Microsoft Sentinel and Microsoft Defender XDR. You want to use a Microsoft Copilot for Security to summarize an incident in Microsoft Defender XDR. What is the minimum role required?

⚠ Common exam trap

A common mix-up: candidates confuse the general Azure Reader role with the security-specific Security Reader role, assuming any read-level access is sufficient, but only Security Reader has the precise permissions to access Defender XDR incident data via Copilot.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Security Reader

The minimum role required to use Microsoft Copilot for Security to summarize an incident in Microsoft Defender XDR is Security Reader. This role grants read-only access to security data, including incidents and alerts, which is sufficient for Copilot to retrieve and summarize incident details without requiring write permissions. Higher-privileged roles like Security Administrator or Global Administrator are unnecessary for this read-only operation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Security Administrator

    Why it's wrong here

    The Security Administrator role in Microsoft Entra ID can manage security policies, modify alert settings, and perform write operations across the tenant. For Copilot to summarize incidents in Microsoft Sentinel or Microsoft Defender, only read access to security data is necessary, not management or configuration capabilities. Assigning Security Administrator therefore exceeds the required privilege and violates least-principle; it is not needed for a read-only summarization task.

  • ✗

    Reader

    Why it's wrong here

    The Reader role is an Azure RBAC role that grants read-only access to Azure resources like virtual machines and storage accounts, but it is not an Entra ID security role recognized by Microsoft 365 Defender or Microsoft Copilot. Copilot needs to query security-specific data from Defender XDR and Sentinel, which requires a role like Security Reader that is scoped to security workloads. Since the Reader role cannot even see security incidents or alerts in these portals, it is insufficient for generating summaries.

  • ✓

    Security Reader

    Why this is correct

    Security Reader is an Entra ID role that grants read-only visibility into security settings, alerts, incidents, and threat intelligence across Microsoft 365 Defender and Microsoft Sentinel. Because Microsoft Copilot for Security only needs to retrieve and summarize security information, this read-only access is sufficient and adheres to least privilege. It is the only option from the list that correctly maps to the required permissions for a Copilot summarization task.

  • ✗

    Global Administrator

    Why it's wrong here

    Global Administrator holds unrestricted access to every administrative feature in Microsoft Entra ID, including user management, password resets, and all security workloads. Using this role solely for Copilot's summarization function is grossly over-privileged, since summarization requires no write or management operations. If a Global Administrator credential were compromised, an attacker could take over the entire tenant, presenting significant security risk. Least privilege dictates that this role should never be assigned for a read-only task like summarizing security data.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.