SC-200 Manage a security operations environment Practice Question
Your organization uses Microsoft Sentinel and Microsoft Defender XDR. You want to use a Microsoft Copilot for Security to summarize an incident in Microsoft Defender XDR. What is the minimum role required?
⚠ Common exam trap
A common mix-up: candidates confuse the general Azure Reader role with the security-specific Security Reader role, assuming any read-level access is sufficient, but only Security Reader has the precise permissions to access Defender XDR incident data via Copilot.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Security Reader
The minimum role required to use Microsoft Copilot for Security to summarize an incident in Microsoft Defender XDR is Security Reader. This role grants read-only access to security data, including incidents and alerts, which is sufficient for Copilot to retrieve and summarize incident details without requiring write permissions. Higher-privileged roles like Security Administrator or Global Administrator are unnecessary for this read-only operation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Security Administrator
Why it's wrong here
The Security Administrator role in Microsoft Entra ID can manage security policies, modify alert settings, and perform write operations across the tenant. For Copilot to summarize incidents in Microsoft Sentinel or Microsoft Defender, only read access to security data is necessary, not management or configuration capabilities. Assigning Security Administrator therefore exceeds the required privilege and violates least-principle; it is not needed for a read-only summarization task.
- ✗
Reader
Why it's wrong here
The Reader role is an Azure RBAC role that grants read-only access to Azure resources like virtual machines and storage accounts, but it is not an Entra ID security role recognized by Microsoft 365 Defender or Microsoft Copilot. Copilot needs to query security-specific data from Defender XDR and Sentinel, which requires a role like Security Reader that is scoped to security workloads. Since the Reader role cannot even see security incidents or alerts in these portals, it is insufficient for generating summaries.
- ✓
Security Reader
Why this is correct
Security Reader is an Entra ID role that grants read-only visibility into security settings, alerts, incidents, and threat intelligence across Microsoft 365 Defender and Microsoft Sentinel. Because Microsoft Copilot for Security only needs to retrieve and summarize security information, this read-only access is sufficient and adheres to least privilege. It is the only option from the list that correctly maps to the required permissions for a Copilot summarization task.
- ✗
Global Administrator
Why it's wrong here
Global Administrator holds unrestricted access to every administrative feature in Microsoft Entra ID, including user management, password resets, and all security workloads. Using this role solely for Copilot's summarization function is grossly over-privileged, since summarization requires no write or management operations. If a Global Administrator credential were compromised, an attacker could take over the entire tenant, presenting significant security risk. Least privilege dictates that this role should never be assigned for a read-only task like summarizing security data.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.