SC-200 Manage a security operations environment Practice Question
Your organization uses Microsoft Sentinel and Microsoft Defender XDR. You need to ensure that a new SOC analyst can triage incidents without being able to delete or modify analytics rules. Which role should you assign?
⚠ Common exam trap
Watch out — candidates often confuse Security Reader (which provides broad read-only access across security services) with Sentinel Reader (which is Sentinel-specific), or they assume Security Operator is sufficient because it allows incident management, but it does not grant the Sentinel-specific read permissions needed to view analytics rules without modification capabilities.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Sentinel Reader
Microsoft Sentinel Reader provides read-only access to Sentinel data, including incidents, workbooks, and analytics rules, but explicitly prevents any modifications or deletions. This role is ideal for SOC analysts who need to triage incidents without altering detection configurations. Security Reader and Global Reader lack Sentinel-specific incident triage permissions, while Security Operator allows modification of incidents, which exceeds the required scope.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Security Reader
Why it's wrong here
The Security Reader role is scoped to Microsoft Defender XDR (formerly Microsoft 365 Defender) and grants read-only access to security alerts, global threat intelligence, and Defender incidents. It does not include any permissions on Azure resources such as a Log Analytics workspace, so it cannot access Sentinel analytics rules or incident data stored in Sentinel. To read Sentinel content, you need the Microsoft Sentinel Reader role, which is explicitly designed for that purpose.
- ✓
Microsoft Sentinel Reader
Why this is correct
The Microsoft Sentinel Reader role is an Azure RBAC scoped to the Sentinel workspace, providing full read-only visibility into incidents, analytics rules, workbooks, and threat intelligence. It allows you to view all Sentinel data and configuration settings without permitting any edits, making it the appropriate role for a user who only needs to monitor security events. Because it is purpose-built for Sentinel, it grants direct access to analytics rules and incident details that other read-only Azure roles lack.
- ✗
Global Reader
Why it's wrong here
Global Reader is an Microsoft Entra ID (formerly Azure AD) role that provides read-only access to directory configuration and tenant-wide settings, not to Azure resource data planes. Without an additional Azure RBAC assignment on the Sentinel workspace, a Global Reader cannot open Sentinel incidents or view analytics rules because Sentinel's RBAC is separate from Entra ID roles. Even as a tenant-wide reader, it lacks the workspace-scoped permission required by Sentinel's own resource hierarchy.
- ✗
Security Operator
Why it's wrong here
Security Operator (in Microsoft Entra ID or Microsoft 365 Defender) grants operational write permissions, such as managing alerts, investigating threats, and modifying security policies or settings. It is not a read-only role, so it violates the requirement of read-only access for the user. Moreover, it does not confer the Sentinel-specific RBAC needed to view analytics rules; its incident management capabilities target Defender workloads rather than Sentinel's workspace.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.