Courseiva

SC-200 Manage a security operations environment Practice Question

Your organization uses Microsoft Sentinel and Microsoft Defender XDR. You need to ensure that a new SOC analyst can triage incidents without being able to delete or modify analytics rules. Which role should you assign?

⚠ Common exam trap

Watch out — candidates often confuse Security Reader (which provides broad read-only access across security services) with Sentinel Reader (which is Sentinel-specific), or they assume Security Operator is sufficient because it allows incident management, but it does not grant the Sentinel-specific read permissions needed to view analytics rules without modification capabilities.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Microsoft Sentinel Reader

Microsoft Sentinel Reader provides read-only access to Sentinel data, including incidents, workbooks, and analytics rules, but explicitly prevents any modifications or deletions. This role is ideal for SOC analysts who need to triage incidents without altering detection configurations. Security Reader and Global Reader lack Sentinel-specific incident triage permissions, while Security Operator allows modification of incidents, which exceeds the required scope.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Security Reader

    Why it's wrong here

    The Security Reader role is scoped to Microsoft Defender XDR (formerly Microsoft 365 Defender) and grants read-only access to security alerts, global threat intelligence, and Defender incidents. It does not include any permissions on Azure resources such as a Log Analytics workspace, so it cannot access Sentinel analytics rules or incident data stored in Sentinel. To read Sentinel content, you need the Microsoft Sentinel Reader role, which is explicitly designed for that purpose.

  • ✓

    Microsoft Sentinel Reader

    Why this is correct

    The Microsoft Sentinel Reader role is an Azure RBAC scoped to the Sentinel workspace, providing full read-only visibility into incidents, analytics rules, workbooks, and threat intelligence. It allows you to view all Sentinel data and configuration settings without permitting any edits, making it the appropriate role for a user who only needs to monitor security events. Because it is purpose-built for Sentinel, it grants direct access to analytics rules and incident details that other read-only Azure roles lack.

  • ✗

    Global Reader

    Why it's wrong here

    Global Reader is an Microsoft Entra ID (formerly Azure AD) role that provides read-only access to directory configuration and tenant-wide settings, not to Azure resource data planes. Without an additional Azure RBAC assignment on the Sentinel workspace, a Global Reader cannot open Sentinel incidents or view analytics rules because Sentinel's RBAC is separate from Entra ID roles. Even as a tenant-wide reader, it lacks the workspace-scoped permission required by Sentinel's own resource hierarchy.

  • ✗

    Security Operator

    Why it's wrong here

    Security Operator (in Microsoft Entra ID or Microsoft 365 Defender) grants operational write permissions, such as managing alerts, investigating threats, and modifying security policies or settings. It is not a read-only role, so it violates the requirement of read-only access for the user. Moreover, it does not confer the Sentinel-specific RBAC needed to view analytics rules; its incident management capabilities target Defender workloads rather than Sentinel's workspace.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.