Courseiva

SC-200 Manage a security operations environment Practice Question

Your organization uses Microsoft Sentinel. You need to provide a SOC analyst with the ability to create and modify incident comments but not delete incidents. Which role should you assign?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Microsoft Sentinel Responder

The Microsoft Sentinel Responder role is designed for SOC analysts who need to manage incidents, including adding and modifying comments, but not delete incidents. Microsoft Sentinel Contributor can delete incidents, so it is too permissive. Microsoft Sentinel Reader is read-only and cannot create or modify comments. Global Administrator has full access to all resources, including the ability to delete incidents, which is excessive for this requirement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Global Administrator

    Why it's wrong here

    Global Administrator is a tenant-wide directory role granting far more than incident comment rights, violating least privilege. It is tempting because it certainly allows commenting, and would be correct only for administering tenant-wide settings such as user management, licensing or directory configuration.

  • ✗

    Microsoft Sentinel Contributor

    Why it's wrong here

    Microsoft Sentinel Contributor grants full incident management, including deleting incidents, exceeding the least-privilege requirement. It is tempting because it does permit comment creation and modification, and would be correct for an analyst who must also triage, assign, close and delete incidents.

  • ✗

    Microsoft Sentinel Reader

    Why it's wrong here

    Microsoft Sentinel Reader permits viewing incidents and their comments but cannot create or modify them, so the analyst could not comment. It is tempting because it is the least-privilege Sentinel role, and would be correct for a stakeholder who only needs to review incidents without altering them.

  • ✓

    Microsoft Sentinel Responder

    Why this is correct

    Microsoft Sentinel Responder grants full incident management — assigning, changing status, and creating or editing comments — but cannot delete incidents, which only the Contributor role permits. This matches the analyst's required permissions exactly while enforcing least privilege.

About these practice questions

This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.