SC-200 Manage a security operations environment Practice Question
Your organization uses Microsoft Sentinel. You need to provide a SOC analyst with the ability to create and modify incident comments but not delete incidents. Which role should you assign?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Sentinel Responder
The Microsoft Sentinel Responder role is designed for SOC analysts who need to manage incidents, including adding and modifying comments, but not delete incidents. Microsoft Sentinel Contributor can delete incidents, so it is too permissive. Microsoft Sentinel Reader is read-only and cannot create or modify comments. Global Administrator has full access to all resources, including the ability to delete incidents, which is excessive for this requirement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Global Administrator
Why it's wrong here
Global Administrator is a tenant-wide directory role granting far more than incident comment rights, violating least privilege. It is tempting because it certainly allows commenting, and would be correct only for administering tenant-wide settings such as user management, licensing or directory configuration.
- ✗
Microsoft Sentinel Contributor
Why it's wrong here
Microsoft Sentinel Contributor grants full incident management, including deleting incidents, exceeding the least-privilege requirement. It is tempting because it does permit comment creation and modification, and would be correct for an analyst who must also triage, assign, close and delete incidents.
- ✗
Microsoft Sentinel Reader
Why it's wrong here
Microsoft Sentinel Reader permits viewing incidents and their comments but cannot create or modify them, so the analyst could not comment. It is tempting because it is the least-privilege Sentinel role, and would be correct for a stakeholder who only needs to review incidents without altering them.
- ✓
Microsoft Sentinel Responder
Why this is correct
Microsoft Sentinel Responder grants full incident management — assigning, changing status, and creating or editing comments — but cannot delete incidents, which only the Contributor role permits. This matches the analyst's required permissions exactly while enforcing least privilege.
Go deeper
Related to this question
About these practice questions
This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.