SC-200 Manage a security operations environment Practice Question
Your security team needs to assign a custom role in Microsoft Sentinel that allows read and write access to incidents but not to analytics rules. Which built-in role should you use as a base for the custom role?
⚠ Common exam trap
Candidates often confuse 'Contributor' as the default for any write access, overlooking that it grants broader permissions than needed, while 'Responder' is specifically scoped to incident operations without analytics rule modification.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Sentinel Responder
The Microsoft Sentinel Responder role is the correct base because it grants read and write access to incidents while explicitly excluding write permissions to analytics rules. This aligns with the requirement for incident management without allowing modifications to detection logic.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Microsoft Sentinel Responder
Why this is correct
Microsoft Sentinel Responder is the correct built-in role when the job requires actively working incidents: it lets the analyst view, triage, assign, update, and comment on incidents, as well as perform investigation actions like running queries. Critically, it omits write rights to analytics rules, automation rules, and data connectors, so an analyst can respond to threats without accidentally weakening detection logic. This aligns with least privilege for a pure incident-response duty.
- ✗
Microsoft Sentinel Reader
Why it's wrong here
Microsoft Sentinel Reader grants only read-only access to Sentinel resources, including incidents, workbooks, and analytic rules. A user with this role can view incident details and the investigation graph but cannot change status, assign incidents, add comments, or perform any management action. Consequently, it fails for anyone expected to actually respond and remediate incidents, since every action is blocked.
- ✗
Microsoft Sentinel Contributor
Why it's wrong here
Microsoft Sentinel Contributor is too broad because it adds full write access to everything in a Sentinel workspace, including the ability to create and edit analytics rules, automation rules, data connectors, and workbooks. While it certainly can manage incidents, granting it for incident handling alone over-permits the user and raises the risk of accidental misconfiguration of detection and response logic. The principle of least privilege dictates using the narrower Responder role instead.
- ✗
Global Administrator
Why it's wrong here
Global Administrator is an Microsoft Entra ID-wide identity (Entra ID) role that provides unrestricted access to all Microsoft Entra ID settings and, through that, broad control over all Azure subscriptions and resources, including Sentinel. Using it for incident management would essentially give the user full tenant control, far beyond the minimal permissions needed, and would create a massive security risk if compromised. It is inappropriate for a role that should be scoped to managing specific incidents.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.