SC-200 Manage a security operations environment Practice Question
Your team uses Microsoft Sentinel to monitor Azure subscriptions. You need to ensure that only users with the 'Microsoft Sentinel Contributor' role can create and edit analytics rules. You want to enforce this using Azure Policy. What should you do?
⚠ Common exam trap
Candidates often confuse Azure Policy (which enforces rules at resource creation/modification time) with Azure RBAC (which controls access to actions) or Azure Blueprints (which is a deployment tool), leading candidates to incorrectly choose role assignments or custom roles instead of a policy-based denial.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create an Azure Policy that denies creation of analytics rules if the user doesn't have the 'Microsoft Sentinel Contributor' role.
Azure Policy can enforce guardrails by denying resource creation or modification based on conditions, such as the user's role. By creating a policy that denies the creation or editing of analytics rules unless the user has the 'Microsoft Sentinel Contributor' role, you directly enforce the requirement. This approach uses Azure Policy's 'deny' effect to prevent unauthorized actions at the Azure Resource Manager level, regardless of other permissions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Create an Azure Policy that denies creation of analytics rules if the user doesn't have the 'Microsoft Sentinel Contributor' role.
Why this is correct
Azure Policy can enforce RBAC at deployment time by using the `requestContext.roleDefinitionIds` property in a policy rule. A custom policy with a `deny` effect on Microsoft.SecurityInsights/alertRules evaluates the caller's roles and blocks creation of analytics rules unless the user holds the Sentinel Contributor role ID. This is a centralized, subscription-wide governance control that prevents unauthorized changes, unlike a one-time role assignment.
- ✗
Use Azure Blueprints to assign the 'Microsoft Sentinel Contributor' role to a security group.
Why it's wrong here
Azure Blueprints are a declarative packaging mechanism for orchestrating the deployment of resources such as role assignments, policies, and ARM templates. While a blueprint could assign the Sentinel Contributor role to a security group, it is a one-time deployment artifact and cannot continuously evaluate or block rule creation by users who lack the role. The requirement is to impose an ongoing restriction on who can create analytics rules, and Blueprints provide no runtime enforcement or conditional deny logic.
- ✗
Assign the 'Microsoft Sentinel Contributor' role to all users at the subscription level.
Why it's wrong here
If all users receive the Sentinel Contributor role at subscription scope, every user—including those outside the security operations team—gains permission to read and modify Sentinel artifacts, including analytics rules, incident settings, and automation. This broad grant actually expands the attack surface and violates least privilege; it does not restrict creation because the role itself grants the `Microsoft.SecurityInsights/alertRules/write` action. The need is to prevent unauthorized rule creation, not to allow it for everyone.
- ✗
Create a custom role that denies write access to analytics rules.
Why it's wrong here
A custom RBAC role cannot implement an explicit `Deny` effect; custom roles define allowed Actions and NotActions, where NotActions only subtract actions from the same role's allowed actions. If a user has another role assignment that grants `Microsoft.SecurityInsights/alertRules/write`, the custom role's NotAction is ineffective, and the user would still be able to create rules. Azure Policy is the correct enforcement mechanism because it can deny resource creation at the resource provider level, independent of identity role semantics.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.