Courseiva

SC-200 Manage a security operations environment Practice Question

Your team uses Microsoft Sentinel to monitor Azure subscriptions. You need to ensure that only users with the 'Microsoft Sentinel Contributor' role can create and edit analytics rules. You want to enforce this using Azure Policy. What should you do?

⚠ Common exam trap

Candidates often confuse Azure Policy (which enforces rules at resource creation/modification time) with Azure RBAC (which controls access to actions) or Azure Blueprints (which is a deployment tool), leading candidates to incorrectly choose role assignments or custom roles instead of a policy-based denial.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create an Azure Policy that denies creation of analytics rules if the user doesn't have the 'Microsoft Sentinel Contributor' role.

Azure Policy can enforce guardrails by denying resource creation or modification based on conditions, such as the user's role. By creating a policy that denies the creation or editing of analytics rules unless the user has the 'Microsoft Sentinel Contributor' role, you directly enforce the requirement. This approach uses Azure Policy's 'deny' effect to prevent unauthorized actions at the Azure Resource Manager level, regardless of other permissions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Create an Azure Policy that denies creation of analytics rules if the user doesn't have the 'Microsoft Sentinel Contributor' role.

    Why this is correct

    Azure Policy can enforce RBAC at deployment time by using the `requestContext.roleDefinitionIds` property in a policy rule. A custom policy with a `deny` effect on Microsoft.SecurityInsights/alertRules evaluates the caller's roles and blocks creation of analytics rules unless the user holds the Sentinel Contributor role ID. This is a centralized, subscription-wide governance control that prevents unauthorized changes, unlike a one-time role assignment.

  • ✗

    Use Azure Blueprints to assign the 'Microsoft Sentinel Contributor' role to a security group.

    Why it's wrong here

    Azure Blueprints are a declarative packaging mechanism for orchestrating the deployment of resources such as role assignments, policies, and ARM templates. While a blueprint could assign the Sentinel Contributor role to a security group, it is a one-time deployment artifact and cannot continuously evaluate or block rule creation by users who lack the role. The requirement is to impose an ongoing restriction on who can create analytics rules, and Blueprints provide no runtime enforcement or conditional deny logic.

  • ✗

    Assign the 'Microsoft Sentinel Contributor' role to all users at the subscription level.

    Why it's wrong here

    If all users receive the Sentinel Contributor role at subscription scope, every user—including those outside the security operations team—gains permission to read and modify Sentinel artifacts, including analytics rules, incident settings, and automation. This broad grant actually expands the attack surface and violates least privilege; it does not restrict creation because the role itself grants the `Microsoft.SecurityInsights/alertRules/write` action. The need is to prevent unauthorized rule creation, not to allow it for everyone.

  • ✗

    Create a custom role that denies write access to analytics rules.

    Why it's wrong here

    A custom RBAC role cannot implement an explicit `Deny` effect; custom roles define allowed Actions and NotActions, where NotActions only subtract actions from the same role's allowed actions. If a user has another role assignment that grants `Microsoft.SecurityInsights/alertRules/write`, the custom role's NotAction is ineffective, and the user would still be able to create rules. Azure Policy is the correct enforcement mechanism because it can deny resource creation at the resource provider level, independent of identity role semantics.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.