Courseiva

SC-200 Manage a security operations environment Practice Question

Your team uses Microsoft Sentinel to monitor multiple Azure subscriptions. You need to grant a junior analyst the ability to view incidents and run playbooks, but not modify analytics rules or data connectors. Which built-in role should you assign?

⚠ Common exam trap

It's easy for candidates to confuse 'Responder' with 'Reader' or 'Contributor', assuming that running playbooks requires Contributor-level access, when in fact the Responder role is specifically designed for incident response actions without broader management rights.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Microsoft Sentinel Responder

Microsoft Sentinel Responder is the correct built-in role because it grants the junior analyst the ability to view incidents and run playbooks, while explicitly preventing modifications to analytics rules or data connectors. This role provides the exact permissions needed for incident response tasks without allowing changes to the security configuration.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Microsoft Sentinel Contributor

    Why it's wrong here

    The Microsoft Sentinel Contributor role grants full write access to Sentinel workspace resources—analytics rules, data connectors, workbooks, and automation rules—but it deliberately excludes the ability to execute playbooks in response to incidents. In the Sentinel RBAC model, playbook execution requires a separate data action (Microsoft.SecurityInsights/incidents/playbooks/execute) that only Responder and Sentinel Playbook Operator possess. Since the scenario requires actually running a playbook to take action on an incident, Contributor, despite its broad management permissions, cannot complete the response workflow.

  • ✗

    Automation Contributor

    Why it's wrong here

    Automation Contributor is scoped to manage Azure Automation resources such as runbooks, schedules, modules, and hybrid worker groups across an Automation account, but it has zero permissions on Microsoft.SecurityInsights (Sentinel). It cannot view incidents, update their statuses, or execute Sentinel playbooks, even though playbooks are technically built on Logic Apps and often tied to Automation accounts. The role is commonly confused because Sentinel playbooks run 'automation,' but the RBAC permission to trigger a playbook from an incident is distinct and belongs to Sentinel-specific roles, making Automation Contributor an incorrect choice.

  • ✗

    Microsoft Sentinel Reader

    Why it's wrong here

    Microsoft Sentinel Reader is a read-only role that permits viewing Sentinel data—incidents, analytics rules, workbooks, and threat intelligence—but it permits no write, update, or execute operations. It cannot run a playbook because doing so requires the execute permission on the playbook resource and the ability to update the incident's status after the playbook runs. While an incident responder with Reader can assess a threat, the requirement to actively execute a playbook for remediation exceeds the role's capabilities, so it is insufficient here.

  • ✓

    Microsoft Sentinel Responder

    Why this is correct

    Microsoft Sentinel Responder is the built-in incident-response role that can view, triage, and manage incidents while also being able to execute playbooks directly from those incidents. Its permission set includes Microsoft.SecurityInsights/incidents/read, /write, and /playbooks/execute, allowing a responder to run the playbook and update the incident without granting broader SIEM configuration rights like altering analytics rules or connectors. This role is the correct least-privilege assignment because it specifically enables the requested playbook execution while still maintaining separation of duties from administrative Sentinel tasks.

About these practice questions

This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.