exam questions

Exam MS-500 All Questions

View all questions & answers for the MS-500 exam

Exam MS-500 topic 4 question 52 discussion

Actual exam question from Microsoft's MS-500
Question #: 52
Topic #: 4
[All MS-500 Questions]

You have a Microsoft 365 subscription.
You enable auditing for the subscription.
You plan to provide a user named Auditor with the ability to review audit logs.
You add Auditor to the Global administrator role group.
Several days later, you discover that Auditor disabled auditing.
You remove Auditor from the Global administrator role group and enable auditing.
You need to modify Auditor to meet the following requirements:
✑ Be prevented from disabling auditing
✑ Use the principle of least privilege
✑ Be able to review the audit log
To which role group should you add Auditor?

  • A. Security reader
  • B. Compliance administrator
  • C. Security operator
  • D. Security administrator
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
itmp
Highly Voted 5 years, 2 months ago
Answer is correct - Security Reader does NOT have the "View-Only Audit Logs". https://docs.microsoft.com/en-us/microsoft-365/security/office-365-security/permissions-in-the-security-and-compliance-center?view=o365-worldwide
upvoted 44 times
jack987
5 years ago
I agree with itmp. The answer is correct - Security Operator - has the View-Only Audit Log
upvoted 3 times
...
TDAC
4 years, 8 months ago
itmp is correct. This person speaks the gospel.
upvoted 4 times
...
gills
5 years, 1 month ago
This is correct as listed in the URL https://docs.microsoft.com/en-us/microsoft-365/security/office-365-security/permissions-in-the-security-and-compliance-center?view=o365-worldwide
upvoted 3 times
...
...
BobInTheMoon
Highly Voted 5 years, 4 months ago
Security reader Read-only access to security features, sign-in reports, and audit logs. https://docs.microsoft.com/en-us/office365/admin/add-users/about-admin-roles?redirectSourcePath=%252farticle%252fAbout-Office-365-admin-roles-da585eea-f576-4f55-a1e0-87090b6aaa9d&view=o365-worldwide
upvoted 12 times
WMG
3 years, 10 months ago
This is wrong. Security reader does not have "view only audit logs" permission. Verified by current documentation and reality.
upvoted 4 times
...
...
bcquest
Most Recent 2 years ago
Selected Answer: C
C is correct. From the links people are providing about the security reader it only shows the ability to read the properties of the audit logs. Not the logs themselves: microsoft.directory/auditLogs/allProperties/read Read all properties on audit logs, including privileged properties
upvoted 1 times
...
naylinu
2 years, 3 months ago
Answer is C Security Operator - Default Role Assigned: Compliance Search Manage Alerts Security Reader Tag Contributor Tag Reader Tenant AllowBlockList Manager ***View-Only Audit Logs *** View-Only Device Management View-Only DLP Compliance Management View-Only IB Compliance Management View-Only Manage Alerts Security Reader - Default Role Assigned: Security Reader Sensitivity Label Reader Tag Reader View-Only Device Management View-Only DLP Compliance Management View-Only IB Compliance Management View-Only Manage Alerts
upvoted 2 times
...
Dzuljzebari
2 years, 4 months ago
Selected Answer: A
Below is the list of extra permissions Security operator gets: Create and delete all resources, and read and update standard properties in ‎Microsoft Cloud App Security.‎ Create and delete all resources, and read and update standard properties in ‎Azure AD Identity Protection‎. Manage all aspects of ‎Azure Advanced Threat Protection.‎ Create and manage support tickets in the ‎Azure portal.‎ Create and delete all resources, and read and update standard properties in the ‎Security & Compliance Center‎. Create and manage service requests in the ‎Microsoft 365 admin center.‎ Manage all aspects of ‎Microsoft Defender Advanced Threat Protection‎. My answer is A. Security reader has access to logs and is read only role.
upvoted 1 times
...
Jonclark
2 years, 4 months ago
Selected Answer: A
Too many conflicting opinions and links to follow here, so I just configured it in my lab. With the Security Reader role assigned, I am able to view the audit logs. When I remove that role, the user cannot view the audit logs. Security reader can read the audit logs and has less privileges than security operator, so the answer is clearly A. This was really easy to test -- just try it and you'll get the answer too.
upvoted 2 times
...
kimble3k
2 years, 4 months ago
Selected Answer: C
as examdog stated: Roles with "View Only Audit Logs" are (there is no security reader): * Compliance Administrator * Compliance Data Administrator * Global Reader * Organization Management * Security Administrator * Security Operator https://docs.microsoft.com/en-us/microsoft-365/security/office-365-security/permissions-in-the-security-and-compliance-center?
upvoted 1 times
...
examdog
2 years, 6 months ago
Selected Answer: C
Roles with "View Only Audit Logs" are (there is no security reader): * Compliance Administrator * Compliance Data Administrator * Global Reader * Organization Management * Security Administrator * Security Operator https://docs.microsoft.com/en-us/microsoft-365/security/office-365-security/permissions-in-the-security-and-compliance-center?
upvoted 2 times
kimble3k
2 years, 4 months ago
yes, you are correct!
upvoted 1 times
...
AWpkl
2 years, 4 months ago
As of 2023, there is STILL a conflict in the documentation VS Azure ad interface. Documentation shows Security reader does not have view-only aduit log access, but Azure's own description and role list says it has global access to read all logs. GG MS, way to make this infuriating. I'll take the literally description on Azure's interface and roles list over what was published by marketing/communications, so the answer is A, security reader.
upvoted 2 times
...
...
tibodenbeer
2 years, 6 months ago
Selected Answer: A
Security operator: Read all properties on audit logs, including privileged properties. Security reader: Read all properties on audit logs, including privileged properties. Straight from the permissions page in azure. So should be reader.
upvoted 1 times
...
King2
2 years, 6 months ago
Selected Answer: A
Both of Security Operator and Security Reader can “Read all properties on audit logs, including privileged properties” Answer is Security Reader according to principle of least privilege.
upvoted 1 times
...
rolia
2 years, 7 months ago
Selected Answer: C
vote for c
upvoted 1 times
...
goape
2 years, 7 months ago
Selected Answer: A
Both reader and operator can do this, but reader is less permissive than operator. Description of reader role taken from AAD: Users with this role have global read-only access, including all information in Azure Active Directory, Identity Protection, Privileged Identity Management, as well as the ability to read Azure Active Directory sign-in reports and audit logs. The role also grants read-only permission in Office 365 Security & Compliance Center
upvoted 1 times
...
Anonymousse
2 years, 7 months ago
using this link: https://learn.microsoft.com/en-us/azure/active-directory/roles/permissions-reference#security-reader It appears that Security Reader has less permissions than Security Operator.
upvoted 1 times
...
Tottan
2 years, 8 months ago
I have added user ALL 4 roles in this question together and Audit Logs are still grayed :/
upvoted 1 times
...
yoton
2 years, 8 months ago
Selected Answer: C
DO YOUR OWN RESEARCH!!!! Security Reader does NOT have audit log read access. Security Reader: Sensitivity Label Reader Tag Reader View-Only Device Management View-Only DLP Compliance Management View-Only IB Compliance Management View-Only Manage Alerts
upvoted 3 times
yoton
2 years, 8 months ago
Ref: https://learn.microsoft.com/en-us/microsoft-365/security/office-365-security/permissions-in-the-security-and-compliance-center?view=o365-worldwide#role-groups-in-the-security--compliance-center
upvoted 2 times
...
...
dakasa
2 years, 9 months ago
Selected Answer: C
I vote for C
upvoted 1 times
...
Bulldozzer
2 years, 10 months ago
The right answer is Security reader as this role has the ability to read audit logs. "Users with this role have global read-only access, including all information in Azure Active Directory, Identity Protection, Privileged Identity Management, as well as the ability to read Azure Active Directory sign-in reports and audit logs. The role also grants read-only permission in Office 365 Security & Compliance Center"
upvoted 2 times
EzeQ
2 years, 10 months ago
I'm also with Reader, to have the principle of least privileges [and I do not see noting about not being able to read logs] Sources: https://docs.microsoft.com/en-us/azure/active-directory/roles/permissions-reference#security-reader https://docs.microsoft.com/en-us/azure/active-directory/roles/permissions-reference#security-operator
upvoted 1 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...