exam questions

Exam SC-200 All Questions

View all questions & answers for the SC-200 exam

Exam SC-200 topic 3 question 106 discussion

Actual exam question from Microsoft's SC-200
Question #: 106
Topic #: 3
[All SC-200 Questions]

You have an Azure subscription that contains a Microsoft Sentinel workspace named Workspace1 and a user named User1.

You need to ensure that User1 can investigate incidents by using Workspace1. The solution must follow the principle of least privilege.

Which role should you assign to User1?

  • A. Microsoft Sentinel Responder
  • B. Microsoft Sentinel Contributor
  • C. Microsoft Sentinel Automation Contributor
  • D. Microsoft Sentinel Reader
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Kristiannn
Highly Voted 7 months, 1 week ago
Selected Answer: D
You can investigate by just viewing the Incident. The question does not specify that the user "manage" the Incident.
upvoted 10 times
...
Aam9303
Most Recent 1 month, 2 weeks ago
Selected Answer: A
ChatGPT says A
upvoted 1 times
...
Onimole
3 months ago
Selected Answer: A
Prerequisites The Microsoft Sentinel Responder role assignment is required to investigate incidents. Learn more about roles in Microsoft Sentinel. If you have a guest user that needs to assign incidents, the user must be assigned the Directory Reader role in your Microsoft Entra tenant. Regular (nonguest) users have this role assigned by default. https://learn.microsoft.com/en-us/azure/sentinel/investigate-incidents
upvoted 2 times
...
limpan
3 months, 2 weeks ago
Selected Answer: A
A. Microsoft Sentinel Responder Explanation: Microsoft Sentinel Responder: This role allows User1 to investigate incidents, including viewing incidents, updating their status, and adding comments. It does not grant permissions to create or modify analytics rules, playbooks, or other configurations, which aligns with the principle of least privilege. Why not the other options? B. Microsoft Sentinel Contributor: This role grants full access to manage Microsoft Sentinel, including creating and modifying analytics rules, playbooks, and other configurations, which exceeds the required permissions. C. Microsoft Sentinel Automation Contributor: This role is used to manage automation rules and playbooks, not for investigating incidents. D. Microsoft Sentinel Reader: This role only allows viewing incidents and data but does not permit User1 to investigate or update incidents. Thus, the correct answer is A.
upvoted 2 times
...
b174f8f
3 months, 3 weeks ago
Selected Answer: A
In Topic 4 Question 29 has a similar case, where “investigate” is required only. It is also marked as requiring the “Respond” role. Here Microsoft specifies that “investigate” requires the role of “respond”: https://learn.microsoft.com/en-us/azure/sentinel/investigate-incidents I think its a bad use of the word, and they shouldn't leave questions open to the imagination, but I'm going to go with A.
upvoted 1 times
...
xRiot007
5 months ago
Selected Answer: A
If you just need to investigate, read rights are enough. If you need to actually investigate and respond/solve the incident, you need to be a Responder.
upvoted 1 times
...
Takakage
6 months, 2 weeks ago
Selected Answer: A
The problem statement mentions that "User1 can investigate incidents using Workspace1." If it is just "investigation," it is possible with the Microsoft Sentinel Reader role. However, investigating incidents typically involves checking the details of the incident and, if necessary, changing the status of the incident or adding comments. These actions require the Microsoft Sentinel Responder role.
upvoted 4 times
...
chirva
7 months ago
Selected Answer: A
GPT4: The "Microsoft Sentinel Reader" role provides read-only access to Microsoft Sentinel resources, which includes viewing incidents, workbooks, and other data. However, it does not provide the necessary permissions to actively investigate or respond to incidents. For User1 to be able to investigate incidents, they need more than just read access; they need the ability to interact with and manage incidents. Therefore, the "Microsoft Sentinel Reader" role would not be sufficient for this purpose. The correct role to assign to User1 to ensure they can investigate incidents while adhering to the principle of least privilege is: A. Microsoft Sentinel Responder
upvoted 3 times
...
sapphire
7 months ago
Selected Answer: A
To investigate the incident, read privileges are sufficient. Microsoft Sentinel Reader
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...