SC-200 · Question #140
You have an Azure subscription that has the enhanced security features in Microsoft Defender for Cloud enabled and contains a user named User1. You need to ensure that User1 can export alert data…
The correct answer is B. Owner. Although Owner appears to violate the principle of least privilege intuitively, configuring continuous export settings in Microsoft Defender for Cloud requires Owner-level permissions at the subscription or resource group scope. Lower roles such as Contributor, Reader, or User…
Question
You have an Azure subscription that has the enhanced security features in Microsoft Defender for Cloud enabled and contains a user named User1. You need to ensure that User1 can export alert data from Defender for Cloud. The solution must use the principle of least privilege. Which role should you assign to User1?
Options
- AUser Access Administrator
- BOwner
- CContributor
- DReader
How the community answered
(53 responses)- A4% (2)
- B75% (40)
- C6% (3)
- D15% (8)
Explanation
Although Owner appears to violate the principle of least privilege intuitively, configuring continuous export settings in Microsoft Defender for Cloud requires Owner-level permissions at the subscription or resource group scope. Lower roles such as Contributor, Reader, or User Access Administrator do not grant sufficient rights to set up alert data export in Defender for Cloud. Because no purpose-built 'Security Export' role exists and Contributor is insufficient for this specific operation, Owner is the minimum role that actually satisfies the requirement-making it the least-privilege correct answer given the available options.
Topics
Community Discussion
No community discussion yet for this question.