SC-200 · Question #22
You have a Microsoft 365 subscription that uses Azure Defender. You have 100 virtual machines in a resource group named RG1. You assign the Security Admin roles to a new user named SecAdmin1. You…
The correct answer is C. the Contributor role for RG1. Applying quick fixes (one-click remediations) in Azure Defender requires write permissions on the target resources. The Security Admin role grants security policy management rights but not resource-level write access needed to apply remediations. Contributor on RG1 provides the…
Question
You have a Microsoft 365 subscription that uses Azure Defender. You have 100 virtual machines in a resource group named RG1. You assign the Security Admin roles to a new user named SecAdmin1. You need to ensure that SecAdmin1 can apply quick fixes to the virtual machines by using Azure Defender. The solution must use the principle of least privilege. Which role should you assign to SecAdmin1?
Options
- Athe Security Reader role for the subscription
- Bthe Contributor for the subscription
- Cthe Contributor role for RG1
- Dthe Owner role for RG1
How the community answered
(43 responses)- A5% (2)
- B12% (5)
- C77% (33)
- D7% (3)
Explanation
Applying quick fixes (one-click remediations) in Azure Defender requires write permissions on the target resources. The Security Admin role grants security policy management rights but not resource-level write access needed to apply remediations. Contributor on RG1 provides the necessary write access scoped only to that resource group, satisfying least privilege. Contributor on the entire subscription (B) is too broad. Owner on RG1 (D) adds unnecessary access management permissions. Security Reader (A) is read-only.
Topics
Community Discussion
No community discussion yet for this question.