SC-200 · Question #40
Your company uses Azure Sentinel. A new security analyst reports that she cannot assign and dismiss incidents in Azure Sentinel. You need to resolve the issue for the analyst. The solution must use…
The correct answer is A. Azure Sentinel Responder. Roles for working in Azure Sentinel Azure Sentinel-specific roles All Azure Sentinel built-in roles grant read access to the data in your Azure Sentinel workspace. Azure Sentinel Reader can view data, incidents, workbooks, and other Azure Sentinel resources. Azure Sentinel…
Question
Your company uses Azure Sentinel. A new security analyst reports that she cannot assign and dismiss incidents in Azure Sentinel. You need to resolve the issue for the analyst. The solution must use the principle of least privilege. Which role should you assign to the analyst?
Options
- AAzure Sentinel Responder
- BLogic App Contributor
- CAzure Sentinel Contributor
- DAzure Sentinel Reader
How the community answered
(32 responses)- A91% (29)
- B6% (2)
- D3% (1)
Explanation
Roles for working in Azure Sentinel Azure Sentinel-specific roles All Azure Sentinel built-in roles grant read access to the data in your Azure Sentinel workspace. Azure Sentinel Reader can view data, incidents, workbooks, and other Azure Sentinel resources. Azure Sentinel Responder can, in addition to the above, manage incidents (assign, dismiss, etc.) Azure Sentinel Contributor can, in addition to the above, create and edit workbooks, analytics rules, and other Azure Sentinel resources. Azure Sentinel Automation Contributor allows Azure Sentinel to add playbooks to automation rules. It is not meant for user accounts. https://docs.microsoft.com/en-us/azure/sentinel/roles
Topics
Community Discussion
No community discussion yet for this question.