nerdexam
Microsoft

SC-200 · Question #40

Your company uses Azure Sentinel. A new security analyst reports that she cannot assign and dismiss incidents in Azure Sentinel. You need to resolve the issue for the analyst. The solution must use…

The correct answer is A. Azure Sentinel Responder. Roles for working in Azure Sentinel Azure Sentinel-specific roles All Azure Sentinel built-in roles grant read access to the data in your Azure Sentinel workspace. Azure Sentinel Reader can view data, incidents, workbooks, and other Azure Sentinel resources. Azure Sentinel…

Submitted by lars.no· Apr 18, 2026Manage incident response

Question

Your company uses Azure Sentinel. A new security analyst reports that she cannot assign and dismiss incidents in Azure Sentinel. You need to resolve the issue for the analyst. The solution must use the principle of least privilege. Which role should you assign to the analyst?

Options

  • AAzure Sentinel Responder
  • BLogic App Contributor
  • CAzure Sentinel Contributor
  • DAzure Sentinel Reader

How the community answered

(32 responses)
  • A
    91% (29)
  • B
    6% (2)
  • D
    3% (1)

Explanation

Roles for working in Azure Sentinel Azure Sentinel-specific roles All Azure Sentinel built-in roles grant read access to the data in your Azure Sentinel workspace. Azure Sentinel Reader can view data, incidents, workbooks, and other Azure Sentinel resources. Azure Sentinel Responder can, in addition to the above, manage incidents (assign, dismiss, etc.) Azure Sentinel Contributor can, in addition to the above, create and edit workbooks, analytics rules, and other Azure Sentinel resources. Azure Sentinel Automation Contributor allows Azure Sentinel to add playbooks to automation rules. It is not meant for user accounts. https://docs.microsoft.com/en-us/azure/sentinel/roles

Topics

#Azure Sentinel#RBAC#Incident Management#Least Privilege

Community Discussion

No community discussion yet for this question.

Full SC-200 Practice