ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 164 - SC-200 discussion

Report
Export

Your company uses Microsoft Sentinel

A new security analyst reports that she cannot assign and resolve incidents in Microsoft Sentinel.

You need to ensure that the analyst can assign and resolve incidents. The solution must use the principle of least privilege.

Which role should you assign to the analyst?

A.

Microsoft Sentinel Responder

Answers
A.

Microsoft Sentinel Responder

B.

Logic App Contributor

Answers
B.

Logic App Contributor

C.

Microsoft Sentinel Reader

Answers
C.

Microsoft Sentinel Reader

D.

Microsoft Sentinel Contributor

Answers
D.

Microsoft Sentinel Contributor

Suggested answer: A

Explanation:

The Microsoft Sentinel Responder role allows users to investigate, triage, and resolve security incidents, which includes the ability to assign incidents to other users. This role is designed to provide the necessary permissions for incident management and response while still adhering to the principle of least privilege. Other roles such as Logic App Contributor and Microsoft Sentinel Contributor would have more permissions than necessary and may not be suitable for the analyst's needs. Microsoft Sentinel Reader role is not sufficient as it doesn't have permission to assign and resolve incidents.

Reference:Ă‚ https://docs.microsoft.com/en-us/azure/sentinel/role-based-access-control-rbac

asked 05/10/2024
Yuri Shpovlov
40 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first