exam questions

Exam SC-200 All Questions

View all questions & answers for the SC-200 exam

Exam SC-200 topic 3 question 43 discussion

Actual exam question from Microsoft's SC-200
Question #: 43
Topic #: 3
[All SC-200 Questions]

You have an Azure subscription that has the enhanced security features in Microsoft Defender for Cloud enabled and contains a user named User1.
You need to ensure that User1 can export alert data from Defender for Cloud. The solution must use the principle of least privilege.
Which role should you assign to User1?

  • A. User Access Administrator
  • B. Owner
  • C. Contributor
  • D. Reader
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
BMG6
Highly Voted 1 year, 7 months ago
The correct answer is D. Reader. The Reader role in Defender for Cloud allows users to view recommendations, alerts, a security policy, and security states, but cannot make changes. This is the least privileged role that allows User1 to export alert data from Defender for Cloud. The other options are incorrect. Option A: The User Access Administrator role allows users to manage user access to Defender for Cloud. It does not allow users to export alert data. Option B: The Owner role allows users to do everything that the Reader role allows, plus they can make changes to the security policy and recommendations. This is more privileged than necessary. Option C: The Contributor role allows users to do everything that the Reader role allows, plus they can apply recommendations and dismiss alerts. This is more privileged than necessary.
upvoted 14 times
nsss
1 year, 3 months ago
As far as I can tell from the documentation, you need Security admin or Owner to export alerts data? https://learn.microsoft.com/en-us/azure/defender-for-cloud/continuous-export?tabs=azure-portal
upvoted 4 times
...
...
tooaungyan
Highly Voted 2 years, 7 months ago
should be C since least privilege
upvoted 13 times
fred99
2 years, 7 months ago
owner see https://docs.microsoft.com/en-us/azure/defender-for-cloud/continuous-export?tabs=azure-portal#manual-one-time-export-of-alerts-and-recommendations
upvoted 1 times
AK4U_111
1 year, 10 months ago
Wrong! The link you provided states clearly that a contributor role can export the data. "For a Log Analytics workspace: After the user accepts the invitation to join the tenant, assign the user in the workspace tenant one of these roles: Owner, Contributor, Log Analytics Contributor, Sentinel Contributor, Monitoring Contributor"
upvoted 3 times
nsss
1 year, 2 months ago
It says that under "Export data to an Azure Event Hubs or Log Analytics workspace in another tenant". It doesn't mention another tenant or even an event hub or workspace.
upvoted 1 times
...
...
...
...
2476aa1
Most Recent 2 months ago
Selected Answer: C
Reader can not export data, next possible role with permission to do this is C, Contributor.
upvoted 1 times
...
Edindude
2 months, 2 weeks ago
Selected Answer: C
I think C - The Contributor (C) role allows full management of resources, including the ability to export alert data from Defender for Cloud. The Reader (D) role only allows viewing resources and data, without the permission to export or modify anything. So, Contributor is necessary because it grants the required permissions to perform the export, while Reader does not.
upvoted 1 times
...
LinearB
3 months ago
Selected Answer: C
Can a Reader export alert data from Defender for CLoud? No, a Reader cannot export alert data from Microsoft Defender for Cloud. The Reader role has read-only access and can view recommendations, alerts, and security policies, but it cannot perform actions like exporting data1. To export alert data, you would need at least the Security Admin role, which has the necessary permissions to perform exports. Can a contributor export alert data from Defender for Cloud? Yes, a Contributor can export alert data from Microsoft Defender for Cloud. The Contributor role has the necessary permissions to set up continuous export and export alert data to a Log Analytics workspace or other targets1.
upvoted 2 times
...
trut_hz
3 months, 2 weeks ago
Selected Answer: C
Why Not Use Reader for Exporting? Exporting is considered an action: Even though it may seem like a read-only task, exporting typically involves interaction with an external service, API, or storage (e.g., copying data to a storage account or triggering a script), which requires write permissions. The Reader role is strictly limited to viewing data and does not support programmatic access to move or export the data. Security Reader vs. Contributor: Capability Security Reader Contributor View alerts and recommendations ✅ ✅ View compliance data ✅ ✅ Export alert data (manual or programmatic) ❌ ✅ Create integrations or automations ❌ ✅
upvoted 2 times
...
ctshepard
4 months ago
Selected Answer: D
D. is correct. Reader is the least privileged role in this question and Readers CAN export from Azure.
upvoted 2 times
...
Avaris
5 months, 2 weeks ago
Selected Answer: C
can't a reader do that? A user with the Reader role has read-only access to the resources and data in Defender for Cloud but doesn't have the permissions to export alert data.
upvoted 1 times
...
talosDevbot
6 months, 3 weeks ago
Selected Answer: B
You can download a CSV report from the Security Alerts page of the Defender for Cloud portal. This will requires only the Reader role. However, since the question exporting data instead of downloading a report, I'll go with the Owner role as my answer
upvoted 1 times
...
Studytime2023
8 months, 3 weeks ago
Selected Answer: D
I don't think it should be owner. Please read: https://learn.microsoft.com/en-us/azure/role-based-access-control/built-in-roles/general#reader If reader is too limiting. Then contributor... The thing is the question only state exporting. Nothing more. So reader should work.
upvoted 3 times
Studytime2023
8 months, 3 weeks ago
GPT is adament that it should be contributor. "The Reader role allows users to view all resources but does not permit making any changes or performing actions such as exporting data. To export alert data, the role assigned must have permissions to perform actions beyond just reading data. Summary of Roles: Reader: View-only access. Cannot export data or perform actions beyond viewing. Contributor: Manage resources, including exporting data but cannot assign roles. Owner: Full control, including assigning roles, which is more access than necessary. User Access Administrator: Manage user access but not related to exporting data."
upvoted 1 times
Studytime2023
8 months, 3 weeks ago
I have found the definitive info that strongly indicates it is contributor. No more interpretations needed. "If you use a Log Analytics workspace, assign the user in the workspace tenant one of these roles: Owner, Contributor, Log Analytics Contributor, Sentinel Contributor, or Monitoring Contributor." https://learn.microsoft.com/en-us/azure/defender-for-cloud/benefits-of-continuous-export#export-data-to-an-event-hub-or-log-analytics-workspace-in-another-tenant
upvoted 2 times
...
...
...
smanzana
9 months ago
Reader (The key is “The solution must use the principle of least privilege”)
upvoted 1 times
...
smosmo
9 months, 1 week ago
Selected Answer: D
Detailed Role Information for Reader The Reader role in Azure provides the following permissions: View all resources. Access and export alert data from Microsoft Defender for Cloud. Read-only access to monitoring data and other resource properties.
upvoted 5 times
...
Hawklx
9 months, 2 weeks ago
Selected Answer: D
Based on others comment and docs
upvoted 3 times
...
sebas12345
9 months, 3 weeks ago
Admin or Owners can export ! So the answer would be Admin ! https://learn.microsoft.com/en-us/azure/defender-for-cloud/continuous-export
upvoted 1 times
Studytime2023
8 months, 3 weeks ago
In that link it states: "Security Admin or Owner for the resource group" It doesn't say for exporting. The answer is most likely to be contributor. Owner is too much. User1 could assign other users with owner. Reader is too little (View only). https://learn.microsoft.com/en-us/azure/role-based-access-control/built-in-roles/general#reader
upvoted 1 times
...
...
7d801bf
9 months, 3 weeks ago
correct answer is Reader
upvoted 1 times
...
Sekpluz
10 months, 2 weeks ago
Selected Answer: B
https://learn.microsoft.com/en-us/azure/defender-for-cloud/continuous-export?tabs=azure-portal#availability
upvoted 1 times
...
Sneekygeek
1 year ago
Selected Answer: B
While a reader can view the alerts the question says we need to be able to export them. All the docs for defender for cloud regarding exporting alerts are talking about setting up SIEM integration which requires owner perms.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago