exam questions

Exam SC-200 All Questions

View all questions & answers for the SC-200 exam

Exam SC-200 topic 2 question 43 discussion

Actual exam question from Microsoft's SC-200
Question #: 43
Topic #: 2
[All SC-200 Questions]

You have an Azure subscription that uses Microsoft Defender for Cloud and contains a user named User1.

You need to ensure that User1 can modify Microsoft Defender for Cloud security policies. The solution must use the principle of least privilege.

Which role should you assign to User1?

  • A. Security operator
  • B. Security Admin
  • C. Owner
  • D. Contributor
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
TheHuman_
Highly Voted 6 months ago
Selected Answer: B
Security Admin has less privileges than the Contributor or Owner roles, but is still able to modify security policies. See: https://learn.microsoft.com/en-us/azure/role-based-access-control/built-in-roles#security-admin
upvoted 6 times
...
smosmo
Most Recent 1 day, 3 hours ago
Selected Answer: B
Only Security Admin and Owner of the Subsc. can modify policies. SecAdmin has least priv. https://learn.microsoft.com/en-us/azure/defender-for-cloud/permissions Security Admin: A user that belongs to this role has the same access as the Security Reader and can also update the security policy, and dismiss alerts and recommendations.
upvoted 1 times
...
chepeerick
7 months, 3 weeks ago
Correct B
upvoted 1 times
...
Doinitza
10 months, 2 weeks ago
Question from ESI: You have an Azure subscription that uses Microsoft Defender for Cloud. You create a user named Admin1. You need to ensure that Admin1 can create and assign security policies in Defender for Cloud. The solution must follow the principle of least privilege. Which role should you assign to Admin1? Right Answer: Contributor in the Azure subscription Wrong Answer: Security Admin in the Azure subscription Comment from MS: Defender for Cloud uses Azure role-based access control (RBAC), which provides built-in roles that can be assigned to users, groups, and services in Azure. Azure AD roles do not have permissions in Defender for Cloud. Only Contributor and Owner roles at the Azure subscription level have sufficient permissions to create and assign security policies in Defender for Cloud. Contributor has less permissions than Owner, and because of that you should assign Admin1 the Contributor role. ***Maybe the Contributor is the right answer.
upvoted 3 times
Ramye
4 months ago
Wrong .. Contributor Grants full access to manage all resources, but does not allow you to assign roles in Azure RBAC, manage assignments in Azure Blueprints, or share image galleries. Security Admin View and update permissions for Microsoft Defender for Cloud. Same permissions as the Security Reader role and can also update the security policy and dismiss alerts and recommendations. Source: https://learn.microsoft.com/en-us/azure/role-based-access-control/built-in-roles#security-admin
upvoted 1 times
...
...
cyber_rip
1 year ago
B-Security Admin
upvoted 1 times
...
antoniokt
1 year, 3 months ago
Selected Answer: B
Security reader: Has rights to view Defender for Cloud items such as recommendations, alerts, policy, and health. Can't make changes. Security admin: Has the same view rights as security reader. Can also update the security policy and dismiss alerts.
upvoted 4 times
...
watoz1851
1 year, 3 months ago
Selected Answer: B
https://learn.microsoft.com/en-us/azure/defender-for-cloud/tutorial-security-policy#who-can-edit-security-policies
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago