Valid SC-200 Dumps shared by ExamDiscuss.com for Helping Passing SC-200 Exam! ExamDiscuss.com now offer the newest SC-200 exam dumps, the ExamDiscuss.com SC-200 exam questions have been updated and answers have been corrected get the newest ExamDiscuss.com SC-200 dumps with Test Engine here:
You use Azure Sentinel. You need to use a built-in role to provide a security analyst with the ability to edit the queries of custom Azure Sentinel workbooks. The solution must use the principle of least privilege. Which role should you assign to the analyst?
Correct Answer: C
Azure Sentinel Contributor can create and edit workbooks, analytics rules, and other Azure Sentinel resources. Reference: https://docs.microsoft.com/en-us/azure/sentinel/roles
Recent Comments (The most recent comments are at the top.)
sam - Dec 04, 2024
A. Azure Sentinel Contributor
B. Security Administrator:
This role provides broader permissions, including managing security configurations across Azure resources. It exceeds the scope of the task and violates the principle of least privilege. C. Azure Sentinel Responder:
The Responder role is designed for incident management and response but does not allow editing workbooks or queries. D. Logic App Contributor:
This role is specific to managing Logic Apps and is unrelated to editing Sentinel workbooks or queries.
Recent Comments (The most recent comments are at the top.)
A. Azure Sentinel Contributor
B. Security Administrator:
This role provides broader permissions, including managing security configurations across Azure resources. It exceeds the scope of the task and violates the principle of least privilege.
C. Azure Sentinel Responder:
The Responder role is designed for incident management and response but does not allow editing workbooks or queries.
D. Logic App Contributor:
This role is specific to managing Logic Apps and is unrelated to editing Sentinel workbooks or queries.