sc-900 Practice Question 1796
Exam: sc-900
Domain: Describe the capabilities of Microsoft security solutions
Topic: Describe Microsoft Defender and Sentinel
Difficulty: medium
During a recent security audit at Contoso Ltd, it was discovered that there are permission bottlenecks in the Microsoft Sentinel workspace. You need to ensure that only authorized users can access and modify the workspace. How would you configure this using Microsoft Sentinel? Explain your choice and why the other options are not suitable.
Answer Options
A
Configure data retention policies for log data.
B
Assign roles via Role-Based Access Control (RBAC) in Microsoft Sentinel.
C
Use Azure Active Directory (AAD) groups to manage access.
D
Create alert rules to monitor access patterns.
Correct Answer
B: Assign roles via Role-Based Access Control (RBAC) in Microsoft Sentinel.
Explanation
The correct answer is B. Configure role-based access control (RBAC) in Microsoft Sentinel to restrict access to specific users or groups. This can be done by assigning roles such as Reader, Contributor, or Owner to different users or groups. Option A is incorrect because it refers to configuring data retention policies which do not control access to the workspace. Option C is incorrect as it suggests using Azure Active Directory (AAD) groups, which is not specific to Microsoft Sentinel's RBAC. Option D is incorrect as it refers to configuring alert rules which are unrelated to access control.