New Year Sale 2026! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Microsoft SC-200 Exam - Topic 1 Question 79 Discussion

Actual exam question for Microsoft's SC-200 exam
Question #: 79
Topic #: 1
[All SC-200 Questions]

You have a Microsoft 365 subscription that uses Microsoft Defender for Endpoint and contains a user named user1 and a Microsoft 365 group named Group1. All users are assigned a Defender for Endpoint Plan 1 license.

You enable Microsoft Defender XDR Unified role-based access control (RBAC) for Endpoints & Vulnerability Management.

You need to ensure that User1 can configure alerts that will send email notifications to Group1. The solution must follow the principle of least privilege.

Which permissions should you assign to User1?

Show Suggested Answer Hide Answer
Suggested Answer: A

Contribute your Thoughts:

0/2000 characters
Gerald
3 months ago
I’m surprised this is even a question, seems straightforward!
upvoted 0 times
...
Hoa
3 months ago
Wait, can User1 really do that with just one permission?
upvoted 0 times
...
Laila
3 months ago
I think B might be necessary too, though.
upvoted 0 times
...
Lavonne
4 months ago
Totally agree, A is the way to go!
upvoted 0 times
...
Izetta
4 months ago
User1 needs Alerts investigation permission for that.
upvoted 0 times
...
Marylou
4 months ago
I think "Defender Vulnerability Management - Remediation handling" is more about fixing issues rather than configuring alerts, so I’m leaning towards option A.
upvoted 0 times
...
Eden
4 months ago
I feel like "Manage security settings" could also be relevant, but I’m not confident if it specifically allows for email notifications to groups.
upvoted 0 times
...
Adelle
4 months ago
This question seems similar to one we practiced about user roles in Defender. I think "Alerts investigation" might be the right choice since it relates to managing alerts.
upvoted 0 times
...
Daniela
5 months ago
I remember we discussed the principle of least privilege, but I'm not entirely sure which permission would be the best fit for configuring alerts.
upvoted 0 times
...
Ngoc
5 months ago
Okay, let me think this through. The key is that we need to follow the principle of least privilege, so we want to give User1 the minimum permissions needed to configure the alerts and send notifications to Group1. I'm leaning towards Alerts investigation as the best option.
upvoted 0 times
...
Bernardo
5 months ago
Hmm, I'm not sure about this one. The question mentions Defender for Endpoint and RBAC, so I'm wondering if there's some specific permission related to that which I should be looking for.
upvoted 0 times
...
Julio
5 months ago
This seems straightforward - I think the answer is Alerts investigation, since the question specifically asks about configuring alerts and email notifications.
upvoted 0 times
...
Geoffrey
5 months ago
I'm a bit confused by the different Defender for Endpoint options listed. Live response capabilities and Defender Vulnerability Management don't seem directly relevant to the task at hand. I think I'll go with Alerts investigation as well.
upvoted 0 times
...
Maurine
5 months ago
I'm a little confused by the options here. Appending the value manually or restarting the service don't seem like the right approaches. I think flushing the cache is the way to go, but I want to double-check that before submitting my answer.
upvoted 0 times
...
Theodora
5 months ago
I'm a little confused by this question. I'm not sure if the right answer is "Outcomes", "Value", "Utility", or "Warranty". I'll have to think it through a bit more before making a decision.
upvoted 0 times
...
Nichelle
1 year ago
Haha, can you imagine User1 getting Manage security settings? That's like handing the keys to the kingdom. A) is definitely the way to go.
upvoted 0 times
...
Vivan
1 year ago
I don't know, D) Live response capabilities: Basic sounds kind of cool. But I guess A) is the safer bet for this scenario.
upvoted 0 times
Alesia
1 year ago
I would go with A) as well. It seems like the most appropriate permission for User1 in this scenario.
upvoted 0 times
...
Marlon
1 year ago
D) Live response capabilities: Basic does sound cool, but A) is definitely the safer choice here.
upvoted 0 times
...
Gerald
1 year ago
Yeah, I agree. It follows the principle of least privilege.
upvoted 0 times
...
Kallie
1 year ago
I think A) Alerts investigation is the best option for configuring alerts.
upvoted 0 times
...
...
Cecily
1 year ago
C) Defender Vulnerability Management - Remediation handling seems like overkill for this task. A) is the obvious choice here.
upvoted 0 times
Gerald
1 year ago
Definitely, it aligns with the principle of least privilege.
upvoted 0 times
...
Mila
1 year ago
I agree, Alerts investigation is the most appropriate permission for configuring alerts.
upvoted 0 times
...
Novella
1 year ago
User1 should be assigned Alerts investigation.
upvoted 0 times
...
...
Annabelle
1 year ago
I agree, A) Alerts investigation is the way to go. Keeps things simple and follows the principle of least privilege.
upvoted 0 times
...
Ethan
1 year ago
The correct answer is A) Alerts investigation. This gives User1 the ability to configure alerts and send email notifications to Group1 without granting unnecessary permissions.
upvoted 0 times
Wilda
1 year ago
That makes sense, it follows the principle of least privilege.
upvoted 0 times
...
Tarra
1 year ago
That makes sense, it follows the principle of least privilege.
upvoted 0 times
...
Marylyn
1 year ago
User1 should be assigned Alerts investigation.
upvoted 0 times
...
Gearldine
1 year ago
User1 should be assigned Alerts investigation.
upvoted 0 times
...
...
Jesusita
2 years ago
I believe Alerts investigation would also be necessary for User1 to configure alerts effectively.
upvoted 0 times
...
Lynda
2 years ago
I agree with Luz. Manage security settings would allow User1 to configure alerts and send email notifications to Group1.
upvoted 0 times
...
Luz
2 years ago
I think User1 should be assigned Manage security settings.
upvoted 0 times
...

Save Cancel