Exam SC-500 Topic 1 Question 32 Discussion

Actual exam question for Microsoft's SC-500 exam
Question #: 32
Topic #: 1
Hotspot Question
You need to deploy the Phishing Triage Agent in Microsoft Security Copilot to manage phishing incidents in Microsoft Defender XDR.
The solution must meet the following requirements:
- Manage the phishing incidents.
- Enable the Phishing Triage Agent.
- Follow the principle of least privilege.
Which roles should you assign? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Suggested Answer:


Explanation:
Box 1: Security Operator in Microsoft Entra and Security Copilot Contributor To enable the Phishing Triage Agent in Microsoft Security Copilot while adhering strictly to the principle of least privilege, you should assign the following two roles:
Microsoft Entra Role: Security Operator
Microsoft Security Copilot Role: Security Copilot Contributor
Security Operator: This role provides the necessary permissions to manage operational security tasks and interact with incidents within Microsoft Defender XDR without granting excessive global administrative rights or broad data modification rights across other Microsoft portals.
Security Copilot Contributor: This role allows the agentic platform to utilize Copilot capabilities, run prompts, and manage agent behaviors without having full admin access to modify Security Copilot tenant configurations (which would require the Security Copilot Owner role).
Box 2: Security Operator in Microsoft Entra and Security Copilot Contributor To manage phishing incidents using the Phishing Triage Agent in Microsoft Defender XDR while strictly adhering to the principle of least privilege, you should assign the following two roles:
Entra Role: Security Operator
Copilot Role: Contributor
Security Operator vs. Security Administrator / Global Administrator: The Security Operator role provides the necessary permissions to read security data, manage alerts, and triage incidents without granting broad configuration or destructive management privileges inherent to a Security Administrator or Global Administrator.
Contributor vs. Owner: The Contributor role allows the agent to run prompts, access core Security Copilot capabilities, and interact with the data sources to execute investigations. It explicitly leaves out platform-level access management and billing configuration rights held by an Owner.
Reference:
https://github.com/MicrosoftDocs/defender-docs/blob/public/defender-xdr/phishing-triage-agent.md

by Richard at Sep 10, 2026, 07:02 AM

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
Nick name: Submit Cancel
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

0
0
0
10