Your company deploys the following services: Microsoft Defender for Identity Microsoft Defender for Endpoint Microsoft Defender for Office 365 You need to provide a security analyst with the ability to use the Microsoft 365 security center. The analyst must be able to approve and reject pending actions generated by Microsoft Defender for Endpoint. The solution must use the principle of least privilege. Which two roles should assign to the analyst?
Q: 15
Options
Discussion
B D, saw a similar one on a practice set. Security Reader for least privilege read, Active remediation for actions. Matches up.
B and C imo. Active remediation actions in Defender for Endpoint gives the approval power but I think Security Administrator is needed for wider security center access, not just reading. Least privilege angle is tricky here, but D (Security Reader) feels like it's view-only, can't approve actions. Anyone see it differently for least privilege cases?
Be respectful. No spam.
Question 15 of 35