Free Microsoft SC-401 Actual Exam Questions - Question 12 Discussion

Question No. 12
You have a Microsoft 365 E5 subscription that contains a user named User1. You deploy Microsoft
Purview Data Security Posture Management for AD (DSPM for AD). You need to ensure that User1
can verify the auditing status of the subscription. The solution must follow the principle of least
privilege. To which role group should you add User1?
Select one option, then reveal solution.
US
AK
Ahmed K.
2026-02-20

D imo, the View-Only Organization Management role is mostly tied to Exchange Online and wouldn’t cover auditing status across Microsoft Purview. Insider Risk roles (A and C) focus on risk investigations, which seems overkill and unrelated. B makes sense because Security Reader is designed for read-only access to security features, which would logically include auditing status. So, I’d skip the others since they either grant too many privileges or don’t fit the auditing context.

0
SS
Sarah S.
2026-02-16

Option B makes the most sense since it’s designed for security-related read-only access across the tenant, which should include auditing info. The Exchange role is too narrow and risk roles are unrelated here.

0
SS
Sarah S.
2026-02-11

It’s B. The Insider Risk roles (A and C) focus on risk investigations and aren’t relevant for just checking audit status. The Exchange Online role (D) is too specific to Exchange and doesn’t cover overall security posture or auditing in DSPM for AD. Security Reader (B) is designed exactly for read-only access to security-related info, so User1 can verify auditing without extra permissions. This fits the principle of least privilege perfectly, since they get only the visibility needed without any ability to modify settings.

0
AX
Ahmed X.
2026-01-20

It’s B for sure. The Security Reader role lets User1 see auditing details without any edit rights, which fits the least privilege rule perfectly. The other roles are way too broad or unrelated.

0
AX
Ahmed X.
2026-01-19

B imo, because User1 just needs to view auditing info without making changes. A or C sound more about managing insider risks, which is more than needed.

0
CZ
Chris Z.
2026-01-15

B, only lets you read security info without extra permissions.

0
UE
Usman E.
2026-01-15

B imo

0