Microsoft 365 B5 サブスクリプションには、Group! と Group2 という名前の 2 つのグループが含まれており、Microsoft Copilot for Security を使用しています。Copilot for Security の役割割り当てを、以下の要件を満たすように構成する必要があります。 * Group1 のメンバーがプロンプトを実行し、Microsoft Defender XDR セキュリティインシデントに対応できることを確認します。 * Group2のメンバーがプロンプトを実行できることを確認してください。 最小権限の原則に従うこと。 コパイロット貢献者ロールから「全員」を削除します。 次に実行すべき2つの行動はどれですか?それぞれの正解は、解決策の一部を示しています。注:正解ごとに1ポイントが加算されます。
正解:A,B
To satisfy the two requirements while following least privilege: (1) members of Group1 must be able to run Copilot prompts and respond to Defender XDR incidents; (2) members of Group2 must only be able to run Copilot prompts. The Copilot Contributor role grants the ability to run and interact with Copilot features (create/run prompts, view Copilot outputs) without broad security admin rights, so assigning Copilot Contributor to Group2 satisfies the "run prompts" requirement with minimal privilege. For Group1, which must additionally respond to incidents, add a security role that allows incident handling - for Defender XDR that responsibility aligns with Security Operator (or equivalent Defender security operator) privileges: the Security Operator role provides permissions to triage, investigate, take responder actions, and perform incident operations but does not grant owner-level or configuration-level permissions. Combining Copilot Contributor behavior (if needed) with Security Operator ensures Group1 can both run prompts and act on incidents. Assigning Copilot Owner or Global elevated roles would violate least privilege; assigning Security Operator to Group2 would grant incident-handling capability that Group2 does not require. Therefore the minimal, correct two actions are: assign Copilot Contributor to Group2 and assign Security Operator to Group1.