Azure サブスクリプションには、Workspace1 という名前の Microsoft Sentinel ワークスペースと User1 という名前のユーザーが含まれています。 User1がWorkspace1を使用してインシデントを調査できるようにする必要があります。このソリューションは、最小権限の原則に従う必要があります。 User1にはどの役割を割り当てるべきですか?
正解:A
The Microsoft Sentinel Responder role is specifically designed for users who need to investigate and respond to incidents in Microsoft Sentinel. This role provides the necessary permissions to investigate incidents and alerts, while adhering to the principle of least privilege, as it does not grant permissions beyond what is needed for incident response.