Exam SC-500 Topic 1 Question 45 Discussion
Actual exam question for Microsoft's SC-500 exam
Question #: 45
Topic #: 1
Question #: 45
Topic #: 1
You use Microsoft Security Copilot.
Security Copilot contributors currently create custom plugins for their own sessions and manage organization- wide custom plugins.
You need to prevent the contributors from managing the organization-wide custom plugins. The solution must NOT affect the contributors ' ability to create custom plugins for their own sessions.
What should you select in the Plugin settings?
Security Copilot contributors currently create custom plugins for their own sessions and manage organization- wide custom plugins.
You need to prevent the contributors from managing the organization-wide custom plugins. The solution must NOT affect the contributors ' ability to create custom plugins for their own sessions.
What should you select in the Plugin settings?
Suggested Answer: D Vote an answer
Organization-wide custom plugin management is a tenant-scope administrative action. Setting the plugin setting to Owners only at the tenant scope removes that capability from contributors while leaving their user- scope session plugin ability unaffected. Moving ownership to user scope would not govern tenant-wide plugins correctly. Allowing contributors at tenant scope preserves the problem. The selected setting separates personal experimentation from organization-wide plugin governance. For SC-500, the decisive distinction is whether the control authenticates an identity, grants authorization, or merely changes configuration visibility.
The incorrect choices generally either grant excessive privilege, change the application model, or operate at the wrong scope. Microsoft expects the least-privilege identity path that satisfies the scenario without introducing shared secrets or unnecessary tenant-wide rights. The result is a direct exam-style implementation choice: it changes the required security behavior without relying on unrelated monitoring, manual cleanup, or excessive privilege. Official Microsoft source/topic: SC-500 Study Guide > Security Copilot plugins; Microsoft Learn > manage custom plugins and owner/contributor scope.
The incorrect choices generally either grant excessive privilege, change the application model, or operate at the wrong scope. Microsoft expects the least-privilege identity path that satisfies the scenario without introducing shared secrets or unnecessary tenant-wide rights. The result is a direct exam-style implementation choice: it changes the required security behavior without relying on unrelated monitoring, manual cleanup, or excessive privilege. Official Microsoft source/topic: SC-500 Study Guide > Security Copilot plugins; Microsoft Learn > manage custom plugins and owner/contributor scope.
by Kim at Jun 16, 2026, 12:47 AM
0
0
0
10
Comments
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
Report Comment
Commenting
You can sign-up / login (it's free).