SC-200 • Practice Test 4 — 25 Questions
Free SC-200 practice test 4 — 25 questions with explanations. No signup required.
A SOC team uses Microsoft Sentinel with multiple workspaces in a single region. They have deployed Azure Policy to send all Azure resource logs to a central Log Analytics workspace. Now they want to create a set of analytics rules that run across multiple workspaces to detect cross-workspace attacks. However, they note that the built-in analytics rules can only query data within the workspace they are defined. Which solution should the team implement to efficiently query data from multiple workspaces for detection?
Choose an answer to begin — your selection is scored in the full session.
25 questions · instant feedback and full explanations after every question.