AZ-500 Practice Question: Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel
You are a security engineer for a large enterprise using Microsoft Sentinel. You have multiple workspaces deployed across different Azure regions to meet data residency requirements. You need to query data across all workspaces from a single query. You have set up a workspace as the 'central' workspace for cross-workspace queries. The central workspace has the necessary permissions to access the other workspaces. Which KQL operator should you use to include data from other workspaces in your query?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
union
The correct option is B, the union operator, because in Microsoft Sentinel and Azure Monitor Log Analytics, cross-workspace queries are performed by using union with workspace identifiers, such as union workspace("WorkspaceName").TableName, which combines rows from tables in the central workspace and the referenced workspaces into a single result set. This matches the scenario where the central workspace has permissions to query the other workspaces for data residency-compliant cross-region reporting. The where operator only filters rows within a single table and cannot reference another workspace, join correlates columns across tables but does not by itself aggregate multiple workspaces, and project only selects or renames columns from an existing result set. Therefore, union is the only operator that satisfies the requirement to include data from other workspaces in one query.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
where
Why it's wrong here
Wrong. The where operator is a filtering operation that uses logical predicates (e.g., ==, contains, timestamp > ago()) to retain only matching rows from the data already in the current query scope. A filter can reduce the volume of events, but it cannot reach outside the current workspace to bring in log sources from another workspace, so it cannot be used to perform a cross-workspace query.
- ✓
union
Why this is correct
Correct. In Kusto Query Language (KQL), the union operator merges rows from two or more table expressions, and its workspace('workspace-id') function lets each branch point to another Log Analytics/Microsoft Sentinel workspace. This makes union the fundamental operator for cross-workspace queries: each table reference can be rewritten as workspace('<workspace>').<Table>, and the results are concatenated into a single result set.
- ✗
join
Why it's wrong here
Wrong. join is a binary operator that horizontally combines two row sets by matching values on one or more key columns, producing a result with the merged schema (all left and right columns). To use join across workspaces, each side of the join would still need an explicit workspace() reference, and join itself does not select databases or workspaces to query. It is designed for correlating events within the available input sets, not for collecting data out of multiple workspaces.
- ✗
project
Why it's wrong here
Wrong. project is a column-based shaping operator that selects, renames, and drops columns from the output of the query, effectively defining the result schema. It operates only on rows that have already been retrieved from a table, view, or another expression; it has no ability to connect to another workspace or pull data in. Cross-workspace queries require an operator that combines input sources, and project cannot introduce new workspaces.
Go deeper
Related to this question
About these practice questions
One of 617 original AZ-500 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.