Courseiva

AZ-500 Practice Question: Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel

You are designing a Microsoft Sentinel deployment for a multinational company. The company requires that data from different geographic regions be stored separately to comply with data residency laws. What is the recommended approach?

⚠ Common exam trap

A common mix-up: candidates think data collection rules or diagnostic settings can route data to different storage accounts or workspaces within a single Sentinel instance, but Sentinel's architecture requires each workspace to be a separate Log Analytics workspace with its own regional binding.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Deploy a separate Microsoft Sentinel workspace in each required region.

Microsoft Sentinel is built on top of Log Analytics workspaces, and each workspace is a distinct data container with its own retention, encryption, and geographic location. To comply with data residency laws that require data from different regions to be stored separately, you must deploy a separate Sentinel workspace in each required region. This ensures that data ingested from a specific region remains within that region's boundaries and is not mixed with data from other regions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Deploy a single Sentinel workspace and use Azure Purview to tag data for residency.

    Why it's wrong here

    Azure Purview (now Microsoft Purview) is a unified data governance service for cataloging, classifying, and auditing data lineage; it does not influence where Log Analytics physically stores Sentinel data. A Sentinel deployment always writes to a single Log Analytics workspace, and Purview tags merely annotate assets without copying or moving them. Residency compliance requires committed in-region storage, which tagging can neither create nor enforce.

  • ✗

    Deploy a single Sentinel workspace and configure diagnostic settings to send data to separate Log Analytics workspaces.

    Why it's wrong here

    Diagnostic settings send telemetry from Azure resources to one or more Log Analytics workspaces, but Sentinel is bound to exactly one workspace as its data store; you cannot use diagnostic settings to redistribute a Sentinel workspace's existing security data into other workspaces. Furthermore, configuring diagnostics on multiple source subscriptions would create independent ingestion pipelines, not a single logical Sentinel view. To use separate workspaces you would need separate Sentinel instances, which contradicts the option's premise.

  • ✗

    Deploy a single Sentinel workspace and use data collection rules to route data to different storage accounts.

    Why it's wrong here

    Data collection rules (DCRs) in Azure Monitor shape which tables agent data goes to and can send to a workspace or custom endpoint, but they do not partition a single workspace's data across multiple storage accounts or regions. A Log Analytics workspace is backed by one dedicated storage cluster in its home region; DCRs cannot reroute Sentinel's stored security events into different storage accounts on a per-event basis. Thus this approach could not achieve geolocation-based residency inside one workspace.

  • ✓

    Deploy a separate Microsoft Sentinel workspace in each required region.

    Why this is correct

    Each Microsoft Sentinel workspace is functionally a Log Analytics workspace with Sentinel enabled, and the workspace's location determines where all underlying data is stored at rest. Deploying Sentinel in each required region creates separate, region-pinned data stores that fully contain that region's logs, satisfying residency requirements. This also allows rules and workbooks to be scoped to local data, though cross-workspace queries or Azure Lighthouse can still provide a pane-of-glass view for centralized monitoring.

About these practice questions

Courseiva writes every AZ-500 question from scratch — 617 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.