Courseiva

AZ-500 Practice Question: Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel

Your company has Microsoft Sentinel deployed in multiple workspaces across several Azure regions. The security operations team wants to query data from all workspaces centrally using a single KQL query. What feature should you implement?

⚠ Common exam trap

Test-takers frequently confuse the workspace() expression with the legacy linked workspace feature (Option A) or assume that a central aggregation mechanism (like a SIEM connector or data export) is required, when in fact KQL's native cross-workspace querying is the simplest and most cost-effective solution.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use cross-workspace queries with the workspace() expression in KQL.

The workspace() expression in KQL allows you to include tables from multiple Log Analytics workspaces in a single query, enabling centralized querying across all Microsoft Sentinel workspaces without moving or aggregating data. This is the native and recommended approach for cross-workspace queries in Azure Sentinel.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Configure Log Analytics workspaces as linked to a central workspace.

    Why it's wrong here

    Linking workspaces is not a native capability in Log Analytics or Microsoft Sentinel. Each Sentinel deployment is bound to a single Log Analytics workspace, and there is no configuration setting that transparently merges two or more workspaces into a unified query boundary. The native pattern for querying across multiple workspaces is to explicitly reference each workspace in KQL using the workspace() expression, so any attempt to 'link' them would rely on unsupported or non-existent functionality.

  • ✓

    Use cross-workspace queries with the workspace() expression in KQL.

    Why this is correct

    The workspace() expression in KQL—e.g., union workspace('Contoso-Sentinel').SecurityEvent, workspace('Fabrikam-Sentinel').SecurityEvent—lets you query tables across multiple Log Analytics workspaces in a single query. This is the Azure-native mechanism designed for Microsoft Sentinel multi-workspace scenarios and works without duplicating data or adding an extra ETL layer. It also supports resource-id based references, so you can query Sentinel workspaces that data is retained in while preserving the full context of the original table schema.

  • ✗

    Export all data to Azure Data Explorer and query there.

    Why it's wrong here

    Exporting all Sentinel workspaces to Azure Data Explorer is not the recommended approach because it requires either continuous export jobs or event hub pipelines to move the data, which adds cost, complexity, and latency. It also creates a second copy of the data, meaning you now have to manage permissions and data residency in yet another location, and you lose the tight integration of Sentinel's analytics rules, UEBA, and investigation tools that are designed to run directly against Log Analytics tables. Cross-workspace queries remain the simplest supported method for unified querying, avoiding unnecessary duplication or architectural overhead.

  • ✗

    Use the Microsoft Sentinel SIEM connector to aggregate data.

    Why it's wrong here

    The Microsoft Sentinel SIEM connector (such as the Common Event Format or Syslog connectors) is an ingestion mechanism that only forwards logs from external appliances into a single Log Analytics workspace. It does not provide any querying capability of its own, and it cannot aggregate data from multiple existing Sentinel workspaces into a unified query surface. Using the SIEM connector for this requirement misunderstands its purpose: it's a data-in path, not a cross-workspace query layer.

About these practice questions

One of 617 original AZ-500 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.