Courseiva

SC-100 Practice Question: Design security operations, identity, and compliance capabilities

You are a security architect for a global financial services company. The company is adopting Microsoft Sentinel as its primary SIEM and Microsoft Defender XDR for endpoint, email, and identity protection. The company has a hybrid environment with on-premises Active Directory and Microsoft Entra ID. The SOC team needs to be able to investigate incidents that involve lateral movement between on-premises and cloud resources. Additionally, the company must comply with GDPR, requiring that personal data be protected and that data residency requirements are met: all security logs for EU users must remain within the EU. The company already has a Microsoft Sentinel workspace in the West Europe region. You need to design a solution that meets these requirements while minimizing administrative overhead. What should you do?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Use the existing West Europe Sentinel workspace and ensure that all EU user logs are sent to that workspace via diagnostic settings.

A single Microsoft Sentinel workspace in West Europe can collect logs from multiple regions via diagnostic settings, satisfying GDPR data residency by keeping EU logs within the EU. This minimizes administrative overhead. Option A is incorrect because Azure Arc does not address data residency and adds unnecessary complexity. Option C is incorrect because creating a separate workspace increases overhead without benefit, as the existing workspace meets requirements. Option D is incorrect because per-region workspaces greatly increase administrative overhead.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Deploy Azure Arc on on-premises servers and use Azure Policy to enforce log collection to the West Europe workspace.

    Why it's wrong here

    Azure Arc is used for managing on-premises servers, but it does not control data residency. Logs will still be sent to the West Europe workspace. This option does not address GDPR data residency requirements and adds unnecessary complexity.

  • Use the existing West Europe Sentinel workspace and ensure that all EU user logs are sent to that workspace via diagnostic settings.

    Why this is correct

    Correct. A single Sentinel workspace can collect logs from multiple regions. By using the existing West Europe workspace and configuring diagnostic settings to send all EU user logs there, data residency requirements are met with minimal administrative overhead.

  • Create a new Sentinel workspace in the EU region for EU logs and a separate workspace for non-EU logs.

    Why it's wrong here

    Creating a separate EU Sentinel workspace alongside the existing West Europe workspace is redundant because West Europe is already an EU region and fully satisfies GDPR data-residency requirements for EU logs. Splitting logs into EU and non-EU workspaces would force analysts to pivot between unrelated security consoles, breaking cross-correlation of threat campaigns that span regions. It also doubles licensing costs, requires duplicate data connectors and role assignments, and adds no compliance benefit over routing all logs to the one existing West Europe workspace via diagnostic settings.

  • Deploy a separate Sentinel workspace in each region where you have users.

    Why it's wrong here

    Deploying a Sentinel workspace in every region where users reside shatters security operations into isolated silos, each with its own analytics rules, playbooks, and alert tuning. Microsoft Sentinel does not natively centralize querying across workspaces, so a distributed attack path would go unnoticed unless you build custom cross-workspace queries or rely on Azure Lighthouse. GDPR requires only that EU user data stay within the EU, not that it reside in the user's exact country, so a single West Europe workspace meets residency needs while preserving unified monitoring and management.

About these practice questions

This SC-100 question is part of Courseiva's 208-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.