Design security operations, identity, and compliance capabilities →hardMultiple ChoiceObjective-mapped
SC-100 Practice Question: Design security operations, identity, and compliance capabilities
You are a security architect for a global financial services company. The company is adopting Microsoft Sentinel as its primary SIEM and Microsoft Defender XDR for endpoint, email, and identity protection. The company has a hybrid environment with on-premises Active Directory and Microsoft Entra ID. The SOC team needs to be able to investigate incidents that involve lateral movement between on-premises and cloud resources. Additionally, the company must comply with GDPR, requiring that personal data be protected and that data residency requirements are met: all security logs for EU users must remain within the EU. The company already has a Microsoft Sentinel workspace in the West Europe region. You need to design a solution that meets these requirements while minimizing administrative overhead. What should you do?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use the existing West Europe Sentinel workspace and ensure that all EU user logs are sent to that workspace via diagnostic settings.
A single Microsoft Sentinel workspace in West Europe can collect logs from multiple regions via diagnostic settings, satisfying GDPR data residency by keeping EU logs within the EU. This minimizes administrative overhead. Option A is incorrect because Azure Arc does not address data residency and adds unnecessary complexity. Option C is incorrect because creating a separate workspace increases overhead without benefit, as the existing workspace meets requirements. Option D is incorrect because per-region workspaces greatly increase administrative overhead.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Deploy Azure Arc on on-premises servers and use Azure Policy to enforce log collection to the West Europe workspace.
Why it's wrong here
Azure Arc is used for managing on-premises servers, but it does not control data residency. Logs will still be sent to the West Europe workspace. This option does not address GDPR data residency requirements and adds unnecessary complexity.
- ✓
Use the existing West Europe Sentinel workspace and ensure that all EU user logs are sent to that workspace via diagnostic settings.
Why this is correct
Correct. A single Sentinel workspace can collect logs from multiple regions. By using the existing West Europe workspace and configuring diagnostic settings to send all EU user logs there, data residency requirements are met with minimal administrative overhead.
- ✗
Create a new Sentinel workspace in the EU region for EU logs and a separate workspace for non-EU logs.
Why it's wrong here
Creating a separate EU Sentinel workspace alongside the existing West Europe workspace is redundant because West Europe is already an EU region and fully satisfies GDPR data-residency requirements for EU logs. Splitting logs into EU and non-EU workspaces would force analysts to pivot between unrelated security consoles, breaking cross-correlation of threat campaigns that span regions. It also doubles licensing costs, requires duplicate data connectors and role assignments, and adds no compliance benefit over routing all logs to the one existing West Europe workspace via diagnostic settings.
- ✗
Deploy a separate Sentinel workspace in each region where you have users.
Why it's wrong here
Deploying a Sentinel workspace in every region where users reside shatters security operations into isolated silos, each with its own analytics rules, playbooks, and alert tuning. Microsoft Sentinel does not natively centralize querying across workspaces, so a distributed attack path would go unnoticed unless you build custom cross-workspace queries or rely on Azure Lighthouse. GDPR requires only that EU user data stay within the EU, not that it reside in the user's exact country, so a single West Europe workspace meets residency needs while preserving unified monitoring and management.
Go deeper
Related to this question
Learn chapter
Understanding the Cybersecurity Architect Role and Exam Scope
Key term
SOC Architecture
SOC Architecture is the structured design of people, processes, and technology in a Security Operations Center to detect, analyze, and respond to cyber threats.
Key term
XDR Strategy
An XDR strategy is a plan to use extended detection and response tools that collect and analyze data from multiple security layers to stop cyberattacks more effectively.
About these practice questions
This SC-100 question is part of Courseiva's 208-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.