Courseiva

SC-100 Practice Question: Design security operations, identity, and compliance capabilities

You are designing a security operations solution for a multinational organization using Microsoft Sentinel. The organization has multiple Azure subscriptions, each with its own Log Analytics workspace. You need to centralize incident management while minimizing data egress costs. What should you recommend?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use a single Log Analytics workspace for all subscriptions and configure Sentinel in that workspace.

Microsoft Sentinel is enabled on a Log Analytics workspace, and using a single workspace for all subscriptions centralizes incident management in one place while avoiding cross-workspace query and data egress charges. All subscriptions can onboard to that workspace via Azure Lighthouse or the Sentinel data connectors, so incidents, analytics rules, and workbooks are managed centrally. Option A does not truly centralize incidents and adds cross-workspace complexity, while Option B sends data to a third-party SIEM and increases egress costs rather than minimizing them. Option C only allows cross-workspace queries for correlation but still leaves incident management distributed across multiple workspaces.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Deploy a Sentinel workspace in each region and use cross-workspace views.

    Why it's wrong here

    Deploying a Sentinel workspace in each region creates a fragmented incident management plane. Each workspace maintains its own incidents, alert rules, and investigation history, and cross-workspace views only visualize data without merging incident ownership or state. This forces manually stitching together responses across regions, incurs cross-region egress charges for any aggregated queries, and undermines a single SOC workflow.

  • ✗

    Export all logs to a third-party SIEM using Azure Event Hubs.

    Why it's wrong here

    Exporting logs to a third-party SIEM via Azure Event Hubs introduces a parallel security pipeline, adding costs for Event Hubs throughput, data egress, and the external SIEM itself. It also sacrifices native Sentinel capabilities such as UEBA, built-in threat intelligence, and automated Playbooks, while introducing latency and additional infrastructure to secure. This approach diverges from consolidating incident management into a single Microsoft Sentinel workspace.

  • ✗

    Configure Azure Monitor cross-workspace queries to correlate incidents.

    Why it's wrong here

    Azure Monitor cross-workspace queries are analytical tools that can aggregate data across Log Analytics workspaces, but they do not centralize incident management. Incidents remain discrete objects with independent state, assignments, and severity, so a responder still has to toggle between workspaces to act on them. The queries merely aid investigation, not the unified command-and-control that a single incident queue provides.

  • ✓

    Use a single Log Analytics workspace for all subscriptions and configure Sentinel in that workspace.

    Why this is correct

    A single Log Analytics workspace for all subscriptions lets Microsoft Sentinel ingest every security log into one repository, so incidents are generated and managed from a unified console. This eliminates cross-region egress fees and enables seamless correlation across subscriptions, while also simplifying automation, access control, and compliance reporting. One caveat is that workspace scale limits and data sovereignty must be carefully evaluated, but for most SOC designs this is the recommended pattern.

About these practice questions

This SC-100 question is part of Courseiva's 605-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.