hardMultiple Choice
SC-200 Practice Question: A SOC analyst is configuring a multi-region…
A SOC analyst is configuring a multi-region deployment of Microsoft Sentinel. The requirement is to ingest security logs from Azure resources located in three different Azure regions. The analyst needs to create the workspace in one region and then use cross-workspace queries to view data from all regions. What is the correct sequence of steps?
⚠ Common exam trap
Test-takers frequently assume a single central workspace can ingest logs from all regions, but the question explicitly requires using cross-workspace queries, which necessitates separate workspaces per region.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Step 1: Create Log Analytics workspaces in each region. Step 2: Enable Sentinel on each workspace. Step 3: Connect data sources. Step 4: Configure cross-workspace queries.
To use cross-workspace queries in Microsoft Sentinel, you must first create a Log Analytics workspace in each region, enable Sentinel on each workspace, connect the data sources to their respective regional workspaces, and then configure cross-workspace queries to unify the data. This sequence ensures that each region's logs are ingested locally, which is required for cross-workspace queries to reference them via the `workspace()` expression.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Step 1: Create Log Analytics workspaces in each region. Step 2: Enable Sentinel on each workspace. Step 3: Connect data sources. Step 4: Configure cross-workspace queries.
Why this is correct
This sequence is correct because Microsoft Sentinel is built on top of a Log Analytics workspace; the workspace must be provisioned before Sentinel can be enabled. Enabling Sentinel on each regional workspace first ensures that the data connectors have a valid destination and can immediately begin ingesting and normalizing logs. Once all regional workspaces have Sentinel active, you can configure cross-workspace queries to unify monitoring while preserving data residency, which is the recommended pattern for multi-region deployments.
- ✗
Step 1: Enable Sentinel in one region. Step 2: Create workspaces in other regions. Step 3: Connect data sources. Step 4: Configure cross-workspace queries.
Why it's wrong here
This order fails because you cannot enable Microsoft Sentinel without first having a Log Analytics workspace to host it—Sentinel is a solution that attaches to an existing workspace. Even if you enabled Sentinel in one region, the other regions would still not have workspaces or Sentinel, meaning you would have to repeat the enable step after creating them. Additionally, the single Sentinel instance cannot ingest data from regional workspaces that do not exist yet, so the sequence is technically invalid from the start.
- ✗
Step 1: Connect data sources. Step 2: Create workspaces. Step 3: Enable Sentinel. Step 4: Configure cross-workspace queries.
Why it's wrong here
Connecting data sources before creating any Log Analytics workspace is technically impossible because the data connectors require an existing workspace as the storage and indexing destination. A Log Analytics workspace must first be created, and Sentinel should be enabled on that workspace before you configure connectors to collect security logs. Attempting to connect sources first would fail because there is no workspace resource to receive and retain the telemetry, making this sequence non-functional.
- ✗
Step 1: Create a central workspace. Step 2: Enable Sentinel on it. Step 3: Connect data sources from all regions to the central workspace. Step 4: Configure cross-workspace queries.
Why it's wrong here
This approach contradicts the recommended multi-region deployment pattern. While a single central workspace can technically receive logs from all regions, doing so forces data to leave its region of origin, potentially violating data residency requirements and introducing latency and egress costs. The correct architecture is to keep data in the workspace of the region where it is generated, then use cross-workspace queries to correlate and investigate incidents without physically centralizing the data.
Go deeper
Related to this question
About these practice questions
This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.