Courseiva

SC-200 Manage a security operations environment Practice Question

You are a security operations architect for a company that uses Microsoft Sentinel in a hybrid environment with multiple workspaces. The company has a central SOC team that needs to view incidents from all workspaces in a single pane of glass. Each workspace belongs to a different business unit and has its own retention and access policies. You need to design a solution that provides centralized incident management without duplicating data or requiring users to switch workspaces. You also need to ensure that the SOC team can perform actions on incidents across workspaces. What should you do?

⚠ Common exam trap

Test-takers frequently confuse data connectors or workspace aggregation with incident-level cross-workspace management, failing to realize that incident multi-view is the only native feature that provides a single pane of glass without data duplication or policy compromise.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use Microsoft Sentinel incident multi-view to connect all workspaces.

Microsoft Sentinel incident multi-view allows SOC teams to view and manage incidents across multiple workspaces from a single interface without duplicating data. This feature provides a centralized pane of glass while respecting each workspace's independent retention and access policies, and it enables cross-workspace incident actions without requiring users to switch contexts.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create a playbook that copies incidents from all workspaces to a central workspace.

    Why it's wrong here

    Creating a playbook to copy incidents from all workspaces to a central workspace is not a native capability in Microsoft Sentinel; it would require custom API calls to read incident JSON from each workspace and write it into another, duplicating state and risking data inconsistency. Playbooks are automation triggers tied to alerts or incidents in a single workspace; they do not provide a built-in replication mechanism, and every sync failure would cause missed updates and conflicting ownership, making it operationally brittle and unsupported in a multi-workspace architecture.

  • ✓

    Use Microsoft Sentinel incident multi-view to connect all workspaces.

    Why this is correct

    Microsoft Sentinel incident multi-view natively connects all workspaces by allowing a single dedicated workspace to display incidents from every workspace in a resource scope through the Incidents interface. This provides a centralized incident queue without moving or duplicating log data; analysts can triage and assign incidents across the enterprise while maintaining the original workspace context. It is the correct approach for centralized incident management in a distributed Sentinel deployment.

  • ✗

    Use the Microsoft Sentinel data connector to connect all workspaces to a central workspace.

    Why it's wrong here

    Using a Microsoft Sentinel data connector to connect workspaces to a central workspace is a category error—data connectors ingest log sources like Microsoft Entra ID, Office 365, or custom applications into a workspace, not incidents from other workspaces. Incidents are stateful entities produced by analytics rules in the workspace where the rule runs; no connector exists to pull those incident objects into another workspace. Even if you used a custom API connector, it would only deliver raw events, which would not create or synchronize the incidents themselves.

  • ✗

    Create a new Log Analytics workspace that ingests data from all workspaces via diagnostic settings.

    Why it's wrong here

    Diagnostic settings can stream log data from one Log Analytics workspace to another, but this only copies raw log tables, not the incident metadata or analytic rule state, so the target workspace would have none of the incidents. This approach also doubles ingestion and storage costs and requires you to recreate all analytics rules in the new workspace to generate incidents, after which you still have two separate incident management surfaces rather than a central one. It therefore neither centralizes incidents nor reduces complexity.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.