SC-200 Manage a security operations environment Practice Question
You are designing a Microsoft Sentinel deployment for a multinational organization that must comply with GDPR and local data residency requirements. They have offices in the US, EU, and Asia. They want to use a single Microsoft Sentinel workspace for global visibility but need to ensure that data from EU sources remains within the EU. What is the best approach to meet these requirements?
⚠ Common exam trap
Many candidates think Azure Lighthouse or cross-workspace queries can magically split a single workspace's storage across regions, when in fact a workspace is a regional resource and data residency requires separate workspaces per region.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Deploy separate Microsoft Sentinel workspaces in the US, EU, and Asia, and use cross-workspace queries and Azure Lighthouse to manage them centrally.
Deploying separate Microsoft Sentinel workspaces in each required region (US, EU, Asia) ensures that data from EU sources remains within the EU, satisfying GDPR and local data residency requirements. Cross-workspace queries and Azure Lighthouse allow centralized management and global visibility across these workspaces without moving data between regions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Deploy a single Microsoft Sentinel workspace in the US and use Azure Policy to restrict data ingestion from EU sources.
Why it's wrong here
A single US-hosted workspace with Azure Policy blocking EU sources would prevent EU telemetry from being collected; Azure Policy can enforce diagnostic settings or data-collection rules, but it cannot reroute log sources to a regional workspace. The result is an incomplete security monitoring footprint and no EU-resident data, which conflicts with the goal of centrally analyzing all regional data.
- ✓
Deploy separate Microsoft Sentinel workspaces in the US, EU, and Asia, and use cross-workspace queries and Azure Lighthouse to manage them centrally.
Why this is correct
Separate Sentinel workspaces placed in the US, EU, and Asia keep each region's log data stored within its corresponding geopolitical boundary, satisfying data-residency requirements. Cross-workspace queries use the workspace() KQL operator to query all three workspaces in one investigation, while Azure Lighthouse grants the central SOC delegated RBAC permissions across subscriptions or tenants without duplicating data. This architecture combines regional compliance with a single-pane-of-glass management experience.
- ✗
Deploy a single workspace in the EU and enable UEBA to analyze all data.
Why it's wrong here
Enabling UEBA in an EU workspace adds entity-behavior profiling to the workspace's analytics, but UEBA does not influence physical storage location or retention. Ingesting US and Asian log sources into that EU workspace writes those regions' data to EU datacenters, which may breach regulations requiring in-country or in-region storage. UEBA also cannot mask or separate data by origin; all entities are blended into one entity timeline regardless of source geography.
- ✗
Use Azure Lighthouse to project a single workspace into multiple regions, which automatically separates data storage.
Why it's wrong here
Azure Lighthouse is a management-plane tool for delegated resource administration across tenants, not a data-replication or geo-striping service. A Microsoft Sentinel workspace is bound to a single home region and all raw data stays in that cluster; Lighthouse only provides cross-tenant views and role assignments. It cannot project a workspace into multiple regions in a way that physically separates storage by locality.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.