SC-200 Manage a security operations environment Practice Question
You are managing a Microsoft Sentinel environment with multiple workspaces across different regions. You need to centralize incident management and allow security analysts to triage incidents from all workspaces in a single view. What should you configure?
⚠ Common exam trap
Test-takers frequently confuse Azure Lighthouse's cross-tenant management capabilities with the specific need to aggregate incidents into a single view, overlooking that Lighthouse alone does not merge incident queues across workspaces.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure a central Microsoft Sentinel workspace with cross-workspace analytics rules.
Cross-workspace analytics rules in Microsoft Sentinel allow you to define a single analytics rule that queries multiple workspaces, enabling centralized incident creation and management. This configuration ensures that security analysts can view and triage incidents from all workspaces in a single Microsoft Sentinel instance, without needing to switch between different workspace blades.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Configure a central Microsoft Sentinel workspace with cross-workspace analytics rules.
Why this is correct
A central Microsoft Sentinel workspace with cross-workspace analytics rules is the correct approach because it lets you define detection rules that query multiple workspaces (e.g., via the workspace() expression or union operator) and route resulting alerts into a single incident queue. This consolidates detection and incident management so security teams can investigate correlated events across all environments without manually stitching incidents together. It also aligns with Sentinel's native support for centralized SOC operations, where one workspace serves as the primary monitoring and response hub.
- ✗
Create a workbook that queries all workspaces.
Why it's wrong here
Creating an Azure Monitor workbook that queries all workspaces is for interactive visualization and reporting, not for operational incident management. Workbooks can display KQL query results from multiple workspaces in dashboards, but they cannot generate alerts, create incidents, or aggregate detection signals into a single queue. Therefore, this option fails to satisfy the requirement of centralizing or consolidating incidents in Sentinel.
- ✗
Use the Microsoft Sentinel SIEM Migration experience.
Why it's wrong here
The Microsoft Sentinel SIEM Migration experience is designed to facilitate onboarding from legacy SIEMs (such as Splunk or ArcSight) by translating detection rules and assisting with data ingestion. It does not address the consolidation of multiple existing Sentinel workspaces into a centralized incident management model. Thus, using this migration tool would not help aggregate or centralize incidents across your current multi-workspace deployment.
- ✗
Use Azure Lighthouse to manage all workspaces from a single pane of glass.
Why it's wrong here
Azure Lighthouse provides cross-tenant management and a single-pane-of-glass view by delegating access to multiple subscriptions or resource groups, but it does not merge or consolidate Sentinel incidents across workspaces. Each workspace retains its own separate incident list and analytics rules, so security analysts would still need to manually correlate incidents from different workspaces. This option improves administrative efficiency but fails to deliver centralized incident aggregation, making it incorrect for this scenario.
Go deeper
Related to this question
About these practice questions
This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.