Courseiva

SC-200 Manage a security operations environment Practice Question

You have a Microsoft Sentinel workspace that uses Customer-Managed Keys (CMK). A security audit requires that all data at rest be encrypted with the CMK. You recently onboarded a new data connector that sends logs to a Log Analytics workspace in a different region. You need to ensure the new workspace uses CMK. What should you do?

⚠ Common exam trap

It's easy for candidates to think CMK can be applied after data ingestion or per table, but Microsoft Sentinel requires CMK to be configured before any data is written to the workspace.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Associate the new Log Analytics workspace with an Azure Key Vault containing the CMK before ingesting data.

Customer-Managed Keys (CMK) for Log Analytics workspaces must be configured at workspace creation time or before any data is ingested. The CMK is associated with the workspace via an Azure Key Vault, and once data is written, the encryption key cannot be changed. Therefore, to ensure the new workspace in a different region uses CMK, you must associate it with the Key Vault containing the CMK before any logs are ingested.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Associate the new Log Analytics workspace with an Azure Key Vault containing the CMK before ingesting data.

    Why this is correct

    CMK configuration must occur before any data is written because Log Analytics binds the customer-managed key to the workspace's encryption context at provisioning time. After ingestion, the key association cannot be retroactively changed; enabling CMK on a workspace with existing data is not supported. Therefore, you must create the new workspace, associate it with the Key Vault key, and only then connect data sources.

  • ✗

    Update the data connector settings to enable CMK at the source.

    Why it's wrong here

    Data connectors (e.g., Azure Activity, Security Events, Microsoft Defender) are pipelines that send logs into the workspace; they only define what sources to collect and how, not how the workspace encrypts stored data. There is no CMK or encryption-key setting within any data connector's configuration blade. CMK is an encryption-at-rest property of the Log Analytics workspace itself, so modifying connector settings cannot affect key management.

  • ✗

    Use Azure Policy to enforce CMK on the new workspace.

    Why it's wrong here

    Azure Policy can enforce an 'audit' or 'deny' effect requiring CMK on new workspaces, but it cannot perform the actual association or replace the required initial configuration step. You still must create the workspace and manually link it to an Azure Key Vault key before ingestion; otherwise, Policy might flag it as non-compliant or block creation, but it won't provision the key link. Policy is a governance guardrail, not a deployment action, so it does not satisfy the 'before ingestion' requirement.

  • ✗

    Configure CMK on the new workspace's tables individually.

    Why it's wrong here

    CMK in Log Analytics is a workspace-level encryption setting applied to the entire Azure Storage account that backs all tables, not an individual table-setting operation. Tables like Sentinel's SecurityEvent, Heartbeat, and CommonSecurityLog share the same underlying storage and therefore inherit the same customer-managed key. The portal/API expose no option to configure different encryption keys per table, so this approach does not exist.

About these practice questions

This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.