Courseiva

SC-200 Manage a security operations environment Practice Question

Your company deploys Microsoft Sentinel in a multi-workspace environment. You need to centralize incident management across workspaces while maintaining data residency. You configure Sentinel workspaces in each region. What additional configuration is required to view all incidents from a single pane?

⚠ Common exam trap

Candidates often confuse deploying the Sentinel solution (Option A) with enabling cross-workspace views, but the solution deployment is a separate prerequisite and does not itself provide centralized incident management.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use an incident manager with a cross-workspace view.

Microsoft Sentinel supports cross-workspace incident management through the incident manager, which can be configured to display incidents from multiple workspaces in a single view. This is achieved by using the 'cross-workspace view' feature, which leverages Azure Resource Graph to query incidents across workspaces without moving data, thus maintaining data residency requirements.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Deploy the Microsoft Sentinel solution across workspaces.

    Why it's wrong here

    Deploying Sentinel solution content across workspaces only installs analytics rules, workbooks, and playbooks into each Log Analytics workspace; it does not unify the incident repositories. Incidents are always persisted in the workspace where the underlying telemetry lives, so the Incident blades remain separate and the SOC still must navigate workspace by workspace. This action broadens coverage but fails to provide the centralized incident pipeline required.

  • ✗

    Assign the same Azure RBAC roles to all users in each workspace.

    Why it's wrong here

    Azure RBAC assignments determine who can read or modify each workspace's Sentinel resources, yet they have no influence over incident storage or aggregation. Granting identical roles to every user simply allows access to multiple independent Incident blades, forcing analysts to switch workspace contexts and mentally correlate findings. RBAC is an authorization mechanism, not a data-plane fusion service, so it cannot consolidate incidents.

  • ✗

    Merge the workspaces into a single workspace.

    Why it's wrong here

    Log Analytics workspaces cannot be merged across geographic regions, and Azure does not support moving existing workspace data across data-residency boundaries, so this option invalidates compliance requirements. Even in a single region, merging would require re-architecting all data connectors and collection pipelines, causing significant downtime and configuration loss. The scenario specifically calls for preserving a multi-workspace setup, not dismantling it.

  • ✓

    Use an incident manager with a cross-workspace view.

    Why this is correct

    Using an incident manager with a cross-workspace view is the correct approach because Microsoft Sentinel can aggregate incidents from multiple workspaces through Azure Lighthouse delegation. A central SOC workspace can then query and manage incidents across all listed workspaces from a single pane of glass, while each workspace retains its data residency and collection boundaries. This directly centralizes the incident lifecycle—triage, assignment, and closure—without duplicating configuration or merging data stores.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.