SC-200 Manage a security operations environment Practice Question
Your organization has deployed Microsoft Sentinel in multiple regions. You need to ensure that incidents created in one workspace are available for correlation in a central workspace. What should you implement?
⚠ Common exam trap
It's easy for candidates to confuse cross-workspace queries (which allow querying data across workspaces but do not replicate incidents) with the native incident replication feature, leading them to select Option A instead of the correct Workspace Manager solution.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Sentinel workspace manager (incident replication)
Sentinel Workspace Manager (incident replication) is the correct choice because it provides native, built-in replication of incidents from multiple workspaces to a central workspace without requiring custom code or external automation. This feature ensures that incidents created in regional workspaces are automatically synchronized to a designated central workspace, enabling unified correlation and investigation across regions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Cross-workspace queries in KQL
Why it's wrong here
KQL cross-workspace queries (using workspace() or union operators) are designed for ad-hoc hunting and detection across multiple Log Analytics workspaces, returning combined raw events or tables. They do not create, update, or synchronize any Sentinel incident objects, so an incident raised in a child workspace never appears in a central workspace as a managed entity. Thus, while useful for investigation, KQL queries do not fulfill the requirement of replicating incidents to a central location.
- ✓
Sentinel workspace manager (incident replication)
Why this is correct
Sentinel workspace manager's incident replication feature is the native, built-in mechanism that replicates incidents from multiple workspaces to a central workspace, providing a single pane of glass for SOC triage. It maintains a one-way copy of incident metadata and status in the central workspace, enabling centralized metrics, queries, and automation without altering the original incident. This is the recommended method over custom exports or cross-workspace queries because it is purpose-built for incident aggregation and requires no manual pipeline.
- ✗
Automated export of incidents to central workspace using Logic Apps
Why it's wrong here
Using Azure Logic Apps to automate incident export is technically feasible, as you can connect to the Microsoft Sentinel API and push incident data to a central workspace's tables or a custom connector. However, this approach is not the recommended built-in solution because it requires you to build and maintain the entire replication pipeline, including handling updates, deletions, and pagination, and it does not provide native incident tracking integration. It also introduces latency, complexity, and potential consistency issues that the workspace manager feature is designed to avoid.
- ✗
Azure Lighthouse
Why it's wrong here
Azure Lighthouse enables a service provider or central security team to manage multiple customer or tenant Sentinel workspaces through delegated access, allowing cross-tenant visibility and creation of custom ARM templates. It does not, however, replicate incidents; it merely extends management plane access, so incidents remain siloed in each workspace unless another mechanism copies them. Therefore, Lighthouse is a management and governance tool, not an incident replication capability.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.