Courseiva

SC-200 Manage a security operations environment Practice Question

Your organization has Microsoft Sentinel deployed across multiple workspaces for different business units. The security team wants to view a unified incident queue across all workspaces. What should you implement?

⚠ Common exam trap

Test-takers frequently confuse Azure Lighthouse (which enables cross-workspace management but not a unified incident queue) with the native cross-workspace query and incident view capabilities in Sentinel, leading them to choose option C instead of A.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create cross-workspace queries and use the incident view with workspace references

Microsoft Sentinel supports cross-workspace incident viewing through the use of workspace references in queries and the unified incident view. By configuring cross-workspace queries and enabling the incident view with workspace references, the security team can aggregate and display incidents from multiple Sentinel workspaces in a single queue, providing a unified view without moving data.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Create cross-workspace queries and use the incident view with workspace references

    Why this is correct

    Microsoft Sentinel supports cross-workspace analytics rules that use the workspace() KQL expression to query data from multiple workspaces in a single detection rule. In the incidents blade, you can add workspace references to display and triage incidents from all connected workspaces in one queue, without duplicating data. This preserves data residency and access control while giving security analysts a unified incident management experience across the entire organization.

  • ✗

    Use Microsoft Defender XDR portal to view all incidents

    Why it's wrong here

    The Microsoft Defender XDR portal is designed to aggregate incidents from Microsoft 365 Defender products, such as Defender for Endpoint, Office 365, and Identity, rather than from Microsoft Sentinel's analytics rules. Even when you enable the unified SOC experience, only Sentinel incidents that are specifically connected via the incident sync are shown, and cross-workspace Sentinel incidents are not automatically visible. Relying on this portal alone would miss Sentinel-only detections and fragment your security operations workflow.

  • ✗

    Use Azure Lighthouse to manage multiple workspaces

    Why it's wrong here

    Azure Lighthouse is a management service that enables delegated resource administration across tenants, allowing MSSPs to manage multiple customer Sentinel workspaces with a single control plane for configuration and role assignments. However, it does not aggregate incident data or merge incident queues; each workspace keeps its own incidents, analytics rules, and alert states. Without additional cross-workspace queries or a custom incident forwarding mechanism, analysts would still need to navigate between different workspaces to perform triage.

  • ✗

    Configure a single workspace to receive all incidents

    Why it's wrong here

    Consolidating all data into a single workspace sounds ideal, but it requires every data source to be reconfigured through connectors, diagnostic settings, and agent routing, which may be impossible for sources with strict data-residency or regulatory requirements. Additionally, concentrating all telemetry into one Log Analytics workspace can easily exceed data ingestion or retention limits, degrading query performance and increasing costs. Finally, distributed organizations with separate security teams or business units often need independent workspaces for access control, making this approach impractical for most real-world deployments.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on SC-200

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. You are managing a Microsoft Sentinel environment with multiple workspaces across different regions. You need to centralize incident management and allow security analysts to triage incidents from all workspaces in a single view. What should you configure?

medium
  • ✓ A.Configure a central Microsoft Sentinel workspace with cross-workspace analytics rules.
  • B.Create a workbook that queries all workspaces.
  • C.Use the Microsoft Sentinel SIEM Migration experience.
  • D.Use Azure Lighthouse to manage all workspaces from a single pane of glass.

Why A: Cross-workspace analytics rules in Microsoft Sentinel allow you to define a single analytics rule that queries multiple workspaces, enabling centralized incident creation and management. This configuration ensures that security analysts can view and triage incidents from all workspaces in a single Microsoft Sentinel instance, without needing to switch between different workspace blades.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.