SC-200 Manage a security operations environment Practice Question
Your organization is implementing Microsoft Sentinel in a multi-tenant environment using Azure Lighthouse. The SOC team needs to investigate incidents across all tenants from a single interface. Which configuration is required?
⚠ Common exam trap
Watch out — candidates often confuse Microsoft Entra B2B (external user access) with Azure Lighthouse (delegated resource management), assuming that granting external identities access to a single workspace is sufficient for multi-tenant incident investigation, when in fact Lighthouse is required to project multiple workspaces into a single management plane.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Onboard multiple workspaces to Azure Lighthouse and use a central workspace for investigation.
Azure Lighthouse enables cross-tenant management by allowing the SOC team to delegate access to multiple Sentinel workspaces from a single control plane. This configuration lets investigators view and manage incidents across all tenants without needing separate sign-ins or duplicating data, which is essential for a multi-tenant SOC environment.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use Microsoft Entra B2B to grant users from other tenants access to the workspace.
Why it's wrong here
Microsoft Entra B2B grants external guest identities access to specific resources, but it does not aggregate Microsoft Sentinel data or incidents across tenants. Users granted via B2B must still individually navigate to each tenant's Sentinel workspace and authenticate within that tenant's context, which fails to provide the unified incident management and cross-workspace investigation capabilities required. B2B addresses identity access only, whereas multi-tenant Sentinel operations depend on Azure Lighthouse's delegated resource management for centralized control.
- ✗
Create a single workspace and have all tenants send logs to it.
Why it's wrong here
Each Microsoft Sentinel workspace is intrinsically bound to a single Microsoft Entra tenant; its data connectors, analytic rules, and permissions are scoped to that tenant's directory. While you could theoretically export logs from other tenants via diagnostic settings or data ingestion APIs, this does not enable those tenants to natively send logs to a workspace outside their own tenant without complex and unsupported pipelines. The architectural requirement for multi-tenant visibility is Azure Lighthouse delegation of each tenant's existing Sentinel workspace, allowing a central management tenant to query and investigate across those workspaces without breaking the one-tenant-per-workspace model.
- ✗
Assign custom roles in each tenant's Sentinel workspace.
Why it's wrong here
Custom roles in each tenant's Sentinel workspace can refine RBAC permissions, such as restricting analysts to specific tables or incident entities, but they do not overcome the fundamental identity and administrative boundary between tenants. Users would still need separate accounts or credentials for each tenant, and they would lose the ability to correlate incidents across workspaces in a single context. Azure Lighthouse solves this by enabling the central tenant's security operators to receive delegated role assignments across all tenant workspaces, so they can use their existing credentials and one unified interface for investigation.
- ✓
Onboard multiple workspaces to Azure Lighthouse and use a central workspace for investigation.
Why this is correct
Onboarding multiple Sentinel workspaces to Azure Lighthouse is the proper approach because it enables delegated resource management across tenant boundaries. Once each tenant's workspace is delegated to the central management tenant, security analysts can use Azure Lighthouse to access all workspaces in a single browser session and leverage Sentinel's built-in multi-workspace views, such as unified incident management and cross-workspace hunting. This preserves each tenant's data ownership and isolation while giving the central SOC operational visibility, and it supports a dedicated central workspace for aggregating alerts and managing investigations across the enterprise.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.