SC-200 Respond to security incidents Practice Question
Your organization's Microsoft Sentinel workspace ingests logs from multiple regions. During an incident, you need to search for a specific user's activity across all workspaces in a single query. What is the most efficient way to accomplish this?
⚠ Common exam trap
Watch out — candidates often confuse the workspace filter in the Sentinel search UI with the KQL workspace() expression, assuming the filter can query multiple workspaces when it actually only filters data within the currently selected workspace.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use a cross-workspace query with the workspace() expression.
The workspace() expression in Kusto Query Language (KQL) allows you to include data from multiple Log Analytics workspaces in a single query. By specifying the workspace ID or name within the expression, you can search across all relevant workspaces without needing to run separate queries or manually combine results. This is the most efficient method because it executes as a single query against the underlying Azure Data Explorer clusters, minimizing latency and administrative overhead.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Use a cross-workspace query with the workspace() expression.
Why this is correct
Cross-workspace queries using the workspace() expression allow you to reference multiple Log Analytics workspaces in a single KQL query, typically with the union operator. This is the most efficient way to search for threats across Microsoft Sentinel workspaces because it avoids data duplication and runs in one query request, returning merged results that can be further processed with KQL operators like project, where, or summarize.
- ✗
Run separate queries in each workspace and combine results manually.
Why it's wrong here
Running separate queries in each workspace and manually combining results is inefficient and error-prone. It requires multiple query executions, manual transformation of schemas and data types, and introduces the risk of missed or duplicated data when merging large result sets. This approach does not scale across many workspaces and severely limits the ability to correlate events across workspaces in real time.
- ✗
Create a new analytics rule that queries all workspaces.
Why it's wrong here
Analytics rules are not designed for ad-hoc querying; they are scheduled detection mechanisms that produce alerts and incidents based on predefined logic. Creating a new analytics rule just to run a one-time cross-workspace query would unnecessarily trigger alerting workflows, require configuration of schedule and incident settings, and still require the rule itself to use workspace() expressions. The rule execution is background-detected, not a direct interactive search.
- ✗
Use the Microsoft Sentinel search feature with the workspace filter.
Why it's wrong here
The Microsoft Sentinel search feature, when used with a workspace filter, is intended to run queries within a single selected workspace at a time; the filter merely selects which workspace the query runs against, not how to combine data across workspaces. To span multiple workspaces, you must explicitly write workspace() expressions in your KQL query, which the filter does not automatically generate. Thus, relying on the workspace filter alone would not aggregate results from multiple workspaces.
Go deeper
Related to this question
About these practice questions
This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.