Courseiva

SC-200 Microsoft Sentinel workspace Practice Question

Your organization uses Microsoft Sentinel with a workspace in the East US region. You need to respond to an incident involving data exfiltration from a virtual machine in West Europe. The incident was created from a custom analytics rule that queries the AzureActivity table. What should you do to ensure the incident contains all relevant evidence from the West Europe region?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Ensure that Azure activity logs from West Europe are streamed to the same Sentinel workspace in East US

To have the analytics rule in the East US workspace evaluate AzureActivity logs from West Europe, those logs must be collected into the same workspace. Streaming activity logs from West Europe to the East US workspace ensures all relevant data is available for the rule to query. Option A is incorrect because creating a separate workspace in West Europe would isolate the data, and the incident is in the East US workspace; cross-workspace queries would be required. Option C is incorrect because the analytics rule runs only in the workspace where it is defined; to query data from another workspace, you would need a cross-workspace query, but the rule is already defined in East US and cannot directly query the West Europe workspace without additional configuration. Option D is incorrect because incident merge is used to combine duplicate incidents within the same workspace, not across different workspaces.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create the analytics rule in a separate workspace in West Europe

    Why it's wrong here

    A second workspace fragments the incident: the East US rule still generates it, while West Europe evidence lands elsewhere, so nothing is consolidated. Separate workspaces suit data-residency segregation or distinct tenants, not enriching one incident with cross-region evidence from a single subscription.

  • ✓

    Ensure that Azure activity logs from West Europe are streamed to the same Sentinel workspace in East US

    Why this is correct

    AzureActivity data is regional; the West Europe VM's activity logs are only written to a workspace in that region unless explicitly streamed. Routing them into the East US workspace ensures the analytics rule can correlate all evidence for the incident.

  • ✗

    Configure the analytics rule to query the West Europe workspace

    Why it's wrong here

    Pointing the rule at a West Europe workspace cannot work, because the AzureActivity data resides in the East US workspace the rule already queries; there is no West Europe workspace holding that evidence. Cross-workspace querying suits multi-workspace designs, not this single-workspace deployment.

  • ✗

    Use the incident merge feature to combine incidents from multiple workspaces

    Why it's wrong here

    Incident merge combines separate incidents within the same workspace, so it cannot pull West Europe evidence into an East US incident when no second workspace or incident exists. Merging suits duplicate alerts for one event, not gathering evidence across regions.

About these practice questions

This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.