SC-200 Microsoft Sentinel workspace Practice Question
Your organization uses Microsoft Sentinel with a workspace in the East US region. You need to respond to an incident involving data exfiltration from a virtual machine in West Europe. The incident was created from a custom analytics rule that queries the AzureActivity table. What should you do to ensure the incident contains all relevant evidence from the West Europe region?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Ensure that Azure activity logs from West Europe are streamed to the same Sentinel workspace in East US
To have the analytics rule in the East US workspace evaluate AzureActivity logs from West Europe, those logs must be collected into the same workspace. Streaming activity logs from West Europe to the East US workspace ensures all relevant data is available for the rule to query. Option A is incorrect because creating a separate workspace in West Europe would isolate the data, and the incident is in the East US workspace; cross-workspace queries would be required. Option C is incorrect because the analytics rule runs only in the workspace where it is defined; to query data from another workspace, you would need a cross-workspace query, but the rule is already defined in East US and cannot directly query the West Europe workspace without additional configuration. Option D is incorrect because incident merge is used to combine duplicate incidents within the same workspace, not across different workspaces.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create the analytics rule in a separate workspace in West Europe
Why it's wrong here
A second workspace fragments the incident: the East US rule still generates it, while West Europe evidence lands elsewhere, so nothing is consolidated. Separate workspaces suit data-residency segregation or distinct tenants, not enriching one incident with cross-region evidence from a single subscription.
- ✓
Ensure that Azure activity logs from West Europe are streamed to the same Sentinel workspace in East US
Why this is correct
AzureActivity data is regional; the West Europe VM's activity logs are only written to a workspace in that region unless explicitly streamed. Routing them into the East US workspace ensures the analytics rule can correlate all evidence for the incident.
- ✗
Configure the analytics rule to query the West Europe workspace
Why it's wrong here
Pointing the rule at a West Europe workspace cannot work, because the AzureActivity data resides in the East US workspace the rule already queries; there is no West Europe workspace holding that evidence. Cross-workspace querying suits multi-workspace designs, not this single-workspace deployment.
- ✗
Use the incident merge feature to combine incidents from multiple workspaces
Why it's wrong here
Incident merge combines separate incidents within the same workspace, so it cannot pull West Europe evidence into an East US incident when no second workspace or incident exists. Merging suits duplicate alerts for one event, not gathering evidence across regions.
Go deeper
Related to this question
About these practice questions
This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.