Courseiva

SC-200 Manage a security operations environment Practice Question

Your SOC uses Microsoft Sentinel with multiple workspaces for different business units. You want to create a single dashboard that shows key performance indicators (KPIs) across all workspaces. Which approach minimizes complexity and query latency?

⚠ Common exam trap

Watch out — candidates often assume a single workspace is simpler (Option B) or that external tools like Power BI are required for cross-source aggregation, missing the native cross-workspace query capability in Sentinel that is designed exactly for this multi-workspace scenario.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use cross-workspace queries in a single dashboard that references all workspaces.

Cross-workspace queries in Microsoft Sentinel allow you to query multiple workspaces in a single KQL query using the `workspace()` expression, enabling a unified dashboard without data duplication or additional infrastructure. This minimizes complexity by avoiding data movement and reduces query latency by leveraging the existing indexing and caching within each workspace.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Export data to Azure Data Explorer and build the dashboard there.

    Why it's wrong here

    Exporting data to Azure Data Explorer (ADX) introduces an extra data movement pipeline that is not minimal for a multi-workspace Sentinel dashboard. You would need to configure continuous export, manage a separate ADX cluster, and pay for additional storage and query costs, while also adding latency between log ingestion and dashboard visibility. Cross-workspace queries in Sentinel avoid this by querying the source workspaces directly, so this approach adds unnecessary complexity without a monitoring benefit.

  • ✗

    Ingest all logs into a single workspace and create the dashboard there.

    Why it's wrong here

    Consolidating all logs into a single Log Analytics workspace conflicts with common compliance, retention, and data-residency requirements, and it may be costly or impossible if workspaces are in different tenants or regions. Even if feasible, it is not the minimal solution because you would need to reconfigure data collection connectors and agent destinations, and any existing older data would have to be migrated. A dashboard can achieve the same view by using cross-workspace queries that reference each workspace without physically moving data.

  • ✗

    Use Power BI to query each workspace separately and combine data.

    Why it's wrong here

    Using Power BI to query each workspace separately and then combine results requires building a custom data model, setting up data gateway or API authentication, and scheduling refreshes, which introduces significant latency and operational overhead compared to a native Sentinel dashboard. The combined dataset is not real-time, and you must handle inconsistent schema and query errors per workspace. Because Sentinel dashboards already support cross-workspace KQL queries, Power BI is an indirect and overly complex workaround.

  • ✓

    Use cross-workspace queries in a single dashboard that references all workspaces.

    Why this is correct

    Cross-workspace queries let a single Sentinel dashboard use KQL to query multiple Log Analytics workspaces in real time by referencing each workspace with the workspace() expression, such as union workspace("WS-A").SecurityEvent, workspace("WS-B").SecurityEvent. This approach avoids moving or duplicating data, provides immediate visibility, and is the minimal-effort design intended by Microsoft. It also requires proper read permissions on all referenced workspaces, but no additional infrastructure or data pipelines.

About these practice questions

This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.