nerdexam
Microsoft

SC-200 · Question #37

Your company stores the data for every project in a different Azure subscription. All the subscriptions use the same Azure Active Directory (Azure AD) tenant. Every project consists of multiple…

The correct answer is B. Create a query that uses the workspace expression and the union operator. E. Add the Azure Sentinel solution to each workspace. Every sentinel deployment must have a workspace - and the union command is used to join multiple workspaces together. https://docs.microsoft.com/en-us/learn/modules/create-manage-azure-sentinel-workspaces/2- plan-for-azure-sentinel-workspace

Submitted by paula_co· Apr 18, 2026Manage threat hunting in Microsoft Sentinel

Question

Your company stores the data for every project in a different Azure subscription. All the subscriptions use the same Azure Active Directory (Azure AD) tenant. Every project consists of multiple Azure virtual machines that run Windows Server. The Windows events of the virtual machines are stored in a Log Analytics workspace in each machine's respective subscription. You deploy Azure Sentinel to a new Azure subscription. You need to perform hunting queries in Azure Sentinel to search across all the Log Analytics workspaces of all the subscriptions. Which two actions should you perform?Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point.

Options

  • AAdd the Security Events connector to the Azure Sentinel workspace.
  • BCreate a query that uses the workspace expression and the union operator.
  • CUse the alias statement.
  • DCreate a query that uses the resource expression and the alias operator.
  • EAdd the Azure Sentinel solution to each workspace.

How the community answered

(24 responses)
  • A
    8% (2)
  • B
    75% (18)
  • C
    13% (3)
  • D
    4% (1)

Explanation

Every sentinel deployment must have a workspace - and the union command is used to join multiple workspaces together. https://docs.microsoft.com/en-us/learn/modules/create-manage-azure-sentinel-workspaces/2- plan-for-azure-sentinel-workspace

Topics

#Azure Sentinel#Threat Hunting#KQL#Cross-workspace queries

Community Discussion

No community discussion yet for this question.

Full SC-200 Practice