Microsoft Security Operations AnalystMitigate threats using Microsoft SentinelHard
A security architect is designing a Microsoft Sentinel deployment for a global enterprise. The enterprise has strict data residency requirements, mandating that security logs generated in a specific geographical region must remain within that region and not cross national borders. How should the architect ensure data residency for Sentinel logs across different regions?
- ADeploy a separate Microsoft Sentinel instance and an associated Log Analytics workspace in each geographical region.
- BUse Azure Private Link to restrict data flow to within the region for a single global Sentinel instance.
- CDeploy multiple Log Analytics workspaces in each required region and connect them to a single Sentinel instance.
- DConfigure Azure Storage accounts in each region to store logs and then ingest them into one central Sentinel instance.
Show answer & explanationAnswer & explanation
Correct answer: A. Deploy a separate Microsoft Sentinel instance and an associated Log Analytics workspace in each geographical region.
To ensure strict data residency, both the Log Analytics workspace (where data is stored) and the Microsoft Sentinel instance (which processes and analyzes the data) must reside in the same geographical region. A separate deployment per region is required.
Why the other options are wrong
- B. Azure Private Link enhances network security but does not change the physical location where the Log Analytics workspace or Sentinel instance stores and processes data.
- C. A single Sentinel instance can only be linked to one Log Analytics workspace for primary data ingestion, and even if multiple workspaces were linked, the Sentinel instance itself would have a residency.
- D. While Azure Storage can store logs regionally, ingesting them into a central Sentinel instance would violate residency if that instance is in a different region.
Microsoft Sentinel Data Residency
Microsoft Sentinel's data residency is determined by the geographical location of the associated Log Analytics workspace. For strict residency requirements, both Sentinel and its workspace must be deployed in the required region.
- Data storage location is tied to the Log Analytics workspace.
- Sentinel itself has a regional deployment.
- Requires multiple Sentinel/workspace pairs for multi-geo residency.
Memory trick: Regions Require Right Sentinel Resources