Microsoft Security Operations Analyst Associate SC-200 Practice Question
You are designing a Microsoft Sentinel deployment. Your organization must keep Azure Firewall logs for 24 months to satisfy regulatory requirements and wants to minimize storage costs. Analysts need to run interactive Kusto queries against the most recent 30 days of firewall data; older data will be accessed only occasionally. Which configuration should you apply to the Azure Monitor Logs workspace that stores the Sentinel data?
Change the table to use the Basic Logs plan and configure a 730-day retention period.
Configure the table to retain 30 days in the Analytics tier and add a data archive rule that stores the next 720 days in the archive tier.
Set a per-table retention period of 730 days in the Analytics tier and leave the archive tier disabled.
Export the Azure Firewall logs to an Azure Storage account through diagnostic settings and delete them from Microsoft Sentinel.
Using a per-table data lifecycle configuration that keeps data in the default (Analytics) tier for 30 days and then automatically moves it to the archive tier for the remaining 720 days satisfies both requirements. The first 30 days remain in hot storage for fast, interactive querying, while the two-year archive tier keeps the data at a much lower cost that still allows on-demand search or restore when needed.
Keeping 730 days in the Analytics tier meets retention goals but is the most expensive option. Basic Logs cannot retain data longer than eight days, so it cannot meet the 24-month mandate. Exporting logs to an external storage account removes them from Sentinel's query experience and requires additional tooling to access the data, failing the requirement for occasional in-product access.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is the Analytics tier in Azure Monitor Logs?
Open an interactive chat with Bash
What is the archive tier in Azure Monitor Logs?
Open an interactive chat with Bash
What is a data lifecycle configuration in Azure Monitor Logs?
Open an interactive chat with Bash
Microsoft Security Operations Analyst Associate SC-200
Manage a security operations environment
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .