Microsoft Security Operations Analyst Associate SC-200 Practice Question
You manage a Microsoft Sentinel deployment that ingests 50 GB of SecurityEvent data daily to a Log Analytics workspace in West Europe. Regulatory policy requires that security event logs remain retrievable for 24 months, but analysts typically query only the most recent 90 days. You must minimize storage costs while being able to run investigations on older data when necessary. Which workspace setting should you configure to meet the requirements?
Set the workspace retention for the SecurityEvent table to 90 days and configure an archive rule that stores the data for an additional 21 months.
Enable continuous export to Azure Storage and delete SecurityEvent data from the workspace after 90 days.
Enable Basic Logs for the SecurityEvent table and set its retention to 24 months.
Create a daily ingestion cap and configure discard rules to delete SecurityEvent data older than 90 days.
Table-level retention lets you keep frequently queried data in the hot cache and automatically move older records to low-cost archive storage. By setting the default retention for the SecurityEvent table to 90 days and adding an archive rule for an additional 21 months, recent data stays fully searchable at normal speed while older data is preserved at a much lower price and can be queried on demand with Search or Restore jobs. Basic Logs do not support SecurityEvent and continuous export would require separate storage and tooling, while daily caps or purging would delete data needed for compliance.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is the difference between table-level retention and archiving in Microsoft Sentinel?
Open an interactive chat with Bash
How does the archive rule work for SecurityEvent data in Microsoft Sentinel?
Open an interactive chat with Bash
What are the limitations of Basic Logs compared to table-level retention in Microsoft Sentinel?
Open an interactive chat with Bash
Microsoft Security Operations Analyst Associate SC-200
Manage a security operations environment
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .