Microsoft Security Operations Analyst Associate SC-200 Practice Question
You manage a Microsoft Sentinel workspace that ingests roughly 2 TB of Windows Security events each day. Security investigators require fast, interactive queries over the most recent 30 days of these events, while compliance regulations mandate that the events remain available for a total of 12 months. You must meet both needs while keeping storage costs as low as possible. Which Log Analytics data management feature should you apply to the WindowsSecurity table?
Keep the table in the Analytics tier and set retention to 12 months.
Convert the table to Basic Logs with default retention.
Move the table to the archive tier and set interactive retention to 30 days.
Enable a daily data cap that stops ingestion after 2 TB.
The archive tier lets you set a short interactive retention period (for example, 30 days) and then store the remaining data (up to seven years) at a much lower cost. Investigators still have immediate access to the latest 30 days, and older data can be restored on demand to satisfy regulatory look-back requirements. Basic Logs are limited to eight days of retention, so they cannot satisfy a 12-month mandate. A workspace-level data cap throttles ingestion volume but does not reduce the cost of storing already-ingested data or change retention. Keeping the table in the Analytics tier for the full 12 months provides interactive access but at a significantly higher cost than using the archive tier.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is the archive tier in Microsoft Sentinel?
Open an interactive chat with Bash
What is the difference between the Analytics and archive tiers in Microsoft Sentinel?
Open an interactive chat with Bash
How does interactive retention work in Microsoft Sentinel?
Open an interactive chat with Bash
Microsoft Security Operations Analyst Associate SC-200
Manage a security operations environment
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .