Microsoft Security Operations Analyst Associate SC-200 Practice Question
You need to examine Windows security events that might be related to a breach that began 45 days ago. The data from that period has already been archived in a Log Analytics workspace connected to Microsoft Sentinel. What is the most appropriate way to interrogate the archived data while minimizing the impact on interactive query performance in the workspace?
Use the Azure Monitor REST API to export the archived tables to Azure Storage and analyze them with an external SIEM.
Submit a Microsoft Sentinel search job that runs a Kusto Query Language (KQL) statement over the 45-day timeframe and review the results when the job completes.
Run the same KQL statement interactively in the Logs blade after temporarily raising the workspace retention to 60 days.
Create a new Microsoft Sentinel workbook that visualizes the query against the archive by enabling cross-workspace queries.
Running a Microsoft Sentinel search job is specifically designed for large-scale, historical investigations across both hot and archived data. A search job executes the supplied KQL asynchronously and processes the results in the background, so it does not consume the same resources as interactive Log Analytics queries. When the job completes, the results are stored for up to 30 days and can be explored or exported without re-querying the archive. Interactive queries, REST API calls without a search job, or increasing the workspace retention would either fail (because the data is in the archive), strain the workspace, or incur unnecessary cost.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is a Microsoft Sentinel search job?
Open an interactive chat with Bash
What does KQL (Kusto Query Language) offer in Microsoft Sentinel?
Open an interactive chat with Bash
Why should you use search jobs over interactive queries in historical investigations?
Open an interactive chat with Bash
Microsoft Security Operations Analyst Associate SC-200
Manage security threats
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .