Microsoft Security Operations Analyst Associate SC-200 Practice Question
You need to examine Windows SecurityEvent records that are 150 days old in a Log Analytics workspace that is connected to Microsoft Sentinel. The workspace retains data in the interactive tier for 30 days; anything older is automatically placed in the archive tier. You must obtain a count of specific event IDs from those 150-day-old records without first restoring the data and while minimizing cost. What should you do?
Increase the workspace interactive retention to 180 days and rerun the KQL query in Log Analytics.
Start a Log Analytics search job scoped to the 150-day time range and query the automatically created *_SRCH results table for the event ID counts.
Restore the SecurityEvent table for the 150-day period and then run a standard KQL query against the restored data.
Configure Continuous Export to an Azure Storage account and analyze the exported logs by using Azure Data Explorer.
A Log Analytics search job can read data that sits in the archive tier without any restore operation. You submit an asynchronous search job scoped to the required 150-day time range and specify an output table name (the system will create a new table that ends with "_SRCH"). After the job finishes, you can run a regular KQL query against that newly created *_SRCH table to view the aggregated counts. This avoids the extra charges and latency of table restore, requires no change to retention settings, and is simpler and cheaper than exporting data for external analysis.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is a Log Analytics search job?
Open an interactive chat with Bash
What is the archive tier in Log Analytics, and why is it used?
Open an interactive chat with Bash
How does the *_SRCH table work in Microsoft Sentinel?
Open an interactive chat with Bash
Microsoft Security Operations Analyst Associate SC-200
Manage security threats
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .