Microsoft Security Operations Analyst Associate SC-200 Practice Question

You need to run an on-demand investigation over 90 days of security events that have already been moved to Microsoft Sentinel's archived logs. You decide to create a search job instead of a standard Log Analytics query. Which action must you perform before you can retrieve the matching events for analysis?

  • Create an export rule that copies the job's output to an Azure Storage account.

  • Run the search again by calling the Execute Query operation with the same query text.

  • Periodically check the search job status until it reports Succeeded.

  • Immediately delete the search job to trigger automatic result retrieval.

Microsoft Security Operations Analyst Associate SC-200
Manage security threats
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot