Microsoft Security Operations Analyst Associate SC-200 Practice Question
Your Microsoft Sentinel workspace keeps log data for 30 days and then moves it to the archive tier for up to seven years. An incident that occurred 14 months ago now requires an interactive Kusto Query Language (KQL) hunt that will join the historic SecurityEvent table with currently active sign-in data. Before you can run this hunting query in Microsoft Sentinel, which action should you perform on the archived SecurityEvent data?
Increase the workspace retention setting to 730 days so that the archived data is automatically moved back into the hot cache for querying.
Configure a data export rule to move the archived SecurityEvent data to Azure Storage and connect the storage account as a new data source.
Create a search job over the archive tier and wait for it to complete, then run the hunting query against the search job results.
Initiate a log restore operation for the SecurityEvent table to copy the required 14-month-old data into a temporary restored table.
To run interactive KQL hunts that can join archived data with current tables, you must first restore the required archive data to an analytics table. A Log Analytics restore operation copies the selected table's data from the archive tier into a new, temporary table with the _RST suffix where full query capabilities-including joins-are available for the specified time range. Search jobs can query archive data directly, but they return results as a static set that cannot be joined with other tables in subsequent interactive queries. Data export rules and changing the workspace retention policy do not make already-archived data immediately queryable in Sentinel hunting queries.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is the purpose of the archive tier in Microsoft Sentinel?
Open an interactive chat with Bash
What is a log restore operation in Microsoft Sentinel?
Open an interactive chat with Bash
How does interactive KQL differ from querying with search jobs over archived data?
Open an interactive chat with Bash
Microsoft Security Operations Analyst Associate SC-200
Manage security threats
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .