Microsoft Security Operations Analyst Associate SC-200 Practice Question
Your Microsoft Sentinel workspace retains SecurityEvent logs for 30 days, after which they are archived for a year. You must investigate a suspicious PowerShell command that ran 35 days ago. Retrieve only relevant events, avoid re-ingesting the full archive, and run KQL queries on the results. Which Sentinel feature should you use?
Enable the Basic Logs tier for SecurityEvent and re-run the hunting query.
Run a search job over the SecurityEvent table for the required 35-day time window.
Use the Restore operation to bring the 35-day archive back into the workspace and then query it.
Create a scheduled analytics rule that queries the archive tier for the suspicious command.
A search job can query data that has been moved to the archive tier without first restoring the entire time range to the workspace. It runs an offline scan over the archived data, writes only the matching records back into a temporary search table inside the workspace, and lets you run standard KQL queries against those results. Restoring data would re-ingest all archived logs for the selected period, which is unnecessary and more expensive. Analytics rules and Basic Logs do not provide direct, selective querying of archived data.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is a search job in Microsoft Sentinel?
Open an interactive chat with Bash
What is KQL (Kusto Query Language)?
Open an interactive chat with Bash
What is the archive tier in Microsoft Sentinel?
Open an interactive chat with Bash
Microsoft Security Operations Analyst Associate SC-200
Manage security threats
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .