Microsoft Security Operations Analyst Associate SC-200 Practice Question

Your organization is creating a new Microsoft Sentinel workspace. Compliance policy requires that all security event data remain searchable for 14 months. Security analysts routinely run interactive queries against the most recent 30 days of data but are willing to wait several hours when they need to investigate older events. You must meet the compliance requirement while keeping Microsoft Sentinel data-retention costs as low as possible. Which configuration should you implement in the Log Analytics workspace?

  • Create a second Log Analytics workspace in the same region, onboard it to Microsoft Sentinel, and forward data from the primary workspace for long-term retention.

  • Configure all high-volume tables to use Basic Logs with eight-day retention and retain the default 30-day workspace retention.

  • Set the workspace retention to 30 days and enable table-level data archive for the required tables for an additional 13 months.

  • Set the workspace's default retention period to 14 months and do not configure data archive.

Microsoft Security Operations Analyst Associate SC-200
Manage a security operations environment
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot