Microsoft Security Operations Analyst Associate SC-200 Practice Question
Your organization retains Microsoft Sentinel operational logs in the connected Log Analytics workspace for 30 days and archives data for two years. You must investigate whether a compromised account was active during a seven-month-old incident, while keeping costs low and avoiding restoring the full archive. Which Sentinel capability should you use to retrieve and analyze the archived log data?
Perform a data restore operation to move the seven-month-old logs back to the hot cache, then run the hunting query.
Create a new hunting query in Microsoft Sentinel and set the Time range filter to Custom covering the seven-month period.
Export the archived logs with Azure Storage Explorer and perform an offline search on the downloaded files.
Run a Log Analytics search job that targets the required seven-month time range and query for the compromised account.
Log Analytics search jobs can query data that resides in the archive tier without first restoring it to the hot cache. A search job runs asynchronously, scans only the specified time range, and returns matching records to a dedicated table that you can query with KQL. Restoring archived data would copy the entire selected period back to hot storage, incurring additional retention costs. Setting a custom time range in a standard hunting query does not access archived data, and downloading raw logs from Azure Storage provides no integrated analysis capabilities. Therefore, using a search job is the most cost-effective and functional approach for hunting across seven-month-old data.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is a Log Analytics search job?
Open an interactive chat with Bash
What is the difference between archived data and hot cache in Microsoft Sentinel?
Open an interactive chat with Bash
How does KQL (Kusto Query Language) work in analyzing search job results?
Open an interactive chat with Bash
Microsoft Security Operations Analyst Associate SC-200
Manage security threats
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .