SC-100 Design security solutions for infrastructure Practice Question
Your company is deploying Microsoft Sentinel to centralize security logs from Azure, on-premises, and other clouds. You need to ensure logs are ingested cost-effectively while maintaining search performance for the last 30 days. What should you configure?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use Log Analytics workspace with 30-day interactive retention and set long-term retention for older data.
Microsoft Sentinel stores ingested data in a Log Analytics workspace, where the interactive retention setting controls how long data remains available for fast KQL queries and analytics rules. Setting 30-day interactive retention satisfies the search-performance requirement for the last 30 days, while configuring long-term retention for older data keeps historical logs at a lower cost. The other options do not fit: Azure Blob Storage with Azure Data Explorer (A) is not Sentinel's native ingestion and query path, Sentinel has no 30-day free tier that then converts to paid (C), and Event Hubs (D) is only an ingestion pipeline, not a retention or query configuration.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Store logs in Azure Blob Storage and use Azure Data Explorer for queries.
Why it's wrong here
Exporting Sentinel logs to Azure Blob Storage and querying them in ADX adds unnecessary architectural complexity and cost. Sentinel’s built-in analytics rules, UEBA, and workbooks require KQL queries against Log Analytics workspaces, not ADX clusters. Blob storage is meant for archival or long-term compliance, not for 30-day interactive security searches, and ADX incurs Always-On compute costs plus data egress fees that exceed Log Analytics' native query performance.
- ✓
Use Log Analytics workspace with 30-day interactive retention and set long-term retention for older data.
Why this is correct
A Log Analytics workspace with 30-day interactive retention provides Sentinel-native KQL query performance for the most recent month of security data, while long-term retention (archiving) keeps older telemetry in the same workspace at a lower storage cost without losing access—you can run search jobs to triage historical events. This configuration aligns with Sentinel’s architecture: Log Analytics is the underlying data store, interactive retention is optimized for frequent incident-hunting queries, and archived data remains queryable when needed, balancing cost and operational efficiency.
- ✗
Use Sentinel's free tier for 30 days and then move to paid tier.
Why it's wrong here
Azure Sentinel does not have a time-limited 'free tier' that you then upgrade; its pricing model is usage-based, charged per gigabyte of data ingested into the Log Analytics workspace, with a free 31-day trial for the service itself. Even if you move to a paid tier after 30 days, retention and query performance are unchanged—you still need to configure interactive retention and archive policies. The suggestion treats Sentinel like a SaaS trial subscription, which misses the fact that data volume, not calendar duration, drives cost and determines whether logs remain searchable.
- ✗
Ingest logs into Azure Event Hubs and then into Sentinel.
Why it's wrong here
Ingesting logs into Azure Event Hubs before Sentinel adds an unnecessary streaming intermediary that increases egress and processing costs without improving 30-day search performance, because Sentinel’s native Log Analytics workspace already provides fast, indexed queries for that retention period. This approach is tempting because Event Hubs is designed for high-throughput ingestion and decoupling producers from consumers, making it correct when you need to buffer logs for multiple downstream systems or handle massive, real-time data streams that exceed Sentinel’s direct ingestion rate limits.
Quick reference
Azure Blob Storage Tier Comparison
| Tier | Storage Cost | Retrieval Cost | Latency | Use Case |
|---|---|---|---|---|
| Hot | Highest | Lowest | Immediate | Active data, frequent reads |
| Cool | Lower | Higher | Immediate | Data accessed < once / month |
| Cold | Lower still | Higher | Immediate | Data accessed < once / quarter |
| Archive | Lowest | Highest + rehydration delay | Hours | Long-term compliance retention |
Go deeper
Related to this question
About these practice questions
This SC-100 question is part of Courseiva's 605-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.