SC-200 Manage a security operations environment Practice Question
A security operations center (SOC) uses Microsoft Sentinel for log management. The SOC manager wants to reduce storage costs by automatically archiving logs that are older than 90 days to long-term retention, but retains the ability to search them if needed. What should the manager configure?
⚠ Common exam trap
Candidates often confuse 'archiving' with 'deleting' or 'exporting,' assuming that moving data to cheaper storage must mean losing queryability, whereas Microsoft Sentinel's archive tier preserves searchability through restore or search jobs.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure a data archiving policy in the Log Analytics workspace to archive logs after 90 days
Configuring a data archiving policy in the Log Analytics workspace automatically moves logs older than 90 days to long-term, low-cost storage while keeping them searchable via the search job or restore feature. This directly meets the SOC manager's requirement to reduce costs without losing the ability to query archived data.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Change the table plan to Basic Logs for logs older than 90 days
Why it's wrong here
Changing the table plan to Basic Logs does not alter retention of existing data; table plans are configured at ingestion time and apply to new data being received. You cannot retroactively convert already-stored Analytics Logs into Basic Logs after 90 days, and Basic Logs does not move data to a cheaper archive tier. It also introduces query limitations and costs, but it is not an archival or long-term retention mechanism.
- ✗
Create a retention policy that deletes logs older than 90 days
Why it's wrong here
Creating a retention policy that deletes logs older than 90 days would permanently purge the data from the Log Analytics workspace, rendering it unrecoverable for security investigations or compliance audits. Unlike an archive tier, deletion removes the ability to search historical events, and there is no way to restore or query deleted logs. This approach sacrifices the core SOC requirement of retaining forensic evidence for extended periods.
- ✓
Configure a data archiving policy in the Log Analytics workspace to archive logs after 90 days
Why this is correct
Configuring a data archiving policy in the Log Analytics workspace automatically moves logs from the interactive retention tier to an archive tier after a defined period, such as 90 days, while preserving the ability to search them through archived log search jobs. Archived data is retained at a lower cost and remains accessible for compliance and incident investigations, subject to a separate total retention duration and additional search costs. This is the intended native method for long-term, queryable log retention in Microsoft Sentinel.
- ✗
Export logs older than 90 days to an Azure Storage account
Why it's wrong here
Exporting logs to an Azure Storage account stores them as blobs or files that are not indexed or directly queryable by Log Analytics. To analyze this data, you would need to implement a separate pipeline (e.g., Azure Data Explorer or custom loading) and the export itself captures future data via diagnostic settings rather than moving existing history unless using a one-time export job. Even then, the exported copy is a static snapshot that lacks the search and correlation capabilities of native Log Analytics archive search.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.