SC-200 Manage a security operations environment Practice Question
Which THREE of the following are valid methods to archive logs in Microsoft Sentinel to reduce costs?
⚠ Common exam trap
It's easy for candidates to confuse 'Basic Logs' (which reduce ingestion cost but not storage cost) with archival methods, or mistakenly think the free tier can be manually selected for cost savings, when in fact it is a temporary promotional offering.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure continuous export to Azure Data Lake Storage Gen2
Microsoft Sentinel supports continuous export of logs to Azure Data Lake Storage Gen2, which allows you to retain raw log data at lower storage costs while still being able to query it using Azure Synapse or other analytics tools. This method reduces the cost of high-volume log retention in Sentinel's native workspace by moving data to a cheaper long-term storage tier.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Configure continuous export to Azure Data Lake Storage Gen2
Why this is correct
Continuous export is a native feature that automatically copies ingested log data from a Log Analytics workspace to an Azure Data Lake Storage Gen2 account in near real time, storing each table as a set of Parquet files. This provides long-term retention and cost-effective archival because you can delete the data from the workspace after export or keep it only for the required interactive period. It supports filtering per table and is fully managed, so it is a valid archival method, especially for compliance or big-data analytics scenarios.
- ✗
Set the workspace to free tier
Why it's wrong here
The Log Analytics free tier is a pricing SKU that imposes a strict daily ingestion cap (typically 500 MB) and a 7-day retention period, not a data lifecycle feature that archives logs. Switching to it would reduce your retention window and could cause data loss when the cap is hit, because logs are dropped or ingestion pauses. Free tier does not offer a cold or archive tier, so it cannot serve as a valid method for long-term archival.
- ✗
Enable Basic Logs ingestion for all tables
Why it's wrong here
Basic Logs is an ingestion pricing tier that lowers costs for high-volume verbose logs, but it provides only 8 days of default retention and intentionally strips query capabilities such as full-text search and joins. It does not move data to an archival tier; instead, it is a separate logging plan with its own retention limits. Enabling it for all tables would break existing analytics on tables that require the Interactive Logs plan, and it still lacks the ability to archive data automatically, so it is not a valid archival method.
- ✓
Use a Logic App to export logs to Azure Storage
Why this is correct
You can build a Logic App that runs on a schedule or in response to an event to run a Log Analytics query and write results to Azure Blob Storage or ADLS, effectively creating a custom archival pipeline. This is valid because the exported data lands in durable, low-cost object storage outside the workspace, and you can partition by time or convert to formats like Parquet for downstream processing. However, unlike continuous export, you are responsible for managing query limits, retries, and incremental export, so it is more of a manual/custom method, but still a recognized way to archive logs.
- ✓
Change the table's retention period to include archival
Why this is correct
Within a Log Analytics workspace, you can set a table's interactive retention (e.g., 30 days) and then specify a longer archival retention period (e.g., up to 2 years) to automatically move older data into an archived state. The archived data remains queryable using Search Job or Restore features, though with slower performance and additional cost, and it is fully managed by Azure. This is a valid archival method because it preserves logs for long-term compliance without exporting them to external storage, and it can be configured via the Azure portal, ARM, or API.
Go deeper
Related to this question
About these practice questions
This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.