SC-200 Respond to security incidents Practice Question
Which TWO of the following are valid methods to retrieve data from Microsoft Sentinel for external analysis during an incident?
⚠ Common exam trap
Candidates often confuse the Log Analytics API (Option D) with the Microsoft Sentinel API (Option E) as separate valid methods, while dismissing the Export to CSV feature (Option C) as a valid retrieval method despite it being a manual export rather than an automated external analysis pipeline.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Connect Log Analytics workspace to external tools via API.
The Log Analytics workspace that underpins Microsoft Sentinel exposes a REST API, allowing external tools to query and export data programmatically for analysis. This API supports OAuth 2.0 authentication and can retrieve log data via KQL queries, making it a valid method for external integration during incident response.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use Microsoft Sentinel PowerShell cmdlets.
Why it's wrong here
The Microsoft Sentinel PowerShell cmdlets (Az.SecurityInsights) operate on the management plane: they manage Sentinel resources such as alert rules, incident comments, and bookmarks, but they do not execute KQL queries against the underlying Log Analytics workspace. To retrieve raw log data via PowerShell, you would need to call the Invoke-AzOperationalInsightsQuery cmdlet or the Log Analytics REST API directly. Therefore, these cmdlets are not a valid method for data retrieval in the context of this question.
- ✗
Create a Power BI dashboard.
Why it's wrong here
Creating a Power BI dashboard is a visualization step, not a data-retrieval mechanism. While Power BI can connect to a Log Analytics workspace or consume data from an API, the dashboard itself merely renders data that has been obtained through another channel; it does not export or expose raw data for external use. It also does not provide a programmatic or queryable interface for pulling data out of Microsoft Sentinel, so it is not one of the valid retrieval methods.
- ✗
Use the Export to CSV feature in the Logs blade.
Why it's wrong here
The Export to CSV feature in the Logs blade is a manual, UI-bound action that only downloads the rows already displayed in the query results, which are capped at 10,000 records per query. It is not designed for large-scale, automated, or auditable data extraction, nor does it support querying from external tools. Because it lacks the ability to retrieve the full result set programmatically, it is unsuitable for external analysis and is therefore not a valid method in this context.
- ✓
Connect Log Analytics workspace to external tools via API.
Why this is correct
Connecting the Log Analytics workspace to external tools via the Log Analytics Query API is a valid data-retrieval method because it allows external applications, such as custom scripts or third-party SIEM/BI solutions, to send KQL queries over HTTPS and receive the query results in JSON format. The API supports large result sets with batching/pagination, making it suitable for pulling data out of Sentinel's underlying workspace for analysis or integration. This is one of the canonical approaches to retrieving Microsoft Sentinel data externally.
- ✓
Use the Microsoft Sentinel API to query incidents and alerts.
Why this is correct
Using the Microsoft Sentinel API to query incidents and alerts is a valid method because it provides programmatic access to the security-operations data model, including incidents, alerts, and hunting bookmarks. This REST API is designed for automation and external integrations, enabling you to retrieve security findings without needing to run raw KQL queries. It is specifically intended for data retrieval and management of Sentinel artifacts, making it the second correct answer for this question.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.