Courseiva

SC-200 Respond to security incidents Practice Question

Which TWO of the following are valid methods to retrieve data from Microsoft Sentinel for external analysis during an incident?

⚠ Common exam trap

Candidates often confuse the Log Analytics API (Option D) with the Microsoft Sentinel API (Option E) as separate valid methods, while dismissing the Export to CSV feature (Option C) as a valid retrieval method despite it being a manual export rather than an automated external analysis pipeline.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Connect Log Analytics workspace to external tools via API.

The Log Analytics workspace that underpins Microsoft Sentinel exposes a REST API, allowing external tools to query and export data programmatically for analysis. This API supports OAuth 2.0 authentication and can retrieve log data via KQL queries, making it a valid method for external integration during incident response.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use Microsoft Sentinel PowerShell cmdlets.

    Why it's wrong here

    The Microsoft Sentinel PowerShell cmdlets (Az.SecurityInsights) operate on the management plane: they manage Sentinel resources such as alert rules, incident comments, and bookmarks, but they do not execute KQL queries against the underlying Log Analytics workspace. To retrieve raw log data via PowerShell, you would need to call the Invoke-AzOperationalInsightsQuery cmdlet or the Log Analytics REST API directly. Therefore, these cmdlets are not a valid method for data retrieval in the context of this question.

  • ✗

    Create a Power BI dashboard.

    Why it's wrong here

    Creating a Power BI dashboard is a visualization step, not a data-retrieval mechanism. While Power BI can connect to a Log Analytics workspace or consume data from an API, the dashboard itself merely renders data that has been obtained through another channel; it does not export or expose raw data for external use. It also does not provide a programmatic or queryable interface for pulling data out of Microsoft Sentinel, so it is not one of the valid retrieval methods.

  • ✗

    Use the Export to CSV feature in the Logs blade.

    Why it's wrong here

    The Export to CSV feature in the Logs blade is a manual, UI-bound action that only downloads the rows already displayed in the query results, which are capped at 10,000 records per query. It is not designed for large-scale, automated, or auditable data extraction, nor does it support querying from external tools. Because it lacks the ability to retrieve the full result set programmatically, it is unsuitable for external analysis and is therefore not a valid method in this context.

  • ✓

    Connect Log Analytics workspace to external tools via API.

    Why this is correct

    Connecting the Log Analytics workspace to external tools via the Log Analytics Query API is a valid data-retrieval method because it allows external applications, such as custom scripts or third-party SIEM/BI solutions, to send KQL queries over HTTPS and receive the query results in JSON format. The API supports large result sets with batching/pagination, making it suitable for pulling data out of Sentinel's underlying workspace for analysis or integration. This is one of the canonical approaches to retrieving Microsoft Sentinel data externally.

  • ✓

    Use the Microsoft Sentinel API to query incidents and alerts.

    Why this is correct

    Using the Microsoft Sentinel API to query incidents and alerts is a valid method because it provides programmatic access to the security-operations data model, including incidents, alerts, and hunting bookmarks. This REST API is designed for automation and external integrations, enabling you to retrieve security findings without needing to run raw KQL queries. It is specifically intended for data retrieval and management of Sentinel artifacts, making it the second correct answer for this question.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.