Courseiva
Manage a security operations environmentmediumMultiple SelectObjective-mapped

SC-200 Manage a security operations environment Practice Question

You need to configure Microsoft Sentinel to comply with a regulatory requirement that all security incidents must be retained for 7 years. Which TWO actions should you take?

⚠ Common exam trap

Test-takers frequently confuse table-level retention policies with workspace-level retention, thinking they can set retention per table to meet compliance, but incidents are not stored in user-defined tables and require workspace-level retention or data export to immutable storage.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Set the workspace retention policy to 2555 days (7 years).

Setting the workspace retention policy to 2555 days (7 years) ensures that all log data ingested into the Log Analytics workspace is retained for the required period. This is the foundational mechanism for meeting long-term retention requirements in Microsoft Sentinel, as Sentinel inherits the workspace's retention settings for incident-related data.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Set the workspace retention policy to 2555 days (7 years).

    Why this is correct

    Workspace retention can be set to up to 730 days by default, but with archive policy it can be extended to 7 years.

  • Configure a data export rule to send data to an Azure Storage account with immutable storage for 7 years.

    Why this is correct

    Data export can be used for long-term retention.

  • Configure table-level retention policies for each table to 7 years.

    Why it's wrong here

    Table-level retention cannot exceed workspace retention without archive.

  • Use Basic Logs for all tables to reduce costs.

    Why it's wrong here

    Basic Logs have limited retention and features.

  • Use Azure Policy to enforce a minimum retention period of 7 years on all workspaces.

    Why it's wrong here

    Azure Policy does not directly set retention; it can audit but not configure.

About these practice questions

Courseiva writes every SC-200 question from scratch — 209 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.