SC-200 Manage a security operations environment Practice Question
You need to configure Microsoft Sentinel to comply with a regulatory requirement that all security incidents must be retained for 7 years. Which TWO actions should you take?
⚠ Common exam trap
Test-takers frequently confuse table-level retention policies with workspace-level retention, thinking they can set retention per table to meet compliance, but incidents are not stored in user-defined tables and require workspace-level retention or data export to immutable storage.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Set the workspace retention policy to 2555 days (7 years).
Setting the workspace retention policy to 2555 days (7 years) ensures that all log data ingested into the Log Analytics workspace is retained for the required period. This is the foundational mechanism for meeting long-term retention requirements in Microsoft Sentinel, as Sentinel inherits the workspace's retention settings for incident-related data.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Set the workspace retention policy to 2555 days (7 years).
Why this is correct
Workspace retention can be set to up to 730 days by default, but with archive policy it can be extended to 7 years.
- ✓
Configure a data export rule to send data to an Azure Storage account with immutable storage for 7 years.
Why this is correct
Data export can be used for long-term retention.
- ✗
Configure table-level retention policies for each table to 7 years.
Why it's wrong here
Table-level retention cannot exceed workspace retention without archive.
- ✗
Use Basic Logs for all tables to reduce costs.
Why it's wrong here
Basic Logs have limited retention and features.
- ✗
Use Azure Policy to enforce a minimum retention period of 7 years on all workspaces.
Why it's wrong here
Azure Policy does not directly set retention; it can audit but not configure.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 209 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.