SC-200 Manage a security operations environment Practice Question
Your Microsoft Sentinel workspace is ingesting data from multiple sources. You need to ensure that data from a specific source is retained for 2 years while other data remains at the default retention. What should you do?
⚠ Common exam trap
Candidates often assume retention is set globally at the workspace level, but Microsoft Sentinel allows per-table retention, which is the correct method for applying different retention policies to different data sources.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a custom table for that source and set its retention to 2 years.
In Microsoft Sentinel, retention is set at the table level. By creating a custom table for the specific data source and configuring its retention period to 2 years, you can override the default workspace retention for that table only. This allows other tables to retain the default retention setting while the custom table retains data for the required duration.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Create a custom table for that source and set its retention to 2 years.
Why this is correct
Create a custom table for that source and set its retention to 2 years. This is correct because Microsoft Sentinel/Log Analytics supports per-table retention policies. By routing this source's data into its own custom table, you can configure that table's retention to 2 years without changing the workspace default. That gives you precisely the granularity needed for a single source.
- ✗
Adjust the data ingestion settings for that source.
Why it's wrong here
Adjust the data ingestion settings for that source. This is wrong because ingestion settings—such as data collection rules, sampling, or diagnostic settings—control whether and how data flows into the workspace, not how long it is stored. Even if you modify ingestion to collect 2 years of history, that would be a backfill, not a retention policy. These settings cannot enforce a retention period, so this does not meet the requirement.
- ✗
Set the workspace retention to 2 years.
Why it's wrong here
Set the workspace retention to 2 years. This is wrong because the workspace retention applies globally to all tables and all sources in the Log Analytics workspace. Raising it to 2 years would extend retention for every data type, which is overbroad and potentially costlier, not just the one source. Since the requirement is to isolate a single source, this also affects unrelated data and is not targeted.
- ✗
Configure archiving for that source's data.
Why it's wrong here
Configure archiving for that source's data. This is wrong because archiving defines the lifecycle after the active retention period expires—it moves data to low-cost long-term storage, but it does not set the initial active retention duration. You could archive the source's data after, say, 90 days, but that still doesn't create a 2-year active retention. Archiving is separate from retention and cannot be used to assign a custom retention period to a single source.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.