Courseiva

SC-200 Manage a security operations environment Practice Question

Your organization has a Microsoft Sentinel workspace that ingests logs from Azure resources, Microsoft 365, and third-party firewalls. You need to ensure that data retention for Azure Activity logs complies with a regulatory requirement of 3 years, while keeping costs low for other data types. What should you do?

⚠ Common exam trap

Candidates often confuse workspace-level retention with table-level retention, assuming that setting the workspace retention to 3 years is the only way to meet the requirement, when in fact table-level policies allow granular control without affecting other data types.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure a data retention policy on the AzureActivity table to 3 years.

Azure Sentinel allows you to configure a custom retention policy on a specific table (e.g., AzureActivity) to retain data for up to 2 years (or longer with Archive tier) independently of the workspace's default retention. This meets the 3-year regulatory requirement for Azure Activity logs without increasing retention costs for other data types, as the workspace default can remain shorter.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use the Archive tier for Azure Activity logs and set the total retention period to 3 years.

    Why it's wrong here

    The Archive tier in Log Analytics stores data in a cost-optimized cold storage that requires rehydration before it can be queried, making it unsuitable when logs must remain readily accessible for compliance audits. Furthermore, setting a total retention period of 3 years on the archive tier does not replace the need for table-level retention policies, and rehydration latency could cause delays for time-sensitive investigations.

  • ✗

    Set the workspace retention to 3 years.

    Why it's wrong here

    Increasing the workspace's default retention to 3 years forces every table (SecurityEvent, Heartbeat, etc.) to retain data for that period, generating unnecessary storage and licensing costs. Compliance for Azure Activity logs alone should be met with a targeted table-level retention policy, leaving other logs on shorter, cost-appropriate retention.

  • ✓

    Configure a data retention policy on the AzureActivity table to 3 years.

    Why this is correct

    This is correct because table-level retention policies let you extend or shorten the retention for a specific table, here the AzureActivity table, to meet 3-year compliance for Azure Activity logs without affecting other tables' data lifecycle. Since the policy targets only that table's logs, it balances compliance requirements with cost optimization while keeping the data natively queryable in the Log Analytics workspace.

  • ✗

    Enable Basic Logs plan on the AzureActivity table.

    Why it's wrong here

    The Basic Logs plan reduces ingestion cost by offering a cheaper, up-to-30-day interactive retention and up to 7-year archive retention, but it does not change the fact that you must define a retention policy for the table. Enabling Basic Logs alone does not guarantee 3-year retention; you still need to set archive/retention, and it may require rehydration for interactive queries, so it fails to meet the compliance requirement as specified.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.