Courseiva

SC-200 Manage a security operations environment Practice Question

Your organization uses Microsoft Sentinel and wants to ensure that all incident-related data is retained for at least 90 days for compliance purposes. Which configuration should you check?

⚠ Common exam trap

Candidates often confuse incident settings (which manage incident metadata and lifecycle) with data retention settings, assuming that configuring incident retention in Sentinel is sufficient, when in fact the underlying log data retention is controlled at the Log Analytics workspace level.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Log Analytics workspace retention settings

Log Analytics workspace retention settings directly control how long raw data ingested into Microsoft Sentinel is stored. For compliance requiring 90-day retention of incident-related data, you must configure the workspace retention period to at least 90 days (or use archive policies for longer retention). Incident data in Sentinel is derived from this underlying workspace data, so retention settings at the workspace level ensure the data persists for the required duration.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Log Analytics workspace retention settings

    Why this is correct

    In Microsoft Sentinel, all ingested telemetry resides in a designated Log Analytics workspace, and the workspace's retention settings determine how many days of raw logs are available for queries, analytics, and threat hunting. Adjusting table-level or workspace-level retention directly controls the lifespan of that data, including whether it moves to long-term retention or archive. Because Sentinel does not maintain a separate storage pool, the Log Analytics retention configuration is the authoritative mechanism for data retention.

  • ✗

    Watchlist settings

    Why it's wrong here

    Watchlist settings in Sentinel let you upload CSV files that act as reference datasets for matching high-value assets, such as VIP account names or sensitive IP ranges, inside analytics rules and hunting queries. These lists are stored as a dedicated _GetWatchlist table and are not the source of workspace telemetry. Configuring a watchlist affects only the contents and availability of those reference lists, not how long the underlying log data is retained.

  • ✗

    Analytics rule settings

    Why it's wrong here

    Analytics rule settings define the detection logic, schedule, query frequency, entity mapping, and alert creation thresholds that generate incidents from log data, but they have no influence over data lifecycle or retention periods. A rule simply runs queries against whatever data resides in the workspace, regardless of how long that data has been stored. Thus, modifying rule settings may change alerts, but it will never extend or shrink the workspace's retention of the underlying security event logs.

  • ✗

    Incident settings in Sentinel

    Why it's wrong here

    Incident settings in Sentinel govern the incident management experience, including alert grouping rules, incident creation status, case classification, and automation triggers within the Incident section of the portal. These settings determine how and when an incident is created from an alert, along with its severity and assignment, but they do not modify the retention policy of the Log Analytics workspace. As a result, adjusting incident settings affects only the incident console and workflows, leaving the raw log data retention entirely untouched.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.