StudyToCert

All certifications / SC-200 / Lessons

Microsoft Certified: Security Operations Analyst Associate SC-200 · Domain 1: Manage a security operations environment

Data retention and cost: analytics tier vs Sentinel data lake tier, table plans, summary rules, SOC optimization recommendations

▶ Watch the overview video

Last reviewed September 30, 2026 · Leer en español

Sentinel is billed mainly on the data you ingest and how long you keep it, so a security operations analyst has to think about cost as well as coverage. Not every log deserves the same treatment. High-value security signals that feed detections, such as sign-in logs, endpoint alerts and identity events, should be fast to query. High-volume, low-value logs, such as verbose firewall, proxy or network flow traffic, are often kept mainly for investigations and compliance. Good design puts each kind of data in the tier that matches how you use it.

Free account

Keep reading for free

Create a free StudyToCert account to read the rest of this lesson: 7 more sections, 6 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.

Sign up free Log in

Study SC-200 for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the SC-200 study plan