StudyToCert

All certifications / SC-500 / Lessons

Microsoft Certified: Cloud and AI Security Engineer Associate (replaces Azure Security Engineer Associate / AZ-500) SC-500 · Domain 4: Manage and monitor security posture

Log tiers and retention (Analytics vs data lake/auxiliary), custom tables, KQL basics

▶ Watch the overview video

Last reviewed September 25, 2026 · Leer en español

Security logs are valuable but expensive when ingested at full price. High-volume sources such as firewall flows, proxy logs or DNS queries may be needed for investigations and compliance, yet rarely used for real-time detection. Sentinel and Log Analytics therefore offer tiers, called table plans, that trade features for cost. Microsoft has been evolving these options, so focus on the concepts and check current names in the portal.

Free account

Keep reading for free

Create a free StudyToCert account to read the rest of this lesson: 6 more sections, 5 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.

Sign up free Log in

Study SC-500 for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the SC-500 study plan