exam questions

Exam SC-300 All Questions

View all questions & answers for the SC-300 exam

Exam SC-300 topic 2 question 83 discussion

Actual exam question from Microsoft's SC-300
Question #: 62
Topic #: 2
[All SC-300 Questions]

You have a Microsoft Entra tenant.

You need to query risky user activity for the tenant.

How long will the logs of risky user activity be retained?

  • A. 30 days
  • B. 60 days
  • C. 90 days
  • D. 180 days
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
d1e85d9
2 months, 3 weeks ago
Selected Answer: C
C) confirmed 90 Days Ref Link: https://learn.microsoft.com/en-us/entra/id-protection/howto-identity-protection-investigate-risk#how-to-investigate-risky-users
upvoted 2 times
...
rvln7
3 months, 1 week ago
Selected Answer: A
This table reflects the latest information on retention periods for Microsoft Entra Free, P1, and P2 as of February 26, 2025. I just had to mark the answer, but as I said...there is no limit for risky users. "Risky users and workload identities are not deleted until the risk has been remediated." ------------------------------------------------- | Feature | Microsoft Entra Free | P1 | P2 | ------------------------------------------------- | Audit Logs | 7 days | 30 days | 30 days | ------------------------------------------------- | Sign-ins | 7 days | 30 days | 30 days | ------------------------------------------------- | Multifactor Authentication Usage | 30 days | 30 days | 30 days | ------------------------------------------------- | Risky Users | No limit | No limit| No limit| ------------------------------------------------- | Risky Sign-ins | 7 days | 30 days | 90 days | -------------------------------------------------
upvoted 2 times
...
Rahgu
4 months, 2 weeks ago
Selected Answer: C
It's 90 days, so C.
upvoted 1 times
...
Btn26
4 months, 4 weeks ago
Selected Answer: C
Why 90 days is the better answer in this context: The question specifically asks about "risky user activity," implying the use of Identity Protection features. Identity Protection, with its detailed risk assessments and reporting, is a core component of Premium P2.   Premium P2 has a 90-day retention for risky sign-ins.
upvoted 2 times
anonymousarpanch
4 months, 2 weeks ago
sorry, if i understand the question, it is asking for Risky user logs and this URL says 'https://learn.microsoft.com/en-us/entra/identity/monitoring-health/reference-reports-data-retention' that risky users there is 'No Limit'. am i not correctly understanding this?
upvoted 2 times
...
...
Phax
7 months ago
90 days, logs of risky user activity are usually retained for 90 days...
upvoted 2 times
...
murcao
7 months ago
The question is not well done, but considering the maximum time is 90 days (Entra P2) I will select the option C > Microsoft Entra ID Free : 7 days > Microsoft Entra ID P1: 30 days > Microsoft Entra ID P2: 90 days This retention period allows you to monitor and analyze risky user activity over a significant period to ensure security and compliance More information: Audit logs > Microsoft Entra ID Free: Seven days > Microsoft Entra ID P1: Seven days > Microsoft Entra ID P2: 30 days Sign-ins > Microsoft Entra ID Free: 30 days > Microsoft Entra ID P1: 30 days > Microsoft Entra ID P2: 30 days Microsoft Entra multifactor authentication usage > Microsoft Entra ID Free: 30 days > Microsoft Entra ID P1: 30 days > Microsoft Entra ID P2: 30 days Based on the link below: https://learn.microsoft.com/en-us/entra/identity/monitoring-health/reference-reports-data-retention
upvoted 1 times
...
Nail
7 months, 2 weeks ago
Selected Answer: C
I'm going with 90. I'm in the portal right now under Identity Protection, Report, Risky Users and I can go back a maximum of 90 days. Almost all of the other questions seem to assume you have P2.
upvoted 4 times
...
Tony416
8 months, 3 weeks ago
Selected Answer: A
This is a tip found in the MS Book SC-300 Exam Prep: The risk reports have different log-rotation periods. The Risky Users report tracks risky users since the beginning of time (from the perspective of tenant inception). The Risky Sign-in report tracks with the log rotation period of the sign-in logs (30 days). The Risk Detections report has a log-rotation period of 90 days.
upvoted 3 times
...
Tony416
9 months ago
Selected Answer: D
This question is entirely nonsensical. I found 90 days. There's no reference to 30 days, even though the log time can be changed. https://learn.microsoft.com/en-us/entra/id-protection/howto-identity-protection-investigate-risk#how-to-investigate-risky-users "When administrators select an individual user, the Risky user details pane appears. Risky user details provide information like: user ID, office location, recent risky sign-in, detections not linked to a sign, and risk history. The Risk history tab shows the events that led to a user risk change in the last 90 days."
upvoted 1 times
...
jarattdavis
10 months, 3 weeks ago
Answer is 90 days. The Risk history tab also shows all the events that led to a user risk change in the last 90 days. This list includes risk detections that increased the user’s risk and admin remediation actions that lowered the user’s risk. Note: Question is not referring to Sign in risk which is 30 days. https://learn.microsoft.com/en-us/entra/id-protection/howto-identity-protection-investigate-risk#:~:text=The%20Risk%20history%20tab%20also%20shows%20all%20the%20events%20that%20led%20to%20a%20user%20risk%20change%20in%20the%20last%2090%20days
upvoted 1 times
...
ELQUMS
1 year, 3 months ago
A - in Exam
upvoted 2 times
...
Sozo
1 year, 3 months ago
Selected Answer: A
The retention period for logs of risky user activity in Microsoft Entra varies by report type and license type. For instance, the risky sign-ins report contains filterable data for up to the past 30 days. However, you can retain the audit and sign-in activity data for longer than the default retention period by routing it to an Azure storage account using Azure Monitor.
upvoted 2 times
...
baz
1 year, 4 months ago
A. The risky sign-ins report contains filterable data for up to the past 30 days (one month) https://learn.microsoft.com/en-us/entra/id-protection/howto-identity-protection-investigate-risk#risky-users-report
upvoted 4 times
...
throwaway10188
1 year, 4 months ago
This question is trash. No license specified and even if it did Risky User 'Activity' is retained until the end of time/resolved.
upvoted 3 times
...
throwaway10188
1 year, 4 months ago
https://learn.microsoft.com/en-us/entra/identity/monitoring-health/reference-reports-data-retention Risky users No limit No limit No limit Risky sign-ins 7 days 30 days 90 days Note Risky users and workload identities are not deleted until the risk has been remediated.
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...