SC-200 Manage a security operations environment Practice Question
Exhibit
Refer to the exhibit.
```json
{
"$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentParameters.json#",
"contentVersion": "1.0.0.0",
"parameters": {
"workspaceName": {
"value": "SentinelWorkspace"
},
"location": {
"value": "eastus"
},
"sku": {
"value": "PerGB2018"
},
"retentionInDays": {
"value": 90
},
"dataRetentionForDailyQuotaInGB": {
"value": 5
},
"dailyQuotaInGB": {
"value": 10
}
}
}
```Refer to the exhibit. You are deploying a Microsoft Sentinel workspace using an ARM template. After deployment, you notice the workspace is in a disabled state for ingesting data. Which parameter is most likely causing this?
⚠ Common exam trap
The SC-200 exam often tests the misconception that workspace names must be globally unique (like storage accounts) or that Sentinel availability varies by region, when in fact the daily cap is the direct cause of a disabled ingestion state.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The dailyQuotaInGB parameter sets a daily cap that may have been exceeded
The dailyQuotaInGB parameter sets a daily ingestion cap for the Log Analytics workspace. If this cap is reached, data ingestion is disabled until the next day, causing the workspace to appear in a disabled state for ingesting data. This is the most likely cause because the question explicitly states the workspace is disabled for data ingestion, which aligns with the behavior of the daily cap being exceeded.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The location parameter is set to 'eastus' but Sentinel is not available in that region
Why it's wrong here
East US is actually one of the many supported Azure regions for Microsoft Sentinel, so the location parameter pointing to eastus is valid and would not cause the workspace to be disabled. The location parameter determines the Azure region for the Log Analytics workspace, and Sentinel is deployed on top of that workspace; if an unsupported region were chosen, the deployment would fail immediately, not result in a workspace that is operationally disabled after creation.
- ✓
The dailyQuotaInGB parameter sets a daily cap that may have been exceeded
Why this is correct
The dailyQuotaInGB parameter is the correct culprit: it configures the workspace's daily ingest cap in the Log Analytics workspace backing your Sentinel deployment. When that cap is reached, Log Analytics pauses data ingestion for the remainder of the day, so Sentinel appears to be 'disabled' because it stops receiving security logs and alerts. This is a well-known operational state that is incorrectly diagnosed as an outage, and it persists until the next day or until the quota is raised.
- ✗
The retentionInDays parameter is set to 90, which is less than the default 30 days
Why it's wrong here
This statement is factually reversed: the retentionInDays parameter is set to 90, which is actually greater than the Log Analytics default of 30 days, not less than it. Retention merely defines how many days historical data is kept before it is purged, and it has no effect on whether the workspace is actively ingesting data. Therefore, a 90-day retention setting cannot be the reason the Sentinel workspace appears disabled.
- ✗
The workspaceName parameter is set to 'SentinelWorkspace' but the name must be globally unique
Why it's wrong here
The workspaceName parameter does not have a global uniqueness requirement; Log Analytics workspace names only need to be unique within their resource group, and each workspace also gets a globally unique workspace ID (customer ID) that is automatically assigned. If the name were already in use, the deployment would fail with a conflict error before the workspace could go live. Since the workspace exists and is being queried for this issue, a name collision is not a plausible explanation for it being disabled.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.