SC-200 Manage a security operations environment Practice Question
Which THREE actions are recommended practices for managing Microsoft Sentinel costs?
⚠ Common exam trap
A common mix-up: candidates confuse 'complete visibility' (Option D) with best practice, but Microsoft Sentinel explicitly recommends filtering noise at ingestion to reduce costs and improve signal-to-noise ratio, not ingesting everything.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Set daily caps on high-volume tables.
Setting daily caps on high-volume tables is a recommended practice because it prevents unexpected cost overruns by limiting the amount of data ingested into expensive tables like SecurityEvent or CommonSecurityLog. Microsoft Sentinel bills per GB ingested, so capping tables that generate large volumes of noise (e.g., verbose Windows event logs) directly controls costs without necessarily impacting security visibility, as critical alerts can still be generated from other sources.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Set daily caps on high-volume tables.
Why this is correct
Setting a daily cap on high-volume tables is a cost-control safeguard that stops ingestion once the defined quota is reached, preventing runaway spend from unexpected data spikes. However, you must configure the cap carefully so that critical security telemetry is not dropped during an incident, since any data exceeding the cap is discarded. This practice is explicitly recommended in Microsoft Sentinel and Log Analytics cost optimization guidance.
- ✓
Use Basic Logs tier for verbose logs.
Why this is correct
The Basic Logs tier stores verbose, high-volume tables at a significantly lower cost than Analytics Logs while still allowing queries with KQL, though with a longer query time and limited interactive analytics features. This is ideal for troubleshooting or debugging logs that are rarely queried, such as custom application traces, because you retain visibility without paying full price. It is a recommended practice because it aligns retention needs with cost efficiency.
- ✓
Implement ingestion-time data transformation to filter out noise.
Why this is correct
Implementing ingestion-time data transformation through a data collection rule (DCR) filters out irrelevant or noisy records before they are stored, reducing the overall volume ingested into Log Analytics. This directly lowers daily ingestion charges and storage costs while still preserving the meaningful data needed for security analytics. It is a core recommendation in Sentinel cost management because it stops unnecessary data at the source rather than after incurring cost.
- ✗
Ingest all logs to ensure complete visibility.
Why it's wrong here
Ingesting all logs in the mistaken belief that it guarantees complete visibility actually creates cost bloat, noise, and alert fatigue, making it harder for analysts to find genuine threats. Many verbose logs contain redundant, informational, or duplicate data that provides little security value, so 'complete' capture does not equal better detection. This approach contradicts the Microsoft Sentinel guidance to curate data sources based on investigative value and threat detection needs.
- ✗
Increase retention period to 1 year for all tables.
Why it's wrong here
Raising retention to 365 days for every table dramatically increases storage and archive costs because most tables contain data with limited short-term analytical value. Microsoft Sentinel recommends using tiered retention—keeping hot data for interactive queries and moving older data to long-term retention (archive) or adjusting per-table retention policies based on compliance and investigation requirements. Uniform long retention is wasteful, as only a fraction of logs are ever accessed after a few weeks.
Go deeper
Related to this question
About these practice questions
This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
2 more ways this is tested on SC-200
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Which TWO actions should you take to optimize cost in Microsoft Sentinel while maintaining security coverage? (Choose two.)
medium- A.Enable continuous export for all tables.
- B.Purchase a Pay-as-you-go commitment tier.
- ✓ C.Adjust the interactive retention period for tables that don't need long-term interactive access.
- D.Add more tables to ingest data.
- ✓ E.Use Basic Logs for high-volume, low-value data sources.
Why C: Reducing interactive retention for tables that do not require long-term, fast query access directly lowers storage costs. Microsoft Sentinel charges per GB for data stored in the interactive retention tier, while data moved to long-term retention (up to 12 years) is significantly cheaper. By tailoring retention periods to actual operational needs, you avoid paying premium rates for data that is rarely queried interactively.
Variation 2. Which TWO actions should you take to reduce the cost of Microsoft Sentinel while maintaining security coverage?
hard- A.Remove data connectors for non-critical sources.
- ✓ B.Reduce the retention period of tables that do not require long-term storage.
- ✓ C.Ingest verbose logs (e.g., DNS events) into Basic Logs tier.
- D.Disable analytics rules that generate low-severity incidents.
- E.Switch the workspace pricing tier from Capacity Reservations to Pay-as-you-Go.
Why B: Reducing the retention period for tables that do not require long-term storage directly lowers the data storage costs in Microsoft Sentinel. Sentinel charges per GB of data stored, and by shortening retention (e.g., from 90 days to 30 days) for non-critical tables, you reduce the volume of data retained without affecting security monitoring or incident investigation for the shortened period.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.