Courseiva

SC-200 Manage a security operations environment Practice Question

Which TWO actions can reduce the cost of Microsoft Sentinel while maintaining security coverage?

⚠ Common exam trap

Many exam-takers confuse reducing retention (Option E) with cost savings, but Microsoft explicitly warns that deleting logs can break detection rules and incident investigations, whereas tiering (Basic Logs or archive) preserves data for compliance and hunting at a lower cost.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure some tables to use Basic Logs tier.

Configuring tables to use the Basic Logs tier reduces ingestion costs for high-volume, verbose logs (e.g., from firewalls or DNS servers) while still retaining the data for security analysis. Basic Logs are stored at a lower cost per GB but have reduced query capabilities (e.g., no interactive full-text search, limited to KQL summarization). This allows you to keep security coverage by retaining the logs for detection and investigation, albeit with a different query pattern.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Remove unused data connectors.

    Why it's wrong here

    Removing unused data connectors does not directly reduce Sentinel costs because Sentinel pricing is based on data ingestion volume and analysis, not the number of connectors. While fewer connectors may reduce data volume, it also degrades security visibility, potentially missing malicious activity. The cost savings are usually negligible compared to the increased risk and potential compliance impact.

  • ✗

    Switch to a pay-as-you-go workspace.

    Why it's wrong here

    Switching to a pay-as-you-go workspace does not lower Sentinel costs because Sentinel is billed separately from the workspace's pricing tier. Pay-as-you-go is a workspace model that affects Log Analytics storage and retention costs, but Sentinel ingestion and analysis charges remain separate. In fact, moving away from a commitment tier could increase the per-GB Sentinel cost, making the workspace more expensive overall.

  • ✓

    Configure some tables to use Basic Logs tier.

    Why this is correct

    Configuring some tables to use Basic Logs tier reduces cost because Basic Logs are offered at a significantly lower ingestion price than Analytics Logs (up to 75% cheaper). This tier is ideal for high-volume, verbose tables used for debugging or troubleshooting, not for security analytics requiring advanced queries and alerts. However, Basic Logs have a shorter retention period and limited query capabilities, so they should only be used for tables that do not drive detection rules.

  • ✓

    Move older logs to Azure Storage archive tier.

    Why this is correct

    Moving older logs to Azure Storage archive tier reduces cost because archiving offloads data from expensive Log Analytics retention to low-cost Blob storage, where you pay only for storage and occasional retrieval. Sentinel no longer charges for ingestion or retention of those archived logs, yet you can still access them on-demand if a deeper investigation is required. This strategy preserves historical data for compliance while cutting ongoing workspace retention expenses.

  • ✗

    Reduce workspace retention to 30 days for all tables.

    Why it's wrong here

    Reducing workspace retention to 30 days for all tables is not a valid cost-saving measure because it treats all logs uniformly, ignoring that some tables require longer retention to satisfy compliance requirements or support long-term security investigations. Such a blanket reduction could delete critical evidence before an incident is fully investigated, potentially leading to data loss and non-compliance penalties. While it may lower short-term costs, the operational and legal risks far outweigh the savings, making it an unsafe practice.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.