SC-200 Manage a security operations environment Practice Question
Which TWO actions can reduce the cost of Microsoft Sentinel while maintaining security coverage?
⚠ Common exam trap
Many exam-takers confuse reducing retention (Option E) with cost savings, but Microsoft explicitly warns that deleting logs can break detection rules and incident investigations, whereas tiering (Basic Logs or archive) preserves data for compliance and hunting at a lower cost.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure some tables to use Basic Logs tier.
Configuring tables to use the Basic Logs tier reduces ingestion costs for high-volume, verbose logs (e.g., from firewalls or DNS servers) while still retaining the data for security analysis. Basic Logs are stored at a lower cost per GB but have reduced query capabilities (e.g., no interactive full-text search, limited to KQL summarization). This allows you to keep security coverage by retaining the logs for detection and investigation, albeit with a different query pattern.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Remove unused data connectors.
Why it's wrong here
Removing unused data connectors does not directly reduce Sentinel costs because Sentinel pricing is based on data ingestion volume and analysis, not the number of connectors. While fewer connectors may reduce data volume, it also degrades security visibility, potentially missing malicious activity. The cost savings are usually negligible compared to the increased risk and potential compliance impact.
- ✗
Switch to a pay-as-you-go workspace.
Why it's wrong here
Switching to a pay-as-you-go workspace does not lower Sentinel costs because Sentinel is billed separately from the workspace's pricing tier. Pay-as-you-go is a workspace model that affects Log Analytics storage and retention costs, but Sentinel ingestion and analysis charges remain separate. In fact, moving away from a commitment tier could increase the per-GB Sentinel cost, making the workspace more expensive overall.
- ✓
Configure some tables to use Basic Logs tier.
Why this is correct
Configuring some tables to use Basic Logs tier reduces cost because Basic Logs are offered at a significantly lower ingestion price than Analytics Logs (up to 75% cheaper). This tier is ideal for high-volume, verbose tables used for debugging or troubleshooting, not for security analytics requiring advanced queries and alerts. However, Basic Logs have a shorter retention period and limited query capabilities, so they should only be used for tables that do not drive detection rules.
- ✓
Move older logs to Azure Storage archive tier.
Why this is correct
Moving older logs to Azure Storage archive tier reduces cost because archiving offloads data from expensive Log Analytics retention to low-cost Blob storage, where you pay only for storage and occasional retrieval. Sentinel no longer charges for ingestion or retention of those archived logs, yet you can still access them on-demand if a deeper investigation is required. This strategy preserves historical data for compliance while cutting ongoing workspace retention expenses.
- ✗
Reduce workspace retention to 30 days for all tables.
Why it's wrong here
Reducing workspace retention to 30 days for all tables is not a valid cost-saving measure because it treats all logs uniformly, ignoring that some tables require longer retention to satisfy compliance requirements or support long-term security investigations. Such a blanket reduction could delete critical evidence before an incident is fully investigated, potentially leading to data loss and non-compliance penalties. While it may lower short-term costs, the operational and legal risks far outweigh the savings, making it an unsafe practice.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.