Courseiva

SC-200 Manage a security operations environment Practice Question

Which TWO actions should you take to improve the performance of Microsoft Sentinel analytics rules that are running slowly? (Choose two.)

⚠ Common exam trap

A common mix-up: candidates confuse rule configuration settings (like severity or frequency) with query performance optimizations, mistakenly thinking that increasing frequency or adding mappings will somehow speed up execution, when in fact they degrade it.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Reduce the query time window

Reducing the query time window (Option B) directly limits the volume of data the analytics rule must process per execution, which reduces query latency and overall rule execution time. This is a common performance optimization because Sentinel analytics rules run KQL queries against the Log Analytics workspace, and smaller time ranges mean fewer log records to scan.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Assign a higher severity to the rule

    Why it's wrong here

    Assigning a higher severity to a detection rule only changes the alert's classification and prioritization in the incident queue; it does not alter how the query is executed or what data is scanned. Severity is a metadata field applied after detection and has zero influence on the rule's performance or resource consumption during scheduled runs.

  • ✓

    Reduce the query time window

    Why this is correct

    Reducing the query time window directly narrows the amount of log data that must be scanned by the detection rule, which lowers I/O and compute costs. For example, changing from 7 days to 24 hours can cut the data volume by roughly a factor of seven for a single execution, dramatically reducing latency and improving overall throughput without changing the query logic.

  • ✓

    Use summarized data in the query

    Why this is correct

    Using summarized or pre-aggregated data, such as Kusto summary tables or Azure Monitor's summarize operator over a materialized view, reduces the cardinality and volume of rows the detection query must process. Instead of scanning raw, verbose event logs, the rule can operate on compacted metrics, which yields faster query times and lower resource usage while preserving the needed detection signals.

  • ✗

    Increase the rule run frequency

    Why it's wrong here

    Increasing the rule run frequency means the same query executes more often over the same data volume, which multiplies the total number of scans and raises the cumulative load on the Log Analytics workspace. More frequent executions do not speed up any individual query; they actually degrade performance by competing for the same ingestion and query resources, potentially causing throttling or delays.

  • ✗

    Add additional entity mapping

    Why it's wrong here

    Adding additional entity mapping enriches the alert output with more fields (users, hosts, IPs) but forces the detection engine to perform extra lookups and data transformations during result processing. This added complexity increases CPU and memory overhead per alert and can slow down the rule's execution, especially when high-volume alerts are generated, without improving detection speed or accuracy.

About these practice questions

This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.