Courseiva

SC-200 Manage a security operations environment Practice Question

You are managing a Microsoft Sentinel environment that ingests data from multiple sources: Microsoft 365, Azure Activity, and custom logs via AMA. The SOC manager has requested that all security events from Windows servers be collected and stored for 90 days for compliance purposes. You have configured the Windows Security Events via AMA data connector to collect all events (Event ID 4624, 4625, etc.) and set the workspace retention to 90 days. After a week, you notice that the daily ingested volume is higher than expected, exceeding the budget. You analyze the data and find that many low-severity informational events are being ingested, such as Event ID 5156 (Windows Filtering Platform allowed connection). The manager confirms that only security-relevant events are needed. What should you do to reduce ingestion volume while still meeting compliance requirements?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Modify the data collection rule (DCR) for the Windows Security Events connector to use a custom XPath query that excludes informational events (e.g., exclude Event ID 5156).

The AMA connector uses data collection rules (DCRs) that allow you to filter events based on custom XPath queries. By creating a custom XPath query that excludes informational events like Event ID 5156, you can reduce ingestion volume while still collecting security-relevant events (e.g., 4624, 4625) for the required 90-day retention. Option A is incorrect because reducing the workspace retention to 30 days would violate the compliance requirement for 90 days. Option B is incorrect because the Azure Activity data connector collects Azure resource logs, not Windows security events. Option D is incorrect because the legacy MMA connector is deprecated and does not provide the same filtering capabilities; AMA is the recommended solution.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Reduce the workspace retention period to 30 days to lower storage costs.

    Why it's wrong here

    Retention governs how long data is stored, not how much is ingested; shortening it to 30 days breaches the 90-day compliance requirement while leaving the 5156 volume unchanged. It tempts because retention reduction genuinely cuts long-term storage cost, which would be right if the requirement were storage spend rather than event filtering.

  • ✗

    Configure the Azure Activity data connector to filter out low-severity events.

    Why it's wrong here

    The Azure Activity connector ingests control-plane operations from the Azure platform, not Windows Security event logs, so filtering it leaves Event ID 5156 flowing through the AMA connector unchanged. It is tempting because both connectors feed the same workspace, but Activity filtering is the correct choice for reducing Azure subscription audit noise.

  • ✓

    Modify the data collection rule (DCR) for the Windows Security Events connector to use a custom XPath query that excludes informational events (e.g., exclude Event ID 5156).

    Why this is correct

    Filtering at the data collection rule with a custom XPath query stops Event ID 5156 and similar informational events before ingestion, directly cutting volume and cost. Because the DCR sits between the AMA agent and the workspace, excluded events never reach Microsoft Sentinel, while security-relevant events still land and satisfy the 90-day retention requirement.

  • ✗

    Disable the AMA-based connector and use the legacy MMA-based connector instead.

    Why it's wrong here

    The legacy MMA connector is deprecated and offers no event-level filtering that the AMA connector lacks; switching connectors does not remove Event ID 5156 ingestion. It is tempting because MMA was the previous standard for Windows event collection, but it is the correct choice only for hosts that AMA cannot yet onboard.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.