SC-200 Manage a security operations environment Practice Question
You are responsible for Microsoft Sentinel pricing. You notice that data ingestion costs are high due to verbose logs from Windows security events. You need to reduce costs while still collecting critical security events. What should you do?
⚠ Common exam trap
Test-takers frequently confuse 'reducing costs' with 'changing retention' (Option C) or 'using a different connector' (Option A), when the real solution is to filter data at the source using the AMA's event filtering capability, which directly addresses ingestion volume.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure Windows Security Events via AMA connector with event filtering
The Azure Monitor Agent (AMA) connector for Windows Security Events allows granular filtering of event IDs and levels, enabling you to collect only critical security events (e.g., 4624, 4625) while excluding verbose logs like Event ID 5156 (Windows Filtering Platform permit connections). This reduces ingestion volume and cost without losing essential security visibility.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use Common Event Format (CEF) connector instead of Windows Events
Why it's wrong here
CEF is a syslog-based format for routing logs from security appliances, not a mechanism for collecting Windows Security Events. Replacing a Windows Event collection path with CEF would either require a separate syslog forwarder and lose native Windows event fields, or fail to capture the same Event IDs altogether. This change does not reduce the volume of Windows security data being ingested, so it cannot lower Sentinel costs for Windows event sources.
- ✗
Change the table plan to Basic Logs
Why it's wrong here
Moving a table to Basic Logs does lower the per-GB ingestion price, but it does not eliminate ingestion fees—you still pay for every gigabyte sent to the table. Basic Logs also have a higher query price and do not currently support the full Log Analytics/Sentinel features needed for interactive security investigations and scheduled analytics rules. For Windows Security Events, which require fast, frequent, and full-data queries, this plan is operationally inappropriate despite the cheaper entry price.
- ✗
Increase the workspace retention period to archive warm data
Why it's wrong here
Increasing the workspace retention period, or moving older data to warm or archive tiers, extends how long data is stored after it has already been ingested. It does nothing to change the amount of data being sent to the workspace, so the per-GB ingestion cost remains the same. In fact, raising retention or archiving warm data typically increases total storage or access costs, making it the opposite of a cost-reduction measure for data that is still being collected now.
- ✓
Configure Windows Security Events via AMA connector with event filtering
Why this is correct
Configuring Windows Security Events via the Azure Monitor Agent (AMA) connector with a data collection rule is the correct approach because it filters event IDs and event levels at the source before the data is transmitted to the workspace. You can select only high-signal security events such as 4624/4625 (logon) and 4688 (process creation) and suppress verbose or unneeded event categories, reducing billable ingestion volume. This directly lowers the Log Analytics/Sentinel ingestion cost while still keeping the security telemetry your analytics rules require.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.