SC-200 Manage a security operations environment Practice Question
You manage a Microsoft Sentinel workspace that ingests logs from multiple sources. You notice that the workspace is approaching its daily ingestion quota, and some data sources are being dropped. You need to ensure that security-related logs are prioritized and that non-critical logs are not ingested. What should you configure?
⚠ Common exam trap
A common mix-up: candidates confuse data collection rules (which filter at ingestion) with diagnostic settings (which control log routing) or daily caps (which stop all ingestion), failing to recognize that DCRs provide the granular control needed to prioritize specific log types.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use data collection rules (DCRs) to filter log ingestion
Data collection rules (DCRs) allow you to define transformations that filter logs before they are ingested into a Log Analytics workspace. By configuring a DCR with a KQL-based transformation, you can drop non-critical logs while ensuring security-related logs are always ingested, preventing them from being dropped when the daily quota is approached.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create analytic rules with entity mapping to prioritize alerts
Why it's wrong here
Analytic rules with entity mapping are part of Sentinel's detection layer, operating on data that has already been ingested into the Log Analytics workspace. They generate alerts and enrich them with entities such as accounts or IPs, but they cannot stop or reduce which log records are collected. Since they run after ingestion, they have no effect on the volume or type of logs sent to Sentinel, so they cannot be used to prioritize ingestion.
- ✓
Use data collection rules (DCRs) to filter log ingestion
Why this is correct
Data collection rules (DCRs) provide a pipeline-level mechanism to control what gets ingested into a Log Analytics workspace. By defining a KQL transformation in a DCR, you can filter out unwanted records or fields from specific data sources before they are stored, which directly enables selective ingestion and cost control. Because this processing occurs during the collection phase, it is the correct tool for filtering log ingestion in Sentinel.
- ✗
Set a daily cap on the Log Analytics workspace
Why it's wrong here
Setting a daily cap on the Log Analytics workspace is a blunt cost-control measure that stops all data ingestion once the cap is reached, regardless of log source or importance. It does not allow you to exclude only low-priority logs or preserve critical security data, so it can silently cause missing logs and missed alerts. The cap is workspace-scoped and cannot distinguish between log types, making it unsuitable for selective ingestion prioritization.
- ✗
Configure diagnostic settings to exclude certain logs
Why it's wrong here
Diagnostic settings are configured on Azure resources to route their platform logs and metrics to destinations like a Log Analytics workspace, and they let you choose which categories of logs to send. However, they do not support filtering individual events or fields within a selected category, and they do not apply to non-Azure or custom log sources. This means they can only exclude entire log categories, not selectively filter the content of incoming logs, so they are insufficient for granular ingestion control.
Go deeper
Related to this question
About these practice questions
This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.