Courseiva

SC-200 Manage a security operations environment Practice Question

Your Microsoft Sentinel workspace is ingesting logs from multiple sources. You notice that the data ingestion cost is higher than expected. You want to reduce costs without losing security value. Which action should you take?

⚠ Common exam trap

Candidates often confuse reducing retention (Option A) with reducing ingestion volume, or they mistakenly think disabling analytics rules (Option C) lowers ingestion costs, when in fact ingestion cost is driven by data volume, not rule execution.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure basic logs ingestion for verbose data sources such as firewall logs.

Basic logs are designed for high-volume, verbose data sources (e.g., firewall logs, syslog) that have lower security value. They are stored at a reduced cost and support only summary queries, not full KQL analytics. By routing verbose logs to basic logs, you reduce ingestion costs while retaining the ability to perform threat hunting and incident response on high-value analytics logs.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Reduce the retention period for all data to 30 days.

    Why it's wrong here

    Reducing the retention period to 30 days across all tables would prematurely purge historical telemetry, potentially violating compliance or regulatory requirements and hampering retrospective investigations that require data older than a month. Furthermore, Sentinel's primary cost driver is data ingestion, not retention; while this change does lower storage costs slightly, it fails to address the ongoing ingestion volume that is inflating the bill. It also doesn't exploit cheaper Basic Logs tiers or capacity reservations to reduce per-GB charges.

  • ✗

    Switch the pricing tier from Capacity Reservations to Pay-as-you-go.

    Why it's wrong here

    Switching from Capacity Reservations to Pay-as-you-go increases the per-GB ingest price for a workspace with steady, high-volume data flow, because capacity tiers offer discounted rates (for example, up to 60% compared to PAYG) for committed throughput. This move would eliminate that commitment discount and expose the organization to price volatility as ingestion spikes, leading to a higher average cost per GB, not a reduction. It is effectively the opposite of a cost-saving measure for predictable, large-scale ingestion.

  • ✗

    Disable analytics rules that generate high volume of alerts.

    Why it's wrong here

    Disabling analytics rules simply to reduce alert volume does not lower Sentinel ingestion costs, since billing is based on data volume, not the number of rules or alerts generated. It also creates significant security blind spots, allowing threats to go undetected because the rules that flag malicious behavior are turned off. The better approach is to tune or suppress noisy rules, or route their source data to Basic Logs, rather than losing detection coverage.

  • ✓

    Configure basic logs ingestion for verbose data sources such as firewall logs.

    Why this is correct

    Configuring Basic Logs ingestion for verbose data sources such as firewall logs is a valid cost optimization because this data tier is significantly cheaper per GB than Analytics Logs, yet still queryable for incident response using KQL within the 8-day default retention window. This allows you to preserve high-volume raw telemetry for on-demand hunting and investigation without paying full analytics prices for every event, and you can selectively upgrade specific tables or add dedicated retention policies as needed. It directly reduces the main cost driver—ingestion—while maintaining access to the data for Deep Dive (also known as resource-oriented) when a security incident occurs.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.