Courseiva

SC-200 Manage a security operations environment Practice Question

Your organization has a Microsoft Sentinel workspace that ingests data from multiple sources. You notice that the cost of data ingestion is higher than expected. You need to reduce costs without affecting security visibility. Which action should you take?

⚠ Common exam trap

Many candidates assume reducing retention or disabling log sources is the simplest cost-saving measure, but the SC-200 exam emphasizes that cost reduction must never compromise security visibility, making the Basic Logs tier the only option that selectively lowers cost without losing critical security data.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure specific tables to use the Basic Logs tier instead of Analytics Logs.

Configuring specific tables to use the Basic Logs tier reduces ingestion costs for high-volume, low-security-value data (e.g., verbose diagnostics or debug logs) while retaining full analytical capabilities for security-critical tables in the Analytics Logs tier. Basic Logs are charged at a lower ingestion rate and support simple queries, but they lack the full KQL and indexing features of Analytics Logs, so you must carefully select which tables to downgrade to avoid impacting security visibility.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Reduce the data retention period for all tables to 30 days.

    Why it's wrong here

    Reducing retention to 30 days across all tables indiscriminately jeopardizes compliance and historical threat hunting, because many analytics rules and investigations depend on longer data availability. Retention duration is separate from ingestion cost, so this does not lower the daily bill for data being processed. A targeted approach, such as switching verbose, seldom-queried tables to Basic Logs, preserves critical data while addressing cost.

  • ✗

    Disable the collection of Windows event logs from domain controllers.

    Why it's wrong here

    Disabling Windows event log collection from domain controllers removes visibility into authentication failures, privilege escalation attempts, and indicators of Active Directory compromise, which are core detection sources for Sentinel. While it reduces ingested volume, it cripples critical security monitoring and incident response. This cost saving is sub-optimal; better to selectively reduce verbose event IDs or use Basic Logs for those tables.

  • ✓

    Configure specific tables to use the Basic Logs tier instead of Analytics Logs.

    Why this is correct

    Configuring specific tables, such as high-volume diagnostic tables, to the Basic Logs tier reduces ingestion cost while still allowing basic KQL queries and a limited retention window. Basic Logs are designed for verbose, less frequently accessed data and cost about 25% of Analytics Logs, but they do not support full analytics, alerts, or advanced hunting features. This option directly addresses cost without removing data from Sentinel, unlike other choices.

  • ✗

    Export logs to Azure Storage and use Azure Data Explorer for analysis.

    Why it's wrong here

    Exporting logs to Azure Storage and querying with Azure Data Explorer creates a separate analytical silo, breaking Sentinel's unified investigation experience and requiring additional tools and skill sets. ADX incurs its own compute and storage costs, often delivering less cost savings than using Basic Logs within Sentinel, while also losing native integrations for analytics rules and UEBA. This approach also increases operational complexity without solving the original cost problem.

About these practice questions

This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

2 more ways this is tested on SC-200

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. You are managing a Microsoft Sentinel workspace that ingests data from multiple sources. You need to reduce the cost of log ingestion while maintaining security visibility. Which two actions should you take?

hard
  • A.Remove all custom log connectors that are not used frequently.
  • B.Increase the retention period for all tables to 90 days to avoid data loss.
  • ✓ C.Enable analytics rules to run only on high-value data sources.
  • ✓ D.Configure data collection rules to send non-critical logs to the Basic Logs tier.
  • E.Use compression algorithms in Log Analytics to reduce log size.

Why C: Option C is correct because scoping analytics rules to high-value data sources reduces the volume of queries and alerts processed, which lowers ingestion and analytics costs while preserving visibility into the most security-relevant events. Option D is correct because configuring data collection rules (DCRs) to route non-critical logs to the Basic Logs tier significantly reduces ingestion cost, since Basic Logs are priced lower than Analytics Logs while still retaining the data for investigation. Option A is not correct because removing unused custom connectors may reduce ingestion but does not directly address cost optimization of the data already being ingested, and it risks losing visibility if those connectors are needed later. Option B is not correct because increasing retention to 90 days for all tables increases cost rather than reducing it. Option E is not correct because Log Analytics does not expose user-configurable compression algorithms for reducing log size; compression is handled by the service and is not a valid cost-reduction action.

Variation 2. You are responsible for Microsoft Sentinel pricing. You notice that data ingestion costs are high due to verbose logs from Windows security events. You need to reduce costs while still collecting critical security events. What should you do?

hard
  • A.Use Common Event Format (CEF) connector instead of Windows Events
  • B.Change the table plan to Basic Logs
  • C.Increase the workspace retention period to archive warm data
  • ✓ D.Configure Windows Security Events via AMA connector with event filtering

Why D: The Azure Monitor Agent (AMA) connector for Windows Security Events allows granular filtering of event IDs and levels, enabling you to collect only critical security events (e.g., 4624, 4625) while excluding verbose logs like Event ID 5156 (Windows Filtering Platform permit connections). This reduces ingestion volume and cost without losing essential security visibility.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.