Courseiva
Manage identity and access →mediumMultiple Choice

AZ-500 Manage identity and access Practice Question

A security operations team uses Microsoft Sentinel. They want to enable User and Entity Behavior Analytics (UEBA) to detect anomalous user activities. Which configuration is required?

⚠ Common exam trap

Watch out — candidates often confuse enabling a feature with installing a connector or creating a rule, but UEBA is a toggle in Sentinel settings, not a data source or alert rule.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable UEBA in the Sentinel settings

UEBA in Microsoft Sentinel is a built-in feature that must be explicitly enabled in the Sentinel configuration settings under 'Entity behavior analytics'. It does not require a separate data connector or analytics rule template; once enabled, Sentinel automatically ingests and analyzes existing log data (e.g., Microsoft Entra ID sign-ins, Office 365 audit logs) to establish behavioral baselines and detect anomalies.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Enable UEBA in the Sentinel settings

    Why this is correct

    UEBA must be explicitly turned on in Microsoft Sentinel by navigating to Settings > Entity behavior and toggling the feature. It does not require any separate deployment or data source configuration because it operates on data already ingested through existing connectors, such as Microsoft Entra ID and Windows Security Events. The toggle immediately activates behavioral profiling for entities like users and hosts, so without this action, no UEBA-based alerts or insights will appear.

  • ✗

    Install the UEBA data connector

    Why it's wrong here

    There is no 'UEBA data connector' in Microsoft Sentinel. UEBA is not a data source that can be installed; it is a built-in analytics engine that consumes telemetry from connectors you have already configured, such as Microsoft Entra ID sign-in logs, Windows Security events, and Office 365 activity. Trying to install a nonexistent connector will not enable UEBA and will only waste time, as the actual requirement is flipping the feature switch in the workspace settings.

  • ✗

    Create an analytics rule with UEBA template

    Why it's wrong here

    Sentinel's analytics rule templates that reference UEBA behaviors, such as 'Anomalous Sign-In Behavior', depend on the entity behavior data that UEBA generates. If UEBA is not enabled first, those rules will either fail to run correctly or produce no results because the underlying behavior analytics data does not exist. You must first enable UEBA in the settings; after that, you can create analytics rules using the UEBA templates to detect anomalies.

  • ✗

    Assign the Security Reader role to Sentinel

    Why it's wrong here

    Assigning the Security Reader role to Sentinel grants read-only permissions, allowing users to view incidents and workspace settings but not modify them. This role does not activate any feature, including UEBA; it only governs access control. To enable UEBA, your account needs write permissions on the Sentinel workspace, and you must specifically change the 'Entity behavior' setting—role assignment alone cannot turn on the feature.

About these practice questions

Courseiva writes every AZ-500 question from scratch — 617 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.