AZ-500 Manage identity and access Practice Question
A security operations team uses Microsoft Sentinel. They want to enable User and Entity Behavior Analytics (UEBA) to detect anomalous user activities. Which configuration is required?
⚠ Common exam trap
Watch out — candidates often confuse enabling a feature with installing a connector or creating a rule, but UEBA is a toggle in Sentinel settings, not a data source or alert rule.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable UEBA in the Sentinel settings
UEBA in Microsoft Sentinel is a built-in feature that must be explicitly enabled in the Sentinel configuration settings under 'Entity behavior analytics'. It does not require a separate data connector or analytics rule template; once enabled, Sentinel automatically ingests and analyzes existing log data (e.g., Microsoft Entra ID sign-ins, Office 365 audit logs) to establish behavioral baselines and detect anomalies.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Enable UEBA in the Sentinel settings
Why this is correct
UEBA must be explicitly turned on in Microsoft Sentinel by navigating to Settings > Entity behavior and toggling the feature. It does not require any separate deployment or data source configuration because it operates on data already ingested through existing connectors, such as Microsoft Entra ID and Windows Security Events. The toggle immediately activates behavioral profiling for entities like users and hosts, so without this action, no UEBA-based alerts or insights will appear.
- ✗
Install the UEBA data connector
Why it's wrong here
There is no 'UEBA data connector' in Microsoft Sentinel. UEBA is not a data source that can be installed; it is a built-in analytics engine that consumes telemetry from connectors you have already configured, such as Microsoft Entra ID sign-in logs, Windows Security events, and Office 365 activity. Trying to install a nonexistent connector will not enable UEBA and will only waste time, as the actual requirement is flipping the feature switch in the workspace settings.
- ✗
Create an analytics rule with UEBA template
Why it's wrong here
Sentinel's analytics rule templates that reference UEBA behaviors, such as 'Anomalous Sign-In Behavior', depend on the entity behavior data that UEBA generates. If UEBA is not enabled first, those rules will either fail to run correctly or produce no results because the underlying behavior analytics data does not exist. You must first enable UEBA in the settings; after that, you can create analytics rules using the UEBA templates to detect anomalies.
- ✗
Assign the Security Reader role to Sentinel
Why it's wrong here
Assigning the Security Reader role to Sentinel grants read-only permissions, allowing users to view incidents and workspace settings but not modify them. This role does not activate any feature, including UEBA; it only governs access control. To enable UEBA, your account needs write permissions on the Sentinel workspace, and you must specifically change the 'Entity behavior' setting—role assignment alone cannot turn on the feature.
Go deeper
Related to this question
About these practice questions
Courseiva writes every AZ-500 question from scratch — 617 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.