AZ-500 Practice Question: Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel
Which TWO are capabilities of Microsoft Sentinel UEBA? (Choose two.)
⚠ Common exam trap
Candidates often confuse UEBA's behavioral alerting with automated incident creation or response, assuming that any anomaly detection must automatically trigger an incident or action, when in fact UEBA focuses on providing investigative context and anomaly scoring.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Entity pages with timelines and related events
Option B is correct because Microsoft Sentinel UEBA provides entity pages that show a timeline of activities and related events for entities such as users, hosts, and IP addresses, helping analysts investigate anomalous behavior in context. Option D is correct because UEBA includes peer group analysis, which baselines an entity's behavior against similar peers to surface deviations that may indicate compromise or insider threat. Option A is not a UEBA capability per se; threat intelligence integration is a separate Sentinel feature (threat intelligence connectors and analytics rules), not part of UEBA's behavioral analytics. Option C is incorrect because UEBA does not automatically create incidents for every detected anomaly; anomalies are surfaced as insights/entities and can be used by analytics rules to generate incidents selectively. Option E is incorrect because automated response actions such as blocking IPs are handled by Sentinel automation rules and playbooks (Logic Apps), not by the UEBA feature itself.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Integration with external threat intelligence feeds
Why it's wrong here
UEBA is not a threat intelligence ingestion service; it analyzes user and entity behavior against baseline patterns. External threat intelligence feeds are consumed via threat intelligence data connectors and used in analytics rules or watchlists, not by the UEBA engine. Including this as a UEBA capability confuses data enrichment with behavioral anomaly detection.
- ✓
Entity pages with timelines and related events
Why this is correct
Entity pages in Microsoft Sentinel are a UEBA feature that aggregates an entity's activity into a timeline, showing behavior over time, related alerts, and anomalies. This allows analysts to quickly assess an entity's risk and contextualize investigations. UEBA specifically contributes anomaly-prone behavior insights and peer-group comparisons to these pages.
- ✗
Automatic incident creation for all detected anomalies
Why it's wrong here
UEBA's anomaly detection produces alerts or observations, but incident creation is controlled by analytics rules that evaluate the anomaly results, often with thresholds or aggregations. Automatically creating incidents for every anomaly would generate noise; so analytics rules and automation rule the response. Therefore this is not a capability of UEBA alone.
- ✓
Peer group analysis to detect anomalies
Why this is correct
UEBA establishes behavioral baselines by grouping similar users or entities (peer groups) based on attributes like role, department, or location, then flags deviations from peer norms. This is a core component of the UEBA machine learning models, enabling detection of insider threats and compromised accounts without hard-coded thresholds.
- ✗
Automated response actions like blocking IPs
Why it's wrong here
Automated response and remediation, such as blocking an IP or disabling an account, is not performed directly by UEBA. Sentinel's automation rules and playbooks (via Logic Apps) orchestrate those responses after an incident or alert is created. UEBA's role is limited to detection and enrichment, not enforcement.
Go deeper
Related to this question
About these practice questions
This AZ-500 question is part of Courseiva's 617-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.