Courseiva

AZ-500 Practice Question: Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel

Which TWO of the following are valid data sources for Microsoft Sentinel's UEBA (User and Entity Behavior Analytics)? (Select two.)

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Microsoft Entra ID sign-in logs.

Microsoft Sentinel UEBA is designed to ingest identity-centric telemetry, and Microsoft Entra ID sign-in logs (option A) are a core data source because they provide the authentication events (user, application, IP, location, device, risk level) that UEBA uses to build behavioral baselines and detect anomalous sign-in activity. Microsoft Entra ID audit logs (option B) are also a valid UEBA source, since they record directory-level changes such as user, group, role, and application modifications that feed entity behavior profiling and help correlate administrative actions with other activity. Options C, D, and E are not among the documented UEBA data sources: Azure SQL Database audit logs, Azure Activity Logs, and Azure Firewall logs are resource/network telemetry that can be collected into Sentinel for analytics, but they are not identity behavior sources used by the UEBA engine.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Microsoft Entra ID sign-in logs.

    Why this is correct

    Microsoft Entra ID sign-in logs are a core UEBA data source in Microsoft Sentinel because UEBA profiles entities based on authentication behavior, such as successful/failed logons, anomalous locations, impossible travel, and device attributes. These logs feed the UEBA engine to establish baselines and detect risky sign-in patterns. Without them, UEBA would lack the primary signal for user identity and access activity.

  • ✓

    Microsoft Entra ID audit logs.

    Why this is correct

    Microsoft Entra ID audit logs are also a required data source for UEBA in Microsoft Sentinel, as they provide a chronological record of user and admin activities within Entra ID—like role changes, group membership updates, and application consent grants. UEBA ingests these logs to enrich user profiles with activity patterns beyond authentication, enabling detection of privilege escalation or unusual directory modifications. The combination of sign-in and audit logs gives UEBA both the 'who' and the 'what' of user behavior.

  • ✗

    Azure SQL Database audit logs.

    Why it's wrong here

    Azure SQL Database audit logs are not a valid UEBA data source in Microsoft Sentinel because they capture database-level events such as queries, schema changes, and data access attempts, not user identity or behavioral patterns. UEBA in Sentinel specifically ingests Microsoft Entra ID and Microsoft Entra ID data sources, not PaaS database telemetry. While SQL audit logs can be connected to Sentinel for security monitoring, they do not feed the UEBA analytics engine.

  • ✗

    Azure Activity Logs.

    Why it's wrong here

    Azure Activity Logs are not a data source for UEBA because they record control-plane operations on Azure resources—like virtual machine creation, network configuration, and resource deletions—not user authentication or directory actions. UEBA focuses on entity behavior (users, hosts, IPs) using identity and activity signals from Entra ID, whereas Activity Logs reflect Azure resource management events. Therefore, they are excluded from UEBA data connectors.

  • ✗

    Azure Firewall logs.

    Why it's wrong here

    Azure Firewall logs are not used by UEBA because they contain network flow data—source/destination IPs, ports, protocols, and allowed/denied traffic—which does not directly represent user identity or behavioral patterns. UEBA in Sentinel relies on identity-centric data sources such as Entra ID sign-in and audit logs to model user behavior. Firewall logs may be used for network detection rules but are not part of the UEBA data source set.

About these practice questions

One of 617 original AZ-500 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.