AZ-500 Practice Question: Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel
Your organization uses Microsoft Sentinel and has enabled User and Entity Behavior Analytics (UEBA). You need to investigate a possible insider threat where a user is accessing sensitive data from unusual locations. Which Sentinel feature should you use to visualize the user's activities and related entities?
⚠ Common exam trap
It's easy for candidates to confuse the proactive, query-based nature of Hunting queries with the reactive, visual investigation capabilities of UEBA entity pages, leading them to select Option A when they need to investigate a specific user's behavior.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
UEBA investigation insights and entity pages
UEBA in Microsoft Sentinel provides investigation insights and entity pages that aggregate user activities, related entities, and behavioral anomalies into a visual timeline. This allows you to see a user's access patterns from unusual locations and correlate them with other entities like devices or IP addresses, making it the correct feature for investigating insider threats.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Hunting queries
Why it's wrong here
Hunting queries are proactive, KQL-based searches that look for suspicious activity across historical and real-time logs, but they are not structured around a single entity's timeline or relationships. They return a set of matching events or raw records, leaving the investigator to correlate and pivot manually. UEBA entity pages, in contrast, aggregate an entity's full activity, peer, and risk insights into a curated view, so hunting queries don't satisfy the entity-focused visualization requirement.
- ✓
UEBA investigation insights and entity pages
Why this is correct
Microsoft Sentinel's UEBA builds entity pages that consolidate a user, device, or other entity's activity into a single pane, including a timeline, related entities, and behavioral analytics. These pages surface investigation insights like anomalous logon patterns, impossible travel, and peer-group deviations, which are automatically generated via machine learning baselines. This gives analysts an entity-centric, visual starting point for investigation, making it the exact feature that matches the question's requirement for timeline and related-entity visualization.
- ✗
Analytics rules
Why it's wrong here
Analytics rules are detection logic (typically KQL-based) that trigger alerts or incidents when specific patterns, thresholds, or anomalies are matched in ingested data. Their purpose is to fire alerts, not to present an entity's history or connections visually. Even though an alert may link to an incident and later to entity pages, the analytics rule itself is just the detection mechanism, not the entity-focused investigation or visualization tool described in the question.
- ✗
Workbooks
Why it's wrong here
Workbooks are interactive Azure Monitor-based dashboards that allow data visualization across multiple sources and workspaces, often used for high-level security metrics and reporting. They are generally scoped to an organization, subscription, or scenario rather than to a single entity's investigation timeline. While you could create a custom workbook to show entity-related data, it doesn't provide the automatic, built-in entity-page experience with UEBA investigation insights, so it is not the correct answer for entity-centric visualization.
Go deeper
Related to this question
About these practice questions
One of 617 original AZ-500 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.