easyMultiple ChoiceObjective-mapped
SC-100 Practice Question: Designing a security operations strategy using…
A company is designing a security operations strategy using Microsoft Sentinel. They want to prioritize triage of incidents that involve critical assets. The SOC manager suggests using the entity behavior analytics feature. Which capability of entity behavior analytics helps achieve this goal?
⚠ Common exam trap
A common mix-up: candidates confuse entity behavior analytics (UEBA) with Fusion or threat intelligence correlation, assuming any 'intelligent' feature must involve combining alerts or external threat data, rather than recognizing that UEBA is specifically about profiling internal entity behavior and scoring anomalies.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
It profiles entities and assigns an anomaly score based on deviations from baseline behaviors.
Entity behavior analytics (UEBA) in Microsoft Sentinel profiles entities such as users, hosts, or applications by establishing baseline behaviors over time. It then assigns an anomaly score to deviations from that baseline, enabling SOC analysts to prioritize incidents involving critical assets based on unusual activity rather than static rules. This directly supports the goal of triaging incidents by highlighting anomalous behavior on high-value targets.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
It combines multiple alerts into a single incident using Fusion.
Why it's wrong here
Fusion is a correlation engine in Microsoft Sentinel that ingests alerts from multiple security products and merges them into a single incident to reduce alert fatigue and simplify triage. It operates based on predefined or ML-based correlation rules, not on per-entity behavioral baselines. UEBA, by contrast, does not combine alerts; it profiles individual entities and scores how far their current activity diverges from their own historical patterns, making Fusion a fundamentally different detection mechanism.
- ✗
It uses threat intelligence to correlate with known bad actors.
Why it's wrong here
This option describes threat intelligence matching, where signals are compared against a catalogue of known indicators of compromise (IOCs) such as malicious IPs, domains, or hashes. UEBA does not rely on a list of known bad actors; instead, it learns the normal behavior of each entity and flags deviations, which enables it to detect novel or zero-day threats that have no intelligence signature. The core distinction is that UEBA is behavioral and baselined, whereas threat intelligence correlation is reactive and based on pre-existing knowledge.
- ✓
It profiles entities and assigns an anomaly score based on deviations from baseline behaviors.
Why this is correct
UEBA in Microsoft Sentinel profiles entities such as users, devices, and applications by establishing a baseline of their typical activities—like login times, geo-locations, accessed resources, and peer-group interactions. It then assigns an anomaly score to each deviation from that baseline, with high scores indicating potentially malicious or risky behavior. This method detects threats that may be unrecognized by signature-based tools because it focuses on behavioral change rather than known attack patterns, enabling identification of compromised entities or insider threats.
- ✗
It automatically groups incidents by severity and asset criticality.
Why it's wrong here
Grouping incidents by severity and asset criticality is a common incident-management and prioritization capability in SOC tooling, helping analysts focus on the most impactful events. This process is an organizational and triage feature, not an analytical engine for behavior. UEBA, on the other hand, is fundamentally about generating behavioral baselines, computing anomaly scores, and identifying risky entities—it does not classify incidents into buckets based on severity or asset value.
Go deeper
Related to this question
About these practice questions
One of 208 original SC-100 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.