SC-200 Perform threat hunting Practice Question
A threat hunter wants to use Microsoft Sentinel's UEBA to identify anomalous behavior. Which data connector must be enabled to provide the necessary Microsoft Entra ID (now Microsoft Entra ID) sign-in logs for UEBA?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Entra ID
UEBA in Microsoft Sentinel requires sign-in logs to detect anomalous behavior. The Microsoft Entra ID connector (option C) provides these sign-in logs from Microsoft Entra ID/Entra ID. Option A (Office 365) provides Exchange, Teams, and SharePoint logs, but not sign-in logs. Option B (Microsoft Entra ID Audit) provides only audit logs, not sign-in events. Option D (Windows Security Events via AMA) provides security event logs from Windows machines, which do not contain cloud sign-in data. Therefore, the Microsoft Entra ID connector is the correct choice.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Office 365
Why it's wrong here
The Office 365 connector ingests unified audit log events such as SharePoint and Exchange activity, not Microsoft Entra ID sign-in records. UEBA requires those sign-in logs to baseline user behaviour. Office 365 is correct when the hunting requirement centres on productivity workload activity rather than identity anomalies.
- ✗
Microsoft Entra ID Audit
Why it's wrong here
The Microsoft Entra ID Audit connector ingests directory administrative activity, such as role and group changes, not interactive sign-in logs. UEBA requires sign-in telemetry to baseline authentication behaviour. Audit is correct when hunting privileged directory modifications rather than anomalous user sign-ins.
- ✓
Microsoft Entra ID
Why this is correct
The Microsoft Entra ID data connector ingests sign-in and audit logs into Microsoft Sentinel, supplying the identity events UEBA analyses for anomalous behaviour detection. Enabling it is required before UEBA can surface risky sign-in activity.
- ✗
Windows Security Events via AMA
Why it's wrong here
Windows Security Events via AMA collects host-based event logs from machines, not Microsoft Entra ID sign-in telemetry. UEBA needs cloud identity sign-in data to detect anomalous authentication. This connector is correct when hunting endpoint activity such as process creation or logon events on servers.
Go deeper
Related to this question
About these practice questions
This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.