Courseiva
Perform threat hunting →easyMultiple Choice

SC-200 Perform threat hunting Practice Question

A threat hunter wants to use Microsoft Sentinel's UEBA to identify anomalous behavior. Which data connector must be enabled to provide the necessary Microsoft Entra ID (now Microsoft Entra ID) sign-in logs for UEBA?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Microsoft Entra ID

UEBA in Microsoft Sentinel requires sign-in logs to detect anomalous behavior. The Microsoft Entra ID connector (option C) provides these sign-in logs from Microsoft Entra ID/Entra ID. Option A (Office 365) provides Exchange, Teams, and SharePoint logs, but not sign-in logs. Option B (Microsoft Entra ID Audit) provides only audit logs, not sign-in events. Option D (Windows Security Events via AMA) provides security event logs from Windows machines, which do not contain cloud sign-in data. Therefore, the Microsoft Entra ID connector is the correct choice.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Office 365

    Why it's wrong here

    The Office 365 connector ingests unified audit log events such as SharePoint and Exchange activity, not Microsoft Entra ID sign-in records. UEBA requires those sign-in logs to baseline user behaviour. Office 365 is correct when the hunting requirement centres on productivity workload activity rather than identity anomalies.

  • ✗

    Microsoft Entra ID Audit

    Why it's wrong here

    The Microsoft Entra ID Audit connector ingests directory administrative activity, such as role and group changes, not interactive sign-in logs. UEBA requires sign-in telemetry to baseline authentication behaviour. Audit is correct when hunting privileged directory modifications rather than anomalous user sign-ins.

  • ✓

    Microsoft Entra ID

    Why this is correct

    The Microsoft Entra ID data connector ingests sign-in and audit logs into Microsoft Sentinel, supplying the identity events UEBA analyses for anomalous behaviour detection. Enabling it is required before UEBA can surface risky sign-in activity.

  • ✗

    Windows Security Events via AMA

    Why it's wrong here

    Windows Security Events via AMA collects host-based event logs from machines, not Microsoft Entra ID sign-in telemetry. UEBA needs cloud identity sign-in data to detect anomalous authentication. This connector is correct when hunting endpoint activity such as process creation or logon events on servers.

About these practice questions

This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.