You are using Microsoft Sentinel UEBA to hunt for insider threats. Which entity type would you investigate to detect unusual access to sensitive data?
The user entity is the core anchor for UEBA in Microsoft Sentinel, enabling the engine to build a behavioral baseline and detect anomalies like unusual logon times, failed logins, or peers' rare access to sensitive resources. Insider threat hunting depends on correlating identity, access, and action attributes around a unique user, which is why user entity analysis correctly identifies abnormal access patterns. Without user-level behavioral analytics, insider threats that leverage legitimate credentials would remain undetected.
Why this answer
Microsoft Sentinel UEBA builds behavior profiles around entity types including User, Host, IP, and Application. To detect insider threats involving unusual access to sensitive data, the User entity is the right focus because UEBA tracks each user's normal data access patterns, peer group comparisons, and anomalies like accessing files or sites they normally do not. Investigating the User entity surfaces deviations such as mass downloads, access outside normal hours, or access to sensitive SharePoint sites.
Exam trap
SC-200 often tests entity-type selection by presenting IP, Device, and Application as plausible alternatives — candidates must recognize that insider data-access anomalies are modeled on the User entity, not infrastructure entities.
How to eliminate wrong answers
Option A is wrong because the IP entity is useful for detecting anomalous network origins or impossible travel, but it does not directly model a user's data access behavior or peer group. Option B is wrong because the Application entity focuses on application usage anomalies (e.g., unusual app access), not the user's access to sensitive data. Option C is wrong because the Device entity tracks device behavior and anomalies (e.g., unusual processes), but insider data access is best modeled at the user level where peer group and access patterns are analyzed.