- A
Create an Azure Machine Learning workspace for anomaly detection.
Why wrong: UEBA uses built-in ML models, not an external workspace.
- B
Enable UEBA in the Sentinel Settings blade and select relevant data sources.
This is the prerequisite for UEBA to baseline and detect anomalies.
- C
Assign Microsoft 365 E5 licenses to all users.
Why wrong: UEBA is a Sentinel feature; E5 is not required.
- D
Deploy a custom data connector for HR systems.
Why wrong: UEBA works with standard data sources; custom connectors are not required.
Quick Answer
The correct first step is to enable UEBA in the Sentinel Settings blade and select relevant data sources. This is required because Microsoft Sentinel UEBA must be explicitly turned on under the 'Entity behavior analytics' section before it can baseline normal user activities; without this activation, the feature cannot ingest logs or generate alerts for deviations. On the SC-200 exam, this question tests your understanding that UEBA is not enabled by default—a common trap is assuming it activates automatically when you connect data sources like Azure AD or Office 365. Instead, you must manually toggle it on and then choose the specific sources (e.g., sign-in logs, Windows Security Events) for behavioral profiling. A useful memory tip: think "Toggle first, then source"—you cannot analyze behavior until you flip the UEBA switch.
SC-200 Manage a security operations environment Practice Question
This SC-200 practice question tests your understanding of manage a security operations environment. The scenario asks you to isolate a root cause — eliminate options that address a different problem before choosing. After answering, compare your reasoning against the explanation and wrong-answer breakdown below. Once you have made your selection, read the full explanation to reinforce the concept and understand why each distractor is designed to mislead on exam day.
Your security team uses Microsoft Sentinel UEBA to detect anomalous user behavior. You need to configure UEBA to baseline user activities and generate alerts for deviations. What must you do first?
Clue words in this question
Noticing these words before you look at the options changes how you read each choice.
Clue:
"first"Why it matters: Order matters here. You are being tested on which action comes before the others — not which action is generally useful.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
Enable UEBA in the Sentinel Settings blade and select relevant data sources.
Option B is correct because Microsoft Sentinel UEBA requires explicit enablement in the Sentinel Settings blade under the 'Entity behavior analytics' section. Once enabled, you must select the relevant data sources (e.g., Azure Active Directory sign-in logs, Office 365 audit logs, Windows Security Events) so that Sentinel can baseline normal user behavior patterns and generate alerts for anomalous deviations. Without this initial configuration, UEBA cannot process any data or produce behavioral analytics.
Key principle: Answer the scenario, not the keyword: identify the specific constraint before choosing the most familiar-sounding option.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create an Azure Machine Learning workspace for anomaly detection.
Why it's wrong here
UEBA uses built-in ML models, not an external workspace.
- ✓
Enable UEBA in the Sentinel Settings blade and select relevant data sources.
Why this is correct
This is the prerequisite for UEBA to baseline and detect anomalies.
Clue confirmation
The clue word "first" in the question point toward this answer.
Related concept
Read the scenario before looking for a memorised answer.
- ✗
Assign Microsoft 365 E5 licenses to all users.
Why it's wrong here
UEBA is a Sentinel feature; E5 is not required.
- ✗
Deploy a custom data connector for HR systems.
Why it's wrong here
UEBA works with standard data sources; custom connectors are not required.
Common exam traps
Common exam trap: answer the scenario, not the keyword
The trap here is that candidates often assume UEBA is automatically enabled or that it requires external ML services (like Azure Machine Learning) or premium licenses (like M365 E5), when in fact the first step is simply toggling the feature on and selecting data sources within Sentinel's own settings.
Detailed technical explanation
How to think about this question
Under the hood, Sentinel UEBA leverages the 'EntityBehaviorAnalytics' table in Log Analytics, which stores aggregated behavioral profiles (e.g., typical login times, locations, and resource access patterns) computed hourly. The baselining process uses a sliding window of 14 days of historical data to establish a 'normal' range, and deviations beyond a statistically calculated threshold (e.g., 3 standard deviations) trigger an anomaly alert. A real-world scenario: if an administrator enables UEBA but forgets to select 'Azure Active Directory sign-in logs' as a data source, the system cannot baseline sign-in behavior, and lateral movement anomalies from compromised credentials will go undetected.
KKey Concepts to Remember
- Read the scenario before looking for a memorised answer.
- Find the constraint that changes the correct option.
- Eliminate answers that are true in general but not in this case.
TExam Day Tips
- Watch for words such as best, first, most likely and least administrative effort.
- Review why wrong options are wrong, not only why the correct option is correct.
Key takeaway
Answer the scenario, not the keyword: identify the specific constraint before choosing the most familiar-sounding option.
Real-world example
How this comes up in practice
A cloud solutions architect for a retail company is evaluating services for a new workload. The correct answer here reflects best practice for the specific scenario described — not a general cloud recommendation. Answer the scenario, not the keyword: identify the specific constraint before choosing the most familiar-sounding option. Cloud exam questions reward reading the constraint carefully: the same technology can be right or wrong depending on the use case.
What to study next
Got this wrong? Here's your next step.
Identify which exam domain this question belongs to, review the core concept, then practise similar questions from the same domain.
- →
Manage a security operations environment — study guide chapter
Learn the concepts, then practise the questions
- →
Manage a security operations environment practice questions
Targeted practice on this topic area only
- →
All SC-200 questions
1,639 questions across all exam domains
- →
Microsoft Security Operations Analyst SC-200 study guide
Full concept coverage aligned to exam objectives
- →
SC-200 practice test guide
How to use practice tests most effectively before exam day
Related practice questions
Related SC-200 practice-question pages
Use these pages to review the topic behind this question. This is how one missed question becomes focused revision.
Manage a security operations environment practice questions
Practise SC-200 questions linked to Manage a security operations environment.
Respond to security incidents practice questions
Practise SC-200 questions linked to Respond to security incidents.
Perform threat hunting practice questions
Practise SC-200 questions linked to Perform threat hunting.
Mitigate threats using Microsoft Defender XDR practice questions
Practise SC-200 questions linked to Mitigate threats using Microsoft Defender XDR.
Mitigate threats using Microsoft Defender for Cloud practice questions
Practise SC-200 questions linked to Mitigate threats using Microsoft Defender for Cloud.
Mitigate threats using Microsoft Sentinel practice questions
Practise SC-200 questions linked to Mitigate threats using Microsoft Sentinel.
SC-200 fundamentals practice questions
Practise SC-200 questions linked to SC-200 fundamentals.
SC-200 scenario practice questions
Practise SC-200 questions linked to SC-200 scenario.
SC-200 troubleshooting practice questions
Practise SC-200 questions linked to SC-200 troubleshooting.
Practice this exam
Start a free SC-200 practice session
Short sessions build daily habit. Longer sessions build exam-day stamina. Try a timed session to simulate real conditions.
FAQ
Questions learners often ask
What does this SC-200 question test?
Manage a security operations environment — This question tests Manage a security operations environment — Read the scenario before looking for a memorised answer..
What is the correct answer to this question?
The correct answer is: Enable UEBA in the Sentinel Settings blade and select relevant data sources. — Option B is correct because Microsoft Sentinel UEBA requires explicit enablement in the Sentinel Settings blade under the 'Entity behavior analytics' section. Once enabled, you must select the relevant data sources (e.g., Azure Active Directory sign-in logs, Office 365 audit logs, Windows Security Events) so that Sentinel can baseline normal user behavior patterns and generate alerts for anomalous deviations. Without this initial configuration, UEBA cannot process any data or produce behavioral analytics.
What should I do if I get this SC-200 question wrong?
Identify which exam domain this question belongs to, review the core concept, then practise similar questions from the same domain.
Are there clue words in this question I should notice?
Yes — watch for: "first". Order matters here. You are being tested on which action comes before the others — not which action is generally useful.
What is the key concept behind this question?
Read the scenario before looking for a memorised answer.
About these practice questions
Courseiva creates original exam-style practice questions with explanations and wrong-answer analysis. It does not publish real exam questions, exam dumps, or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
2 more ways this is tested on SC-200
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Your organization has deployed Microsoft Sentinel. You need to ensure that user and entity behavior analytics (UEBA) is enabled for all data sources. What is the minimum role required to enable UEBA in Microsoft Sentinel?
easy- ✓ A.Microsoft Sentinel Contributor
- B.Global Administrator
- C.Security Reader
- D.Log Analytics Contributor
Why A: Option C is correct because to enable UEBA, you need at least 'Microsoft Sentinel Contributor' role on the workspace. Option A is wrong because Global Admin is not required. Option B is wrong because Security Reader is read-only. Option D is wrong because Log Analytics Contributor does not include Sentinel-specific permissions.
Variation 2. Your SOC team uses Microsoft Sentinel's UEBA to detect insider threats. You want to ensure that UEBA can correlate activities across multiple data sources. Which data source must be enabled for UEBA to function properly?
hard- A.Azure Activity logs
- B.Office 365 audit logs
- C.Windows Security Events
- ✓ D.Microsoft Entra ID audit logs
Why D: Microsoft Entra ID (formerly Azure AD) audit logs provide identity context that is essential for UEBA to correlate user activities. Option B is wrong because Azure Activity logs provide resource-level operations. Option C is wrong because Windows Security Events alone lack identity correlation. Option D is wrong because Office 365 audit logs are useful but not the core requirement.
Last reviewed: Jun 25, 2026
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.
Question Discussion
Share a tip, memory trick, or ask about the reasoning behind this question. Do not post real exam questions, leaked content, braindumps, or copyrighted exam material. Comments are moderated and may be removed without notice.
Sign in to join the discussion.