SC-200 Manage a security operations environment Practice Question
Which TWO of the following are required to enable Microsoft Sentinel UEBA (User and Entity Behavior Analytics)?
⚠ Common exam trap
It's easy for candidates to assume UEBA requires a separate license or integration with a specific security product like Defender for Cloud Apps, when in fact it is a built-in feature of Sentinel that only needs to be enabled and fed with appropriate log sources.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable UEBA in the Microsoft Sentinel workspace settings.
UEBA must be explicitly enabled in the Microsoft Sentinel workspace settings under the 'Entity behavior analytics' blade. This activation allows Sentinel to start profiling user and entity behaviors using built-in machine learning models. Without this toggle, UEBA remains disabled regardless of other configurations.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Enable UEBA in the Microsoft Sentinel workspace settings.
Why this is correct
UEBA is disabled by default in Microsoft Sentinel; you must explicitly turn it on via the workspace settings under Entity behavior. This setting activates the machine learning-based analytics that profile entities and surface anomalous activity. Without toggling this on, UEBA features remain dormant even if other data sources are connected.
- ✗
Integrate Microsoft Defender for Cloud Apps.
Why it's wrong here
Integrating Microsoft Defender for Cloud Apps is an optional enrichment, not a prerequisite, because UEBA can operate using data already in the Log Analytics workspace, such as Microsoft Entra ID and Windows Security events. It adds cloud app activity and risk signals for deeper investigations, but the core UEBA engine does not depend on it for activation. Therefore, while useful, it is not one of the required components.
- ✗
Purchase a separate UEBA license.
Why it's wrong here
UEBA does not have a standalone license in Microsoft Sentinel; its functionality is included in the standard Sentinel pricing, whether pay-as-you-go or through capacity reservations. Enabling the UEBA setting in the workspace incurs no separate per-user fee or licensing SKU. The only costs are those associated with data ingestion and retention in Log Analytics, so purchasing an extra license is unnecessary.
- ✗
Configure Azure Key Vault to store UEBA data.
Why it's wrong here
UEBA data is persisted in the Log Analytics workspace that is tied to the Sentinel instance, not in Azure Key Vault. Key Vault is a managed service for safeguarding cryptographic keys and secrets, and UEBA has no integration that writes behavioral profiles there. Configuring Key Vault for this purpose would be both unnecessary and architecturally wrong, as it does not support the required schema or querying capabilities.
- ✓
Ingest Microsoft Entra ID sign-in logs and audit logs.
Why this is correct
Microsoft Entra ID sign-in and audit logs are required because UEBA builds behavioral baselines from these identity-centric events. Sign-in logs record authentication attempts, locations, and device details, while audit logs track user and admin actions in the directory. Without both streams, Sentinel's UEBA cannot correlate user activity or detect anomalies such as impossible travel incidents, making these logs a mandatory prerequisite for meaningful entity behavior analytics.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.