SC-200 Manage a security operations environment Practice Question
You are a security operations analyst for a company that uses Microsoft Sentinel. You need to enable User and Entity Behavior Analytics (UEBA) to identify anomalous behavior. You have already enabled the UEBA setting in Microsoft Sentinel. What else must you do to ensure UEBA data is available for investigation?
⚠ Common exam trap
The trap here is assuming that simply toggling UEBA on is enough, when in fact you must also select and enable the relevant data sources for entity behavior.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure data sources to send logs to the Microsoft Sentinel workspace and enable entity behavior data sources in UEBA settings.
After enabling UEBA in Microsoft Sentinel, you must configure the data sources that provide entity behavior information. This includes connecting sources like Microsoft Entra ID sign-in logs and enabling them in the UEBA settings. Without this, UEBA tables remain empty and anomaly detection cannot function. The other options either confuse detection with data population or involve unrelated configurations.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create a custom analytics rule that runs on the BehaviorAnalytics table to generate incidents.
Why it's wrong here
While you can create analytics rules on the BehaviorAnalytics table, this is not required to enable UEBA data availability. UEBA data is populated automatically once data sources are configured; custom rules are for detection, not for enabling the data.
- ✗
Assign the Microsoft Sentinel Contributor role to the UEBA service account.
Why it's wrong here
UEBA does not use a separate service account; it uses the permissions of the user enabling it and the workspace's managed identity. Assigning a role to a service account is not a step for enabling UEBA data, and Contributor role is not required for data population.
- ✗
Enable the Microsoft Defender XDR connector to import UEBA data from Defender services.
Why it's wrong here
The Microsoft Defender XDR connector imports alerts and incidents, not UEBA data. UEBA data is generated within Microsoft Sentinel from connected logs. Enabling this connector does not provide the required entity behavior data sources for UEBA.
- ✓
Configure data sources to send logs to the Microsoft Sentinel workspace and enable entity behavior data sources in UEBA settings.
Why this is correct
UEBA requires data sources to be connected and entity behavior data sources enabled. After enabling UEBA, you must select which data sources provide entity behavior information, such as Microsoft Entra ID sign-in logs, to populate the UEBA tables and enable anomaly detection.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.