Courseiva

SC-200 Respond to security incidents Practice Question

You are investigating a potential insider threat incident in Microsoft Sentinel. A user account has been flagged for downloading a large number of files from SharePoint Online. You need to determine if the user's activity is anomalous compared to their normal behavior. Which Microsoft Sentinel feature should you use to analyze this?

⚠ Common exam trap

The trap here is assuming that any detection feature can perform behavioral analysis, when in fact UEBA is the dedicated capability for baselining and anomaly detection.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

User and Entity Behavior Analytics (UEBA)

UEBA in Microsoft Sentinel is specifically designed to analyze user and entity behavior, establishing baselines and detecting anomalies. For a user downloading an unusually large number of SharePoint files, UEBA can identify this deviation from normal activity, aiding in insider threat investigations. Other features like Fusion, threshold rules, or workbooks do not provide behavioral baselining and anomaly detection.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Workbooks with custom visualizations

    Why it's wrong here

    Workbooks provide visualization and reporting but do not perform behavioral analysis or anomaly detection. They can display data from logs, but without UEBA's machine learning, they cannot determine if the download volume is anomalous for the user. Thus, workbooks alone are insufficient for this investigation.

  • ✓

    User and Entity Behavior Analytics (UEBA)

    Why this is correct

    UEBA in Microsoft Sentinel uses machine learning to establish baselines of normal behavior for users and entities, then identifies anomalies. For a user downloading an unusually large number of files from SharePoint, UEBA can flag this as anomalous based on historical activity, helping you determine if it's an insider threat. This is the correct feature for behavioral analysis.

  • ✗

    Fusion incident detection

    Why it's wrong here

    Fusion incident detection correlates alerts from multiple sources to identify multi-stage attacks, but it does not analyze user behavior for anomalies. It focuses on attack patterns across products, not on individual user activity baselines. Therefore, it would not help determine if the SharePoint downloads are anomalous for this specific user.

  • ✗

    Microsoft Sentinel analytics rules with threshold-based detection

    Why it's wrong here

    Threshold-based analytics rules can trigger when a fixed number of files are downloaded, but they do not compare against the user's normal behavior. They are static and may generate false positives or miss subtle anomalies. UEBA is designed for behavioral baselining, making it more suitable for this scenario.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.