SC-200 Respond to security incidents Practice Question
You are responding to an incident where a user's credentials were stolen via a phishing email. The attacker used the credentials to access Microsoft Entra ID and then tried to perform privileged role escalation. Which Microsoft Sentinel solution should you use to detect this type of attack?
⚠ Common exam trap
It's easy for candidates to confuse UEBA with threat intelligence or network logs, mistakenly thinking that detecting credential theft requires matching known malicious IPs or analyzing raw network traffic, when in fact the attack relies on behavioral anomalies that only UEBA can identify.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
UEBA (User and Entity Behavior Analytics)
UEBA (User and Entity Behavior Analytics) is the correct solution because it uses machine learning to establish baseline behavioral patterns for users and entities, then detects anomalies such as a user logging in from an unusual location and immediately attempting privileged role escalation. This directly identifies the credential theft and privilege escalation chain described in the incident, whereas other options focus on network traffic, generic syslog ingestion, or threat intelligence matching, which would not catch the behavioral anomaly of a stolen credential being used for role escalation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Network Security Group flow logs
Why it's wrong here
Network Security Group (NSG) flow logs capture network-layer traffic metadata, including source and destination IP addresses, ports, and protocols, but they contain no identity context such as user login events, authentication results, or role assignment activity. This makes them unable to reveal behavioral anomalies like privilege escalation or account misuse that would indicate compromised credentials.
- ✗
Syslog data connector
Why it's wrong here
Syslog data connectors ingest raw event messages from firewalls, servers, and other network devices into Microsoft Sentinel, usually in Common Event Format. Although these logs might include authentication entries, the connector itself provides no statistical baseline or machine learning-based anomaly detection, so it cannot identify deviations in user behavior that signal a compromised account.
- ✗
Threat intelligence connectors
Why it's wrong here
Threat intelligence connectors import known indicators of compromise, such as malicious IP addresses, domains, URLs, and file hashes, from sources like Microsoft Threat Intelligence or third-party feeds. They match telemetry against these static signatures but lack any capability to profile normal user or entity behavior, so they cannot detect an attacker using valid credentials for unusual role assignments or privilege escalation attempts.
- ✓
UEBA (User and Entity Behavior Analytics)
Why this is correct
UEBA (User and Entity Behavior Analytics) in Microsoft Sentinel builds individual baselines from historical sign-in patterns, role assignments, and user activities, then applies machine learning to detect anomalies such as unusual privilege escalation or impossible travel. Because it focuses on behavioral deviations rather than static rules, UEBA is specifically designed to surface the kind of account misuse associated with compromised credentials.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.