SC-200 Perform threat hunting Practice Question
You are using Microsoft Sentinel UEBA to hunt for insider threats. Which entity type would you investigate to detect unusual access to sensitive data?
⚠ Common exam trap
SC-200 often tests entity-type selection by presenting IP, Device, and Application as plausible alternatives — candidates must recognize that insider data-access anomalies are modeled on the User entity, not infrastructure entities.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
User
Microsoft Sentinel UEBA builds behavior profiles around entity types including User, Host, IP, and Application. To detect insider threats involving unusual access to sensitive data, the User entity is the right focus because UEBA tracks each user's normal data access patterns, peer group comparisons, and anomalies like accessing files or sites they normally do not. Investigating the User entity surfaces deviations such as mass downloads, access outside normal hours, or access to sensitive SharePoint sites.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
IP
Why it's wrong here
An IP address entity represents network-level telemetry such as source IP geolocation, Tor usage, or known malicious addresses. While anomalous IPs can indicate compromised infrastructure, they are often shared behind NAT or VPNs and cannot reliably identify the specific insider user's behavioral pattern. UEBA's insider threat hunting correlates identity-centric signals, so the IP entity alone lacks sufficient user context to surface access anomalies.
- ✗
Application
Why it's wrong here
Application entities in UEBA profile activity like sign-ins to Office 365, SharePoint, or custom apps, but they focus on application health and usage trends, not the user's intent or authorization state. Insider threat indicators such as abnormal after-hours permissions changes or mass downloads are only meaningful when attributed to a user entity across multiple applications. A suspicious application pattern without user context cannot distinguish between a legitimate admin and a malicious insider.
- ✗
Device
Why it's wrong here
Device entities track endpoint-level behaviors such as OS health, installed software, and process execution, which helps identify compromised hosts, not insider intent. An insider may act from their assigned, clean device using valid credentials, so device anomalies are not a reliable proxy for malicious access patterns. UEBA requires the user entity to link device events with identity and access history to detect privilege misuse.
- ✓
User
Why this is correct
The user entity is the core anchor for UEBA in Microsoft Sentinel, enabling the engine to build a behavioral baseline and detect anomalies like unusual logon times, failed logins, or peers' rare access to sensitive resources. Insider threat hunting depends on correlating identity, access, and action attributes around a unique user, which is why user entity analysis correctly identifies abnormal access patterns. Without user-level behavioral analytics, insider threats that leverage legitimate credentials would remain undetected.
Go deeper
Related to this question
About these practice questions
This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.