SC-200 Manage a security operations environment Practice Question
Your organization has Microsoft Sentinel with UEBA enabled. An incident is generated for a user with high risk score. You need to identify if the user's recent behavior deviates from their baseline. Which Sentinel feature should you use?
⚠ Common exam trap
Watch out — candidates often confuse the BehaviorAnalytics table (option A) as the primary tool for deviation analysis, overlooking that the UEBA timeline is the purpose-built, no-code interface for visualizing baseline deviations directly on the entity page.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The UEBA timeline in the entity page.
The UEBA timeline in the entity page is the correct feature because it provides a chronological view of a user's activities, including deviations from their established behavioral baseline. When UEBA is enabled, Sentinel profiles normal behavior for each user and flags anomalies; the timeline directly visualizes these deviations, such as unusual login times, locations, or resource access, which aligns with the need to identify if recent behavior deviates from the baseline.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A custom hunting query using the BehaviorAnalytics table.
Why it's wrong here
The BehaviorAnalytics table does surface UEBA-enriched records, so a custom KQL hunting query could uncover the same underlying anomalies, but that approach requires manually authoring a query and interpreting results. Sentinel's built-in UEBA experience is the entity page timeline, which automatically aggregates deviations and baseline behavior without custom code. Because the question asks for the built-in feature, this is a possible workaround, not the correct answer.
- ✗
The user's Microsoft Entra ID sign-in logs.
Why it's wrong here
Microsoft Entra ID sign-in logs are raw authentication events that capture who signed in, when, from where, and with what client, but they do not contain UEBA's behavioral analytics fields such as baseline deviations or anomaly scores. UEBA processing is applied at the entity level in Sentinel, and its results are not back-filled into the sign-in log schema. Therefore, viewing sign-in logs alone will not show the enriched timeline of behavioral anomalies.
- ✓
The UEBA timeline in the entity page.
Why this is correct
The UEBA timeline is a dedicated tab on the Sentinel entity page that presents a chronological view of a user's or device's activities, highlighting deviations from established behavioral baselines and flagging risky actions with anomaly scores. Because UEBA is natively integrated into entity pages, this is the built-in feature designed to show baseline deviations over time. It directly addresses the requirement to see anomalies relative to normal behavior.
- ✗
The incident investigation graph.
Why it's wrong here
The incident investigation graph is a visual map that links related entities, alerts, and evidence around a specific incident, helping analysts trace attack paths and relationships. It is not a chronological timeline of a single entity's baseline behavior, and it does not display UEBA deviation history as a sequential feed. Thus, although useful for investigation, it serves a different purpose and does not satisfy the need for a baseline-comparison timeline.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.