Courseiva

SC-200 Manage a security operations environment Practice Question

Your organization uses Microsoft Sentinel and has enabled UEBA (User and Entity Behavior Analytics). You notice that the UEBA timeline is not populating for some users. You have verified that the data sources are connected and the UEBA feature is enabled. What could be the issue?

⚠ Common exam trap

Watch out — candidates often assume UEBA will work immediately after enabling it, overlooking the mandatory 14-day baseline requirement, and instead blame data source connectivity or user permissions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

There is insufficient data to build baselines for those users; UEBA needs at least 14 days of data.

UEBA requires a minimum of 14 days of historical data to establish behavioral baselines for each user. Without sufficient data, the timeline cannot detect anomalies or populate entries. Even if data sources are connected and UEBA is enabled, the feature will not generate timeline events until baselines are built.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    There is insufficient data to build baselines for those users; UEBA needs at least 14 days of data.

    Why this is correct

    Microsoft Sentinel UEBA uses proprietary machine learning to build behavioral baselines for entities such as users, and it requires at least 14 days of historical telemetry before it can produce analytical timelines. If a user is newly on-boarded or has only sporadic log activity, the available data does not meet that minimum threshold, so no anomaly or timeline appears. This is a documented prerequisite, not a configuration error or a connectivity problem.

  • ✗

    Users must opt in to UEBA tracking.

    Why it's wrong here

    UEBA in Microsoft Sentinel is a background analytics service that operates on telemetry the organization already sends to the workspace; it does not require individual users to consent or opt in. The administrator enables UEBA globally through the entity behavior settings, and processing occurs without any per-user agreement. Therefore, a missing timeline is never the result of a user declining to participate, because no such mechanism exists.

  • ✗

    UEBA only works with Microsoft Entra ID (now Microsoft Entra ID) audit logs.

    Why it's wrong here

    UEBA does not rely solely on Microsoft Entra ID (now Microsoft Entra ID) sign-in and audit logs; it ingests a heterogeneous set of sources including Windows Security events (such as 4624, 4625, and 4672), CommonSecurityLog flow from security appliances, and Azure Activity logs to populate different entity types (users, hosts, and applications). Restricting data sources to only Entra ID would actually degrade UEBA analytics, because host-based anomalies require Windows event telemetry. Thus the claim incorrectly narrows the source requirements.

  • ✗

    The data sources are not sending logs for those users.

    Why it's wrong here

    The scenario likely has all data sources correctly connected because the question states logs are flowing, but UEBA requires specific historical data over a 14-day window to create a per-user baseline. Simply receiving logs today is not enough; if the user was only synchronized or started generating events recently, there is no prior behavior to compare. The absence of a timeline is due to insufficient baseline data, not because connectors are broken or collection pipelines are silently dropping events.

About these practice questions

This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.