Courseiva

SC-200 Manage a security operations environment Practice Question

Your organization uses Microsoft Sentinel and has enabled user and entity behavior analytics (UEBA). You need to identify which two data sources are required to enable UEBA in Microsoft Sentinel. (Choose two.)

⚠ Common exam trap

The trap here is assuming that all Microsoft 365 or Defender logs are required; in fact, only Microsoft Entra ID sign-in and audit logs are prerequisites for UEBA.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Microsoft Entra ID (Azure AD) audit logs

To enable UEBA in Microsoft Sentinel, you must ingest Microsoft Entra ID sign-in logs and Microsoft Entra ID audit logs. These provide the necessary user authentication and activity data for behavioral baselining. Other logs can be added later to enrich UEBA but are not mandatory for the initial enablement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Azure Activity logs

    Why it's wrong here

    Azure Activity logs record subscription-level operations and can be useful for UEBA, but they are not required to enable UEBA. The core requirement is Microsoft Entra ID logs. Azure Activity logs are optional and typically used for monitoring Azure resource changes.

  • ✓

    Microsoft Entra ID (Azure AD) audit logs

    Why this is correct

    Microsoft Entra ID audit logs are required for UEBA because they track administrative and user activities such as group changes, role assignments, and application consent. These logs help UEBA establish normal behavior and detect suspicious changes. Together with sign-in logs, they form the minimum data set for UEBA.

  • ✗

    Microsoft Defender for Identity logs

    Why it's wrong here

    While Defender for Identity logs can enrich UEBA, they are not a mandatory data source for enabling UEBA. UEBA can function with other sources, and Defender for Identity is optional. The required sources are typically Microsoft Entra ID sign-in logs and Microsoft Entra ID audit logs.

  • ✗

    Microsoft 365 audit logs

    Why it's wrong here

    Microsoft 365 audit logs can be ingested into Microsoft Sentinel and used by UEBA, but they are not a prerequisite for enabling UEBA. UEBA can be enabled with just Microsoft Entra ID logs. Other logs enhance the analysis but are not required for initial setup.

  • ✓

    Microsoft Entra ID (Azure AD) sign-in logs

    Why this is correct

    Microsoft Entra ID sign-in logs are a core data source for UEBA. They provide information about user authentication activities, which UEBA uses to build behavioral baselines and detect anomalies such as impossible travel or unfamiliar sign-in properties. Without sign-in logs, UEBA cannot effectively analyze user access patterns.

About these practice questions

This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.