SC-200 Manage a security operations environment Practice Question
Your organization uses Microsoft Sentinel and has enabled user and entity behavior analytics (UEBA). You need to identify which two data sources are required to enable UEBA in Microsoft Sentinel. (Choose two.)
⚠ Common exam trap
The trap here is assuming that all Microsoft 365 or Defender logs are required; in fact, only Microsoft Entra ID sign-in and audit logs are prerequisites for UEBA.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Entra ID (Azure AD) audit logs
To enable UEBA in Microsoft Sentinel, you must ingest Microsoft Entra ID sign-in logs and Microsoft Entra ID audit logs. These provide the necessary user authentication and activity data for behavioral baselining. Other logs can be added later to enrich UEBA but are not mandatory for the initial enablement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Azure Activity logs
Why it's wrong here
Azure Activity logs record subscription-level operations and can be useful for UEBA, but they are not required to enable UEBA. The core requirement is Microsoft Entra ID logs. Azure Activity logs are optional and typically used for monitoring Azure resource changes.
- ✓
Microsoft Entra ID (Azure AD) audit logs
Why this is correct
Microsoft Entra ID audit logs are required for UEBA because they track administrative and user activities such as group changes, role assignments, and application consent. These logs help UEBA establish normal behavior and detect suspicious changes. Together with sign-in logs, they form the minimum data set for UEBA.
- ✗
Microsoft Defender for Identity logs
Why it's wrong here
While Defender for Identity logs can enrich UEBA, they are not a mandatory data source for enabling UEBA. UEBA can function with other sources, and Defender for Identity is optional. The required sources are typically Microsoft Entra ID sign-in logs and Microsoft Entra ID audit logs.
- ✗
Microsoft 365 audit logs
Why it's wrong here
Microsoft 365 audit logs can be ingested into Microsoft Sentinel and used by UEBA, but they are not a prerequisite for enabling UEBA. UEBA can be enabled with just Microsoft Entra ID logs. Other logs enhance the analysis but are not required for initial setup.
- ✓
Microsoft Entra ID (Azure AD) sign-in logs
Why this is correct
Microsoft Entra ID sign-in logs are a core data source for UEBA. They provide information about user authentication activities, which UEBA uses to build behavioral baselines and detect anomalies such as impossible travel or unfamiliar sign-in properties. Without sign-in logs, UEBA cannot effectively analyze user access patterns.
Go deeper
Related to this question
About these practice questions
This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.