SC-200 Respond to security incidents Practice Question
Your organization uses Microsoft Sentinel with the UEBA (User and Entity Behavior Analytics) feature enabled. A security analyst notices that a user account has been flagged with an anomaly indicating a possible compromised credential. Which entity type in Microsoft Sentinel's UEBA is most relevant for this alert?
⚠ Common exam trap
The SC-200 exam often tests the distinction between entity types in UEBA, and the trap here is that candidates may confuse the IP address entity (which is associated with network-level anomalies) with the user account entity, failing to recognize that credential compromise is fundamentally a user identity anomaly.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
User account
The UEBA anomaly alert for a possible compromised credential is specifically tied to the User account entity because UEBA profiles user behavior over time and detects deviations from established baselines, such as unusual logon times, locations, or impossible travel. The alert directly reflects a risk to the user's identity, making the User account the most relevant entity type for this scenario.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Device
Why it's wrong here
While a device can be the source or target of a credential compromise, Microsoft Sentinel UEBA anchors its behavioral analytics on entities such as users, hosts, and IP addresses, with the user account as the primary subject for credential-based attacks. A device provides context—like the machine from which a login originates—but does not itself embody the credential; multiple users may share a device, so its baseline is less indicative of account takeover. Therefore, Device is not the primary entity when investigating a credential compromise.
- ✗
Application
Why it's wrong here
Applications (such as enterprise apps or OAuth integrations) serve as access targets or authentication registrations in Microsoft Entra ID, not as the behavioral subject in Sentinel UEBA for detecting credential compromise. A malicious sign-in to a corporate app is attributed by Sentinel to the user account that authenticates and to the source IP/host, while the application itself only reflects which resource was accessed. Since compromised credentials can be used across many applications, the Application entity provides no standalone behavioral signal for account takeover.
- ✗
IP address
Why it's wrong here
An IP address is an ephemeral, shareable network attribute that Microsoft Sentinel UEBA treats as a contextual indicator, not as the entity that is compromised. IPs can be changed, spoofed, or shared behind NAT/VPN, so they cannot represent a distinct identity; a single IP may host multiple user accounts, and a single user may constantly change IPs. While impossible-travel detections use IP geography, the investigation still pivots on the user account whose credentials are being abused, making IP only a supporting clue.
- ✓
User account
Why this is correct
In Microsoft Sentinel UEBA, the user account is the primary entity type for detecting credential compromise because authentication and authorization are fundamentally tied to accounts. Attacks such as password spray, brute force, impossible travel, and anomalous sign-in all manifest as unusual activity on a user account, and UEBA builds a behavioral baseline per user to score these deviations. The investigation timeline aggregates sign-in events, machine activity, and assigned alerts around the account, enabling analysts to trace the full scope of a compromise. Therefore, User account is the correct answer.
Go deeper
Related to this question
About these practice questions
This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.