SC-200 Manage a security operations environment Practice Question
Your organization uses Microsoft Sentinel with UEBA enabled. You need to identify anomalous user behavior that indicates a potential compromise. Which entity behavior analytics feature should you use?
⚠ Common exam trap
Watch out — candidates often confuse anomaly rules in analytics (option D) with UEBA peer comparison, but anomaly rules are generic detection mechanisms that do not inherently use peer-group baselines, whereas peer comparison is a dedicated UEBA capability for entity-specific anomaly detection.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Entity behavior analytics peer comparison
Entity behavior analytics peer comparison (option C) is the correct feature because it uses UEBA to compare a user's activities against their historical baseline and peer group behavior to detect anomalies indicative of compromise. This directly addresses the requirement to identify anomalous user behavior, as peer comparison highlights deviations like unusual access patterns or data exfiltration attempts that single-entity baselines might miss.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Automation rules
Why it's wrong here
Automation rules in Microsoft Sentinel are triggered by incident creation or alert generation and execute playbooks to automate response actions, such as changing an incident's status or assigning it to an analyst. They operate post-detection and do not analyze raw behavioral data, nor do they compare user activities against baselines to identify anomalies. Consequently, they cannot serve as the mechanism for detecting peer-comparison-based behavioral anomalies.
- ✗
Hunting queries
Why it's wrong here
While hunting queries allow analysts to proactively search Sentinel's workspace for suspicious activity using Kusto Query Language, they are not automated baseline anomaly detection. A hunter must manually define the query logic, and scheduled hunting rules simply execute those predefined queries repeatedly rather than dynamically learning what is normal for each user or entity. UEBA's peer comparison, by contrast, continuously computes behavioral baselines and flags deviations without requiring manual query design.
- ✓
Entity behavior analytics peer comparison
Why this is correct
Entity behavior analytics in Microsoft Sentinel uses UEBA to build a historical behavioral profile for each user, host, or other entity, including attributes like sign-in times, accessed apps, and resource usage. It then performs peer comparison by grouping entities with similar roles or attributes and statistically identifies when an individual's current behavior deviates from the group's baseline, such as an unusual location or impossible travel. This automated, baseline-driven peer comparison is precisely how UEBA detects anomalies, making it the correct answer.
- ✗
Anomaly rules in analytics
Why it's wrong here
Anomaly rules in analytics are a type of detection rule in Sentinel that can be configured to alert on statistically unusual patterns, but they rely on explicit thresholds, time ranges, and specific ML algorithms chosen by the rule builder rather than on automatic peer-group baseline comparison. Unlike UEBA's entity behavior analytics, anomaly rules do not inherently leverage the same entity-based peer profiles to establish normal behavior. Therefore, while they are related to UEBA, they are not the primary feature that compares a user's behavior against peers to flag anomalies.
Go deeper
Related to this question
About these practice questions
This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.