Courseiva

SC-200 Manage a security operations environment Practice Question

Your organization uses Microsoft Sentinel with UEBA enabled. You need to investigate a potential insider threat where a user is accessing sensitive data outside of business hours. Which three built-in UEBA entities should you review?

⚠ Common exam trap

The SC-200 exam often tests the distinction between Azure resource management constructs (subscriptions, resource groups) and actual security entities that UEBA monitors, leading candidates to select options that sound related but are not part of the UEBA entity schema.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

User account

User account (B) is correct because UEBA in Microsoft Sentinel profiles user behavior to detect anomalies such as accessing sensitive data outside business hours. The user account entity is the primary identity used to correlate activities, logon events, and data access patterns, enabling the detection of insider threats based on deviations from established baselines.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Azure subscription

    Why it's wrong here

    An Azure subscription is a billing and access-management boundary that groups resources and applies Azure Policy/RBAC, but it is not an entity in Microsoft Sentinel's UEBA model. UEBA builds behavioral profiles for things that can exhibit identity or location characteristics—such as users, hosts, and IP addresses—not for management containers. Subscriptions do not produce independent sign-in or interaction events with a risk score, so they are excluded from entity pages and analytics.

  • ✓

    User account

    Why this is correct

    The user account is the central entity type in UEBA because it has a distinct identity that can be associated with authentication events, directory actions, and application usage. Sentinel's UEBA profiles the user by aggregating raw activities from sources like Microsoft Entra ID sign-in logs, Office 365 audit logs, and Windows security events, then computes a baseline to identify anomalies such as impossible travel or privileged-account misuse. Without a user entity, behavioral analytics like 'user from new country' or 'user added to privileged group' would have no subject to attach to.

  • ✓

    Device

    Why this is correct

    A device (also represented as a host entity) is a UEBA entity because devices initiate network connections, run processes, and receive authentication attempts, making them observable subjects of behavior. Sentinel tracks device identifiers such as hostname, device ID, or MAC address to spot signals like a compromised device beaconing to a command-and-control server or a device performing unusual name-resolution queries. Device behavior is analyzed alongside user behavior, for example linking a risky sign-in from a new device to a subsequent lateral movement event.

  • ✓

    IP address

    Why this is correct

    An IP address is a UEBA entity because it is the network-level identity that can be correlated with geographic location, Autonomous System Number (ASN), and connection patterns. UEBA uses IP entities to detect anomalies like failed logins originating from a previously unseen IP, data exfiltration to a suspicious IP range, or brute-force attempts from a host that has never communicated with the organization before. IP entities are also key to building 'impossible travel' detections, as the source address's physical location is compared against the user's normal travel patterns.

  • ✗

    Resource group

    Why it's wrong here

    A resource group is a logical container in Azure used to organize resources like VMs, storage accounts, and network interfaces; it is not a manageable entity in UEBA. Unlike users or devices, a resource group does not have an identity, cannot authenticate, and does not generate behavioral signals that Sentinel's entity timeline can aggregate. While individual resources within a resource group can be mapped to host or IP entities, the resource group itself is filtered out of entity pages and is never the subject of UEBA-based analytics rules.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.