SC-200 Manage a security operations environment Practice Question
Your organization uses Microsoft Sentinel with UEBA enabled. You need to investigate a potential insider threat where a user is accessing sensitive data outside of business hours. Which three built-in UEBA entities should you review?
⚠ Common exam trap
The SC-200 exam often tests the distinction between Azure resource management constructs (subscriptions, resource groups) and actual security entities that UEBA monitors, leading candidates to select options that sound related but are not part of the UEBA entity schema.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
User account
User account (B) is correct because UEBA in Microsoft Sentinel profiles user behavior to detect anomalies such as accessing sensitive data outside business hours. The user account entity is the primary identity used to correlate activities, logon events, and data access patterns, enabling the detection of insider threats based on deviations from established baselines.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Azure subscription
Why it's wrong here
An Azure subscription is a billing and access-management boundary that groups resources and applies Azure Policy/RBAC, but it is not an entity in Microsoft Sentinel's UEBA model. UEBA builds behavioral profiles for things that can exhibit identity or location characteristics—such as users, hosts, and IP addresses—not for management containers. Subscriptions do not produce independent sign-in or interaction events with a risk score, so they are excluded from entity pages and analytics.
- ✓
User account
Why this is correct
The user account is the central entity type in UEBA because it has a distinct identity that can be associated with authentication events, directory actions, and application usage. Sentinel's UEBA profiles the user by aggregating raw activities from sources like Microsoft Entra ID sign-in logs, Office 365 audit logs, and Windows security events, then computes a baseline to identify anomalies such as impossible travel or privileged-account misuse. Without a user entity, behavioral analytics like 'user from new country' or 'user added to privileged group' would have no subject to attach to.
- ✓
Device
Why this is correct
A device (also represented as a host entity) is a UEBA entity because devices initiate network connections, run processes, and receive authentication attempts, making them observable subjects of behavior. Sentinel tracks device identifiers such as hostname, device ID, or MAC address to spot signals like a compromised device beaconing to a command-and-control server or a device performing unusual name-resolution queries. Device behavior is analyzed alongside user behavior, for example linking a risky sign-in from a new device to a subsequent lateral movement event.
- ✓
IP address
Why this is correct
An IP address is a UEBA entity because it is the network-level identity that can be correlated with geographic location, Autonomous System Number (ASN), and connection patterns. UEBA uses IP entities to detect anomalies like failed logins originating from a previously unseen IP, data exfiltration to a suspicious IP range, or brute-force attempts from a host that has never communicated with the organization before. IP entities are also key to building 'impossible travel' detections, as the source address's physical location is compared against the user's normal travel patterns.
- ✗
Resource group
Why it's wrong here
A resource group is a logical container in Azure used to organize resources like VMs, storage accounts, and network interfaces; it is not a manageable entity in UEBA. Unlike users or devices, a resource group does not have an identity, cannot authenticate, and does not generate behavioral signals that Sentinel's entity timeline can aggregate. While individual resources within a resource group can be mapped to host or IP entities, the resource group itself is filtered out of entity pages and is never the subject of UEBA-based analytics rules.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.