SC-200 Manage a security operations environment Practice Question
Your organization uses Microsoft Sentinel with User and Entity Behavior Analytics (UEBA) enabled. You notice that the UEBA is not generating any anomalies for a particular user who has been inactive for 30 days. You have verified that the user's data is being ingested into the workspace. What is the most likely reason?
⚠ Common exam trap
Test-takers frequently assume data ingestion alone is sufficient for UEBA, but the feature specifically requires a minimum baseline period of 14 days of activity to generate anomalies, and inactivity beyond that period breaks the baseline.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
UEBA requires a minimum of 14 days of activity to establish a baseline.
UEBA in Microsoft Sentinel requires a minimum of 14 days of historical data to build a behavioral baseline for each user. If a user has been inactive for 30 days, the baseline may have expired or never been established, so no anomalies are generated. The data ingestion is confirmed, but without recent activity, UEBA cannot compare current behavior against a meaningful profile.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
UEBA requires a minimum of 14 days of activity to establish a baseline.
Why this is correct
UEBA in Microsoft Sentinel relies on machine learning to learn what 'normal' behavior looks like for each user or entity. A minimum of 14 days of historical activity must be ingested into the workspace before a reliable baseline is established; without that baseline, UEBA cannot differentiate anomalous activity from ordinary variations. Even though UEBA is enabled, the lack of detections within the initial period is expected and not due to configuration errors.
- ✗
The user's license does not include UEBA.
Why it's wrong here
This option mischaracterizes the licensing model for Microsoft Sentinel. UEBA is not a per-user entitlement that must be assigned like an identity license; it is a built-in security analytics feature of Sentinel itself, available as part of the workspace's pricing plan. Therefore, an individual user's license status cannot prevent UEBA from functioning, and the statement is incorrect.
- ✗
UEBA only works with Active Directory data, not Microsoft Entra ID.
Why it's wrong here
UEBA does not depend exclusively on Active Directory; Microsoft Sentinel's UEBA ingests and analyzes data from a wide array of sources, including Microsoft Entra ID sign-in and audit logs, Windows Security events, Office 365 activity, and more. This broad data ingestion is what enables the entity behavioral profiles, so limiting UEBA to on-premises AD is a false premise. The incorrect assumption about data-source dependence is not the reason for missing detections.
- ✗
UEBA is not enabled for the workspace.
Why it's wrong here
The scenario explicitly states that user and entity behavior analytics is already enabled for the Sentinel workspace, so a disabled UEBA cannot be the cause of the expected anomaly detections. While it is true that UEBA must be enabled for behavioral baselining, the enabling step has already been completed in the given scenario. Thus, this explanation contradicts the provided facts and is not the correct reason.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.