Courseiva

SC-200 Manage a security operations environment Practice Question

Your security team uses Microsoft Sentinel UEBA to detect anomalous user behavior. You need to configure UEBA to baseline user activities and generate alerts for deviations. What must you do first?

⚠ Common exam trap

It's easy for candidates to assume UEBA is automatically enabled or that it requires external ML services (like Azure Machine Learning) or premium licenses (like M365 E5), when in fact the first step is simply toggling the feature on and selecting data sources within Sentinel's own settings.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable UEBA in the Sentinel Settings blade and select relevant data sources.

Microsoft Sentinel UEBA requires explicit enablement in the Sentinel Settings blade under the 'Entity behavior analytics' section. Once enabled, you must select the relevant data sources (e.g., Microsoft Entra ID sign-in logs, Office 365 audit logs, Windows Security Events) so that Sentinel can baseline normal user behavior patterns and generate alerts for anomalous deviations. Without this initial configuration, UEBA cannot process any data or produce behavioral analytics.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create an Azure Machine Learning workspace for anomaly detection.

    Why it's wrong here

    Creating an Azure Machine Learning workspace is unnecessary because Microsoft Sentinel UEBA uses built-in, pre-trained ML models that require no custom model development or external workspace. You would still have to enable UEBA in Sentinel Settings and select data sources; an Azure ML workspace does not activate entity behavior analytics. This option conflates building a custom anomaly detector with the configuration of Sentinel's native UEBA capability.

  • ✓

    Enable UEBA in the Sentinel Settings blade and select relevant data sources.

    Why this is correct

    In Microsoft Sentinel, UEBA is disabled by default; you must open Settings > UEBA, toggle it on, and select the relevant data sources such as Microsoft Entra ID sign-in logs, Microsoft Entra ID audit logs, and Microsoft Defender for Identity data. Once enabled, Sentinel creates entity profiles, establishes behavioral baselines over time, and uses built-in ML to detect anomalies including impossible travel and sign-in from unusual locations. This is the definitive prerequisite step; without it, no entity behavior analytics or anomaly scoring runs in Sentinel.

  • ✗

    Assign Microsoft 365 E5 licenses to all users.

    Why it's wrong here

    Assigning Microsoft 365 E5 licenses is not required for Sentinel UEBA because UEBA is a Microsoft Sentinel feature governed by Sentinel licensing, not by Microsoft 365 plans. While E5 includes related technologies such as Microsoft Defender for Identity that can enrich UEBA if connected, simply assigning E5 licenses does not turn on UEBA in the Sentinel Settings blade. This answer incorrectly suggests an identity-license dependency that does not exist for enabling Sentinel's UEBA.

  • ✗

    Deploy a custom data connector for HR systems.

    Why it's wrong here

    Deploying a custom data connector for HR systems is irrelevant because Sentinel UEBA relies on standard data sources already available through built-in connectors, and the UEBA settings blade lists specific source types such as Microsoft Entra ID and Defender for Identity. HR data, even if ingested, is not a recognized UEBA source used for baseline creation or anomaly detection in the UEBA feature; watchlists could add context but are not a prerequisite. This option incorrectly implies that additional custom ingestion is required when the actual task is configuring Sentinel's native UEBA settings.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.