Courseiva

SC-200 Manage a security operations environment Practice Question

Your SOC team uses Microsoft Sentinel's UEBA to detect insider threats. You want to ensure that UEBA can correlate activities across multiple data sources. Which data source must be enabled for UEBA to function properly?

⚠ Common exam trap

Candidates often assume Office 365 audit logs (Option B) are the primary identity source because they contain user actions, but Microsoft Sentinel's UEBA specifically requires Entra ID audit logs to establish the foundational identity baseline before correlating other data sources.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Microsoft Entra ID audit logs

Microsoft Sentinel's UEBA relies on Microsoft Entra ID (formerly Azure AD) audit logs as the primary identity source to establish a baseline of user behavior and correlate activities across different data sources. Without these logs, UEBA cannot map activities to specific user identities, which is essential for detecting anomalous behavior patterns indicative of insider threats.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Azure Activity logs

    Why it's wrong here

    Azure Activity logs capture control-plane events such as resource creation, deletion, and configuration changes in Azure Resource Manager. They lack user-level identity context like user principal names or sign-in patterns, so they cannot feed UEBA's behavioral profiling of individual users. The audit trail is primarily about 'what happened to the resource' rather than 'what the user did across applications and services.'

  • ✗

    Office 365 audit logs

    Why it's wrong here

    Office 365 audit logs do contain user actions within Exchange, SharePoint, and Teams workloads, making them useful for investigating productivity app anomalies. However, they are workload-specific and do not provide the foundational identity-centric data UEBA requires, such as sign-in failures, conditional access results, and directory changes. UEBA correlates identity patterns across all sources, and Office 365 logs alone cannot establish the baseline user behavior that Microsoft Entra ID audit and sign-in logs provide.

  • ✗

    Windows Security Events

    Why it's wrong here

    Windows Security Events are endpoint-level logs that record local authentication and process activity (e.g., Event IDs 4624 and 4625) on Windows machines. They lack the cross-source identity correlation needed for UEBA because they do not capture cloud sign-ins, application usage, or directory modifications. UEBA ingests these events as one data source, but they are not the primary identity source—without the directory schema and user entity mapping from Entra ID, behavioral analytics cannot function.

  • ✓

    Microsoft Entra ID audit logs

    Why this is correct

    Microsoft Entra ID audit logs are the correct primary source for UEBA because they contain identity-centric actions such as user sign-ins, conditional access evaluations, and directory modifications (e.g., password changes, role assignments). UEBA uses these logs to construct user profiles and establish behavioral baselines, enabling detection of anomalous activity like impossible travel or unusual authentication patterns. Since UEBA is fundamentally about user entity behavior, Entra ID logs provide the identity context that other logs lack.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.