SC-900 Practice Question: Describe the capabilities of Microsoft security solutions
A security operations center (SOC) team uses Microsoft Sentinel with User and Entity Behavior Analytics (UEBA) enabled. They notice an alert about a user accessing a sensitive HR application from an unusual IP address at 3 AM. What does UEBA primarily use to detect this anomaly?
⚠ Common exam trap
Watch out — candidates often confuse UEBA's ML-driven behavioral baselines with static rule-based detection or external threat intelligence, assuming any unusual IP must come from a threat feed rather than recognizing the anomaly is based on the user's own historical patterns.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Historical behavior baselines and machine learning
UEBA in Microsoft Sentinel detects anomalies by establishing a baseline of normal user behavior over time—such as typical login times, locations, and accessed applications—using machine learning models. When a user accesses a sensitive HR app from an unusual IP at 3 AM, the deviation from this learned baseline triggers an alert, not a static rule or manual input.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Static rule-based thresholds defined by the SOC
Why it's wrong here
User and Entity Behavior Analytics (UEBA) fundamentally deviates from static rule-based thresholds. While traditional security information and event management (SIEM) systems often rely on predefined rules to detect known threats, UEBA leverages machine learning algorithms to dynamically establish baselines of normal behavior. This approach allows it to identify subtle anomalies that would bypass fixed thresholds, which are prone to generating excessive false positives or missing novel attack patterns.
- ✗
Manual input from the SOC team
Why it's wrong here
User and Entity Behavior Analytics (UEBA) is designed to operate with a high degree of automation, significantly reducing the need for continuous manual input from the Security Operations Center (SOC) team. Its core function involves autonomously collecting and analyzing vast amounts of user and entity activity data to build behavioral profiles. While SOC analysts certainly investigate the high-fidelity alerts generated by UEBA, the system itself does not depend on manual data entry or rule creation for its primary detection capabilities.
- ✓
Historical behavior baselines and machine learning
Why this is correct
User and Entity Behavior Analytics (UEBA) relies critically on establishing comprehensive historical behavior baselines for users and entities within an environment. Machine learning algorithms continuously process vast datasets of activity, learning what constitutes "normal" behavior over time for each individual or system. By comparing current activities against these dynamically learned baselines, UEBA can effectively identify deviations and anomalous patterns that indicate potential security threats, such as insider threats or compromised accounts, without requiring explicit rules.
- ✗
Threat intelligence feeds from Microsoft
Why it's wrong here
While threat intelligence feeds, including those from Microsoft, are crucial components of a robust security posture, they represent a distinct mechanism from the core functionality of User and Entity Behavior Analytics (UEBA). Threat intelligence provides information about known malicious IP addresses, domains, file hashes, and attack patterns, enabling detection of external threats. In contrast, UEBA focuses on internal behavioral anomalies by profiling user and entity activities, detecting deviations from established norms rather than matching against known bad indicators.
Go deeper
Related to this question
Learn chapter
Core Security Concepts
Key term
Baseline
A baseline is a documented starting point for the normal performance and behavior of a system, network, or component, used to detect changes and troubleshoot issues.
Key term
Microsoft Sentinel
Microsoft Sentinel is a cloud-native security information and event management (SIEM) and security orchestration automation and response (SOAR) service that helps organizations detect, investigate, and respond to cyber threats across their entire digital estate.
About these practice questions
One of 1,250 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.