Courseiva

SC-900 Practice Question: Describe the capabilities of Microsoft security solutions

A security operations center (SOC) team uses Microsoft Sentinel with User and Entity Behavior Analytics (UEBA) enabled. They notice an alert about a user accessing a sensitive HR application from an unusual IP address at 3 AM. What does UEBA primarily use to detect this anomaly?

⚠ Common exam trap

Watch out — candidates often confuse UEBA's ML-driven behavioral baselines with static rule-based detection or external threat intelligence, assuming any unusual IP must come from a threat feed rather than recognizing the anomaly is based on the user's own historical patterns.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Historical behavior baselines and machine learning

UEBA in Microsoft Sentinel detects anomalies by establishing a baseline of normal user behavior over time—such as typical login times, locations, and accessed applications—using machine learning models. When a user accesses a sensitive HR app from an unusual IP at 3 AM, the deviation from this learned baseline triggers an alert, not a static rule or manual input.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Static rule-based thresholds defined by the SOC

    Why it's wrong here

    User and Entity Behavior Analytics (UEBA) fundamentally deviates from static rule-based thresholds. While traditional security information and event management (SIEM) systems often rely on predefined rules to detect known threats, UEBA leverages machine learning algorithms to dynamically establish baselines of normal behavior. This approach allows it to identify subtle anomalies that would bypass fixed thresholds, which are prone to generating excessive false positives or missing novel attack patterns.

  • Manual input from the SOC team

    Why it's wrong here

    User and Entity Behavior Analytics (UEBA) is designed to operate with a high degree of automation, significantly reducing the need for continuous manual input from the Security Operations Center (SOC) team. Its core function involves autonomously collecting and analyzing vast amounts of user and entity activity data to build behavioral profiles. While SOC analysts certainly investigate the high-fidelity alerts generated by UEBA, the system itself does not depend on manual data entry or rule creation for its primary detection capabilities.

  • Historical behavior baselines and machine learning

    Why this is correct

    User and Entity Behavior Analytics (UEBA) relies critically on establishing comprehensive historical behavior baselines for users and entities within an environment. Machine learning algorithms continuously process vast datasets of activity, learning what constitutes "normal" behavior over time for each individual or system. By comparing current activities against these dynamically learned baselines, UEBA can effectively identify deviations and anomalous patterns that indicate potential security threats, such as insider threats or compromised accounts, without requiring explicit rules.

  • Threat intelligence feeds from Microsoft

    Why it's wrong here

    While threat intelligence feeds, including those from Microsoft, are crucial components of a robust security posture, they represent a distinct mechanism from the core functionality of User and Entity Behavior Analytics (UEBA). Threat intelligence provides information about known malicious IP addresses, domains, file hashes, and attack patterns, enabling detection of external threats. In contrast, UEBA focuses on internal behavioral anomalies by profiling user and entity activities, detecting deviations from established norms rather than matching against known bad indicators.

Go deeper

Related to this question

About these practice questions

One of 1,250 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.