Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Microsoft SC-200 Exam - Topic 3 Question 112 Discussion

You have a Microsoft Sentinel workspace.You enable User and Entity Behavior Analytics (UFBA) by using Audit logs and Signin logs. The following entities are detected in the Azure AD tenant:* App name: App1* IP address: 192.168.1.2* Computer name: Device1* Used client app: Microsoft Edge* Email address: user1@company.com* Sign-in URL: https://www.company.comWhich entities can be investigated by using UEBA?
B) IP address and email address only
A) app name, computer name, IP address, email address, and used client app only
C) used client app and app name only
D) IP address only

Microsoft SC-200 Exam - Topic 3 Question 112 Discussion

Actual exam question for Microsoft's SC-200 exam
Question #: 112
Topic #: 3
[All SC-200 Questions]

You have a Microsoft Sentinel workspace.

You enable User and Entity Behavior Analytics (UFBA) by using Audit logs and Signin logs. The following entities are detected in the Azure AD tenant:

* App name: App1

* IP address: 192.168.1.2

* Computer name: Device1

* Used client app: Microsoft Edge

* Email address: user1@company.com

* Sign-in URL: https://www.company.com

Which entities can be investigated by using UEBA?

Show Suggested Answer Hide Answer
Suggested Answer: B

Microsoft Sentinel UEBA (User and Entity Behavior Analytics) focuses on users and hosts (devices) and enriches data with contextual information. When enabling UEBA with Audit logs and Signin logs, the only entities supported for investigation are:

User accounts (email addresses)

Hosts or devices (including IP addresses)

Other values like App name, Used client app, and Sign-in URL are attributes in log data but not tracked entities in UEBA investigations.

Answe r: B. IP address and email address only


Contribute your Thoughts:

0/2000 characters
Vallie
23 days ago
I'm leaning towards B. IP and email are crucial for tracking.
upvoted 0 times
...
Judy
29 days ago
I agree with A. It covers everything we need to investigate.
upvoted 0 times
...
Iesha
1 month ago
I think A is the best choice. All those entities are relevant.
upvoted 0 times
...
Kassandra
1 month ago
I thought we could look into more than just the IP and email.
upvoted 0 times
...
Celestina
1 month ago
I disagree, B is way too limited.
upvoted 0 times
...
Lizbeth
2 months ago
Wait, can we really only investigate those? Seems off.
upvoted 0 times
...
Kizzy
2 months ago
Definitely A! Makes the most sense.
upvoted 0 times
...
Patria
2 months ago
I think all those entities can be investigated.
upvoted 0 times
...
Fausto
2 months ago
I vaguely recall that UEBA focuses on user behavior, so maybe it’s just the email and app name that are relevant?
upvoted 0 times
...
Talia
2 months ago
I’m leaning towards option A because it seems like UEBA would cover most of those entities, but I could be wrong.
upvoted 0 times
...
Allene
3 months ago
I remember a practice question where we had to identify which entities were relevant for investigation, and I feel like it was more than just one or two.
upvoted 0 times
...
Sueann
3 months ago
I think we can investigate multiple entities with UEBA, but I'm not sure if all of them are included in the options.
upvoted 0 times
...

Save Cancel