Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Microsoft SC-200 Exam - Topic 3 Question 112 Discussion

You have a Microsoft Sentinel workspace.You enable User and Entity Behavior Analytics (UFBA) by using Audit logs and Signin logs. The following entities are detected in the Azure AD tenant:* App name: App1* IP address: 192.168.1.2* Computer name: Device1* Used client app: Microsoft Edge* Email address: user1@company.com* Sign-in URL: https://www.company.comWhich entities can be investigated by using UEBA?
B) IP address and email address only
A) app name, computer name, IP address, email address, and used client app only
C) used client app and app name only
D) IP address only

Microsoft SC-200 Exam - Topic 3 Question 112 Discussion

Actual exam question for Microsoft's SC-200 exam
Question #: 112
Topic #: 3
[All SC-200 Questions]

You have a Microsoft Sentinel workspace.

You enable User and Entity Behavior Analytics (UFBA) by using Audit logs and Signin logs. The following entities are detected in the Azure AD tenant:

* App name: App1

* IP address: 192.168.1.2

* Computer name: Device1

* Used client app: Microsoft Edge

* Email address: user1@company.com

* Sign-in URL: https://www.company.com

Which entities can be investigated by using UEBA?

Show Suggested Answer Hide Answer
Suggested Answer: B

Microsoft Sentinel UEBA (User and Entity Behavior Analytics) focuses on users and hosts (devices) and enriches data with contextual information. When enabling UEBA with Audit logs and Signin logs, the only entities supported for investigation are:

User accounts (email addresses)

Hosts or devices (including IP addresses)

Other values like App name, Used client app, and Sign-in URL are attributes in log data but not tracked entities in UEBA investigations.

Answe r: B. IP address and email address only


Contribute your Thoughts:

0/2000 characters

Currently there are no comments in this discussion, be the first to comment!


Save Cancel