nerdexam
Microsoft

SC-200 · Question #238

You have a Microsoft Sentinel workspace. You enable User and Entity Behavior Analytics (UEBA) by using Audit Logs and Signin Logs. The following entities are detected in the Azure AD tenant: - App…

The correct answer is B. app name, computer name, IP address, email address, and used client app only. UEBA in Microsoft Sentinel uses various types of entities for analysis, including users, hosts, IP addresses, applications, and devices.

Submitted by haruto_sh· Apr 18, 2026Detect and remediate threats using Microsoft Sentinel

Question

You have a Microsoft Sentinel workspace. You enable User and Entity Behavior Analytics (UEBA) by using Audit Logs and Signin Logs. The following entities are detected in the Azure AD tenant:

  • App name: App1
  • IP address: 192.168.1.2
  • Computer name: Device1
  • Used client app: Microsoft Edge
  • Email address: [email protected]

Which entities can be investigated by using UEBA?

Options

  • AIP address and email address only
  • Bapp name, computer name, IP address, email address, and used client app only
  • CIP address only
  • Dused client app and app name only

How the community answered

(28 responses)
  • B
    96% (27)
  • C
    4% (1)

Why each option

UEBA in Microsoft Sentinel uses various types of entities for analysis, including users, hosts, IP addresses, applications, and devices.

AIP address and email address only

This choice is too restrictive; UEBA supports more entity types than just IP addresses and email addresses.

Bapp name, computer name, IP address, email address, and used client app onlyCorrect

Microsoft Sentinel's UEBA capability correlates data across multiple logs, including Audit Logs and Signin Logs, to build behavioral profiles for a wide range of entities such as users, hosts (computers), IP addresses, applications, and devices (client apps like Microsoft Edge). All the listed entities (app name, computer name, IP address, email address/user, and used client app) are recognized and can be investigated by UEBA.

CIP address only

This choice is too restrictive; UEBA supports many more entity types than just IP addresses.

Dused client app and app name only

This choice is too restrictive; UEBA supports more entity types, including users, hosts, and IP addresses.

Concept tested: Microsoft Sentinel UEBA entity types

Source: https://learn.microsoft.com/en-us/azure/sentinel/ueba-reference

Topics

#Microsoft Sentinel#UEBA#Entities#Threat detection

Community Discussion

No community discussion yet for this question.

Full SC-200 Practice