SC-200 · Question #251
You have a Microsoft Sentinel workspace that has User and Entity Behavior Analytics (UEBA) enabled for Signin Logs. You need to ensure that failed interactive sign-ins are detected. The solution…
The correct answer is C. a UEBA activity template. To detect common security scenarios with minimal administrative effort when UEBA is enabled, using a built-in UEBA activity template is the most efficient solution.
Question
You have a Microsoft Sentinel workspace that has User and Entity Behavior Analytics (UEBA) enabled for Signin Logs. You need to ensure that failed interactive sign-ins are detected. The solution must minimize administrative effort. What should you use?
Options
- Aa scheduled alert query
- Bthe Activity Log data connector
- Ca UEBA activity template
- Da hunting query
How the community answered
(24 responses)- A4% (1)
- B13% (3)
- C79% (19)
- D4% (1)
Why each option
To detect common security scenarios with minimal administrative effort when UEBA is enabled, using a built-in UEBA activity template is the most efficient solution.
A scheduled alert query would require manual creation and maintenance of the KQL query and alert logic, increasing administrative effort compared to a template.
The Activity Log data connector collects Azure activity logs, which are different from Azure AD Signin Logs and not directly relevant to detecting failed interactive sign-ins via UEBA in this context.
UEBA activity templates are pre-built configurations within Microsoft Sentinel that leverage UEBA's behavioral analytics to detect specific activities, such as failed interactive sign-ins, with minimal administrative setup. Since UEBA is already enabled for Signin Logs, these templates can directly use that data.
A hunting query is used for proactive threat hunting and investigation, not for automatically detecting and alerting on common, well-defined security incidents with minimal administrative effort.
Concept tested: Microsoft Sentinel UEBA activity templates
Source: https://learn.microsoft.com/en-us/azure/sentinel/monitor-entities-with-ueba#investigate-activities-across-users-and-entities
Topics
Community Discussion
No community discussion yet for this question.