SC-200 · Question #366
You have an Azure subscription that contains a Microsoft Sentinel workspace named WS1. WS1 has the Azure Activity connector and the Microsoft Entra ID connector configured. You need to investigate…
The correct answer is B. Enable User and Entity Behavior Analytics (UEBA). To investigate accounts with the most alerts and incident information in WS1 with minimal administrative effort, first enable User and Entity Behavior Analytics (UEBA).
Question
You have an Azure subscription that contains a Microsoft Sentinel workspace named WS1. WS1 has the Azure Activity connector and the Microsoft Entra ID connector configured. You need to investigate which accounts have the most alerts and any corresponding incident information for each alert. The solution must minimize administrative effort. What should you do first in WS1?
Options
- AUse User and Entity Behavior Analytics (UEBA) to detect anomalies.
- BEnable User and Entity Behavior Analytics (UEBA).
- CFrom Content hub, install the Microsoft Purview insider risk management solution.
- DFrom Content hub, install Cloud Identity Threat Protection Essentials.
How the community answered
(41 responses)- A5% (2)
- B76% (31)
- C5% (2)
- D15% (6)
Why each option
To investigate accounts with the most alerts and incident information in WS1 with minimal administrative effort, first enable User and Entity Behavior Analytics (UEBA).
You cannot 'use' UEBA to detect anomalies until it has been enabled and configured, making enabling it the prerequisite first action.
Enabling User and Entity Behavior Analytics (UEBA) in Microsoft Sentinel is the foundational step to enrich user and entity data, enabling the system to automatically correlate activities and provide insights into anomalous behavior, which is essential for investigating accounts with the most alerts and associated incidents.
Installing Microsoft Purview insider risk management is primarily for managing insider risks within Microsoft 365 and does not directly enhance Sentinel's core capabilities for investigating general account-based alerts and incidents.
While 'Cloud Identity Threat Protection Essentials' may offer useful content, enabling UEBA is a more fundamental and direct step for gaining behavioral insights into accounts and alerts from the existing connectors.
Concept tested: Microsoft Sentinel UEBA enablement for account investigation
Source: learn.microsoft.com/azure/sentinel/enable-ueba
Community Discussion
No community discussion yet for this question.