Valid SC-200 Dumps shared by EduDump.com for Helping Passing SC-200 Exam! EduDump.com now offer the newest SC-200 exam dumps, the EduDump.com SC-200 exam questions have been updated and answers have been corrected get the newest EduDump.com SC-200 dumps with Test Engine here:
You have a Microsoft Sentinel workspace. You enable User and Entity Behavior Analytics (UFBA) by using Audit logs and Signin logs. The following entities are detected in the Azure AD tenant: * App name: App1 * IP address: 192.168.1.2 * Computer name: Device1 * Used client app: Microsoft Edge * Email address: [email protected] * Sign-in URL: https://www.company.com Which entities can be investigated by using UEBA?
Correct Answer: B
Microsoft Sentinel UEBA (U ser and Entity Behavior Analytics) focuses on users and hosts (devices) and enriches data with contextual information. When enabling UEBA with Audit logs and Signin logs , the only entities supported for investigation are: * User accounts (email addresses) * Ho sts or devices (including IP addresses) Other values like App name , Used client app , and Sign-in URL are attributes in log data but not tracked entities in UEBA investigations. # Answer: B. IP address and email address only