Microsoft Security, Compliance, and Identity Fundamentals (SC-900)Describe the concepts of security, compliance, and identityMedium

A security architect is designing a system that must detect and respond to unusual activities, such as an employee attempting to access sensitive data outside their typical working hours from an unfamiliar location. Which security capability is best suited for identifying and alerting on such anomalous behavior?

  1. ALeast Privilege
  2. BRole-Based Access Control (RBAC)
  3. CMulti-Factor Authentication (MFA)
  4. DUser and Entity Behavior Analytics (UEBA)
Show answer & explanation

Correct answer: D. User and Entity Behavior Analytics (UEBA)

User and Entity Behavior Analytics (UEBA) specifically uses machine learning and algorithms to establish a baseline of normal behavior and then identifies deviations, which are indicative of potential threats or compromises.

Why the other options are wrong

  • A. Least Privilege ensures users only have necessary permissions, but doesn't actively monitor for unusual activity within those permissions.
  • B. RBAC defines what resources users can access based on their role, but doesn't detect anomalous behavior outside of those permissions.
  • C. MFA strengthens authentication but doesn't detect or respond to anomalous post-authentication behavior.

User and Entity Behavior Analytics (UEBA)

UEBA is a cybersecurity process that leverages machine learning and deep learning algorithms to analyze user and entity behavior patterns, identify deviations from normal baselines, and detect potential threats or attacks.

  • Establishes baselines of normal behavior.
  • Detects anomalies indicative of threats.
  • Identifies insider threats and compromised accounts.

Memory trick: UEBA watches for the odd ones out in behavior patterns.

More Describe the concepts of security, compliance, and identity questions