Microsoft Security, Compliance, and Identity Fundamentals (SC-900)Describe the concepts of security, compliance, and identityMedium
A security architect is designing a system that must detect and respond to unusual activities, such as an employee attempting to access sensitive files outside of their usual working hours or from an unfamiliar location. The goal is to identify potential insider threats or compromised accounts. Which security capability is primarily focused on this type of detection?
- AUser and Entity Behavior Analytics (UEBA)
- BSecurity Information and Event Management (SIEM)
- CEndpoint Detection and Response (EDR)
- DIdentity and Access Management (IAM)
Show answer & explanationAnswer & explanation
Correct answer: A. User and Entity Behavior Analytics (UEBA)
UEBA systems specialize in analyzing user and entity behavior patterns to detect anomalies that may indicate threats, such as unusual access times or locations, which directly matches the scenario.
Why the other options are wrong
- B. SIEM collects and aggregates security logs, but UEBA specifically focuses on behavioral anomalies within those logs.
- C. EDR focuses on detecting and responding to threats on endpoints (e.g., laptops, servers).
- D. IAM manages user identities and access rights, but doesn't primarily detect behavioral anomalies.
User and Entity Behavior Analytics (UEBA)
A security solution that uses machine learning and analytics to detect anomalies in user and entity behavior, indicating potential threats.
- Identifies insider threats and compromised accounts.
- Analyzes patterns like login times, access locations, data usage.
- Goes beyond signature-based detection.
Memory trick: UEBA watches for unusual user actions.