Microsoft Security, Compliance, and Identity Fundamentals (SC-900)Describe the concepts of security, compliance, and identityMedium
A security architect is designing a system that must detect and respond to unusual activities, such as an employee attempting to access a sensitive database outside of their normal working hours from an unfamiliar location. Which security technology is designed for this type of behavioral analysis?
- AIntrusion Prevention System (IPS)
- BUser and Entity Behavior Analytics (UEBA)
- CData Loss Prevention (DLP)
- DSecurity Information and Event Management (SIEM)
Show answer & explanationAnswer & explanation
Correct answer: B. User and Entity Behavior Analytics (UEBA)
UEBA specifically analyzes behavioral patterns of users and entities to detect anomalies that may indicate insider threats or compromised accounts, directly addressing the scenario described.
Why the other options are wrong
- A. IPS primarily focuses on signature-based or anomaly-based detection of network intrusions, not user behavior.
- C. DLP focuses on preventing sensitive data from leaving the organization, not detecting behavioral anomalies.
- D. SIEM aggregates logs but doesn't inherently perform advanced behavioral analytics like UEBA.
User and Entity Behavior Analytics (UEBA)
A security solution that uses machine learning and algorithms to analyze user and entity behavior patterns, identifying anomalies that could indicate a threat.
- Detects insider threats and compromised accounts.
- Establishes a baseline of normal behavior.
- Integrates with SIEM systems to provide enhanced threat detection.
Memory trick: UEBA watches for unusual U-sers and E-ntities