Study workspace

Prepare for SC-200 with a reference that remembers your progress.

All nine learning paths now run in the new architecture. Select one to reveal its brief and modules.

09 / 09

Choose a learning path

0/404 units
07Create detections and perform investigations using Microsoft Sentinel8 modules · 56 units · Analytics, automation, playbooks, incidents, UEBA, ASIM, workbooks, and content management0/56 units complete
Learning path 07 · Create detections and perform investigations using Microsoft Sentinel

8 modules · 56 units · Analytics, automation, playbooks, incidents, UEBA, ASIM, workbooks, and content management

0%

Study focus

Detection and response

Build analytics rules, automate triage, run playbooks, and manage security incidents.

Analytics and content

Apply UEBA, ASIM, KQL, workbooks, Content Hub solutions, and repository-based deployment.

8 modules · 56 units

Select one or more modules

Each click adds or removes a module from your workspace. Units remain closed until you open them.

05

Module 5

Identify threats with Behavioral Analytics

Focus: UEBA baselines, entities, timelines, behavioral insights, investigation priority, and anomalies.
0/7
01 / 07Introduction

User and Entity Behavior Analytics adds behavioral context to users, hosts, IPs, applications, and other entities so analysts can prioritize activity that static rules may miss.

Official moduleUEBA objectives
02 / 07Understand behavioral analytics

Sentinel builds baselines from entity history, peer groups, organization behavior, time, location, devices, and environments. ML adds anomalous context, sensitivity, relationships, and potential blast radius. The 0-10 investigation priority score is a prioritization signal, not proof of compromise.

Official lessonBaselines and scoring
03 / 07Explore entities

Sentinel merges identifiers such as GUID, UPN, account name, and domain when enough context exists. Entity pages combine identifying facts, a timeline of alerts, bookmarks and activities, and behavioral insights from sign-in, audit, Office, Syslog, SecurityEvent, and BehaviorAnalytics data.

Official lessonEntity identity and timelines
04 / 07Display entity behavior information

Search entities and review risk context, activity trends, peers, related alerts, and anomalies. Pivot from incidents or hunting results into the same entity view to keep investigation context connected.

Official lessonEntity behavior views
05 / 07Use Anomaly detection analytical rule templates

Anomaly templates use Microsoft-managed ML. Review required sources, anomaly details, contributing events, and entity context; combine anomaly evidence with other signals instead of treating it as a verdict.

Official lessonManaged anomaly detections
06 / 07Module assessment

Review baselines, peer comparison, priority scoring, entity identifiers and merging, entity pages, timelines, insights, and anomaly interpretation.

Official assessmentBehavioral analytics knowledge check
07 / 07Summary and resources

UEBA depends on complete telemetry, correct entity mapping, and analyst validation of anomalous context.

Official moduleSummary and resources
End of learning pathCreate detections and perform investigations using Microsoft Sentinel