SC-200T00 Microsoft Security Operations Analyst

Duration: 4 days Dates:

Learn how to hunt for threats, respond to them and take countermeasures using Microsoft Azure Sentinel, Azure Defender and Microsoft 365 Defender. In this course, you will learn how to mitigate cyberthreats using these technologies. In particular, you will configure and use Azure Sentinel and Kusto Query Language (KQL) to perform detection, analysis and reporting.

  • Mitigating threats with Microsoft Defender for Endpoint
    • Protection against threats
    • Deploying the environment
    • Implementing Windows 10 security enhancements with
    • Managing alerts and incidents
    • Performing device investigations
    • Performing actions on a device
    • Performing evidence and entity investigations
    • Configuring and managing automation
    • Configuring alerts and detections
    • Threat and vulnerability management
  • Mitigating threats with Microsoft 365 Defender
    • Introduction to threat protection with Microsoft 365
    • Mitigating incidents
    • Protecting identities with Azure AD Identity Protection
    • Remediating risks with Microsoft Defender for Office 365
    • Securing the environment
    • Securing cloud apps and services with Microsoft Cloud App Security
    • Responding to data loss prevention alerts
    • Managing insider risk
  • Defending against threats with Azure Defender
    • Planning cloud workload protection measures
    • Explaining cloud workload protection
    • Connecting Azure resources
    • Connecting non-Azure resources
    • Remediating security alerts
  • Creating queries for Azure Sentinel with Kusto Query Language (KQL)
    • Constructing KQL statements for Azure Sentinel
    • Analysing query results with KQL
    • Creating multi-table statements with KQL
    • Working with data in Azure Sentinel using Kusto Query Language
  • Configuring your Azure Sentinel environment
    • Introduction to Azure Sentinel
    • Creating and managing workspaces
    • Querying logs
    • Using watchlists
    • Using threat intelligence
  • Connecting logs to Azure Sentinel
    • Connecting data using data connectors
    • Connecting Microsoft services
    • Connecting to Microsoft 365 Defender
    • Connecting Windows hosts
    • Connecting Common Event Format logs
    • Connecting Syslog data sources
    • Connecting threat indicators
  • Creating detections and performing investigations with Azure Sentinel
    • Detecting threats with Azure Sentinel analytics
    • Responding to threats with Azure Sentinel playbooks
    • Managing security incidents
    • Using entity behaviour analytics
    • Querying, visualising and monitoring data
  • Performing threat hunting in Azure Sentinel
    • Threat hunting
    • Threat hunting using notebooks
Learning Solution

Blended Learning, Firmenseminar, Individualcoaching, Klassenraumtraining, Online Live Webinar

Language

Deutsch, Englisch, Französisch, Italienisch

Dates

2021/08/23, 2021/10/25, 2021/12/13, flexibel, auf Anfrage

Location

Brüttisellen, Lausanne, flexibel, auf Anfrage

This course is aimed at people working in a security operations job role and helps participants prepare for the SC-200: Microsoft Security Operations Analyst exam.

This role primarily investigates, responds to and hunts for threats using Microsoft Azure Sentinel, Azure Defender, Microsoft 365 Defender and third-party security products. Because the security operations analyst makes use of the operational output of these tools, they are also a key stakeholder in the configuration and deployment of these technologies.

  • Basic understanding of Microsoft 365
  • Basic understanding of Microsoft’s security, compliance and identity products
  • Good understanding of Windows 10
  • Familiarity with Azure services, particularly Azure SQL Database and Azure Storage
  • Familiarity with virtual machines and virtual networks in Azure
  • Basic understanding of scripting concepts

Price range: CHF3'300 through CHF12'000 excl. VAT

Clear

SIGN UP

Newsletter

Receive news about new courses, offers and promotions by email.

← Back

Thank you for your response. ✨

Email Subscription
Amazon
VMware and Virtualisation