|
所在平台: Udemy |
课程主页: https://www.udemy.com/course/az-500-practice-test-latest/
课程评论:没有评论
课程名称:AZ-500 实践测试 - 最新版(2023) 概述:本课程基于微软最新的考试资料和题库,专为希望深入了解Azure安全工程的考生设计。课程涵盖Azure、混合云和多云环境中的安全资源管理与监控,帮助考生理解考试格式与内容。Azure安全工程师负责管理安全态势、识别和修复漏洞、进行威胁建模及实施威胁保护,并可能参与安全事件响应。他们需要与架构师、管理员和开发者紧密合作,以规划和实施符合安全与合规要求的解决方案。 目标受众:该课程面向Azure安全工程师,他们在Azure环境和混合环境中实施、管理和监控安全资源。参与者需拥有Microsoft Azure的实际管理经验,熟悉计算、网络和存储,并具备Azure Active Directory及Microsoft Entra的相关知识。 课程内容包括: 1. 身份和访问管理(25-30%) - 管理Azure AD身份 - 实施多因素认证 - 配置Microsoft Entra验证ID - 管理Azure AD角色权限 2. 安全网络(20-25%) - 规划和实施虚拟网络安全 - 配置应用安全组和网络安全组 - 实施虚拟专用网络的安全连接 3. 安全计算、存储和数据库(20-25%) - 实施计算高级安全 - 配置存储账户安全及加密 - 确保Azure SQL数据库的安全 4. 管理安全操作(25-30%) - 规划和实施安全治理 - 配置Azure Policy和安全蓝图 - 使用Microsoft Defender for Cloud管理安全态势 该课程不仅帮助考生准备AZ-500考试,还为其提供实用的Azure安全工程技术知识,以提升其在实际工作中的能力和效率。通过练习题集,考生将更好地理解考试的形式和内容,并为日后的安全工程师职业生涯做好准备。
These Practice question sets is developed based on the inputs and Microsoft Latest dumps. Consider this module as a practice test to get clear understanding on the format.Candidates for this exam implement, manage, and monitor security for resources in Azure, multi-cloud, and hybrid environments as part of an end-to-end infrastructure. They recommend security components and configurations to protect identity & access, data, applications, and networks.Responsibilities for an Azure security engineer include managing the security posture, identifying and remediating vulnerabilities, performing threat modelling, and implementing threat protection. They may also participate in responding to security incidents.Azure security engineers work with architects, administrators, and developers to plan and implement solutions that meet security and compliance requirements.The Azure security engineer should have practical experience in administration of Microsoft Azure and hybrid environments. The Azure security engineer should have a strong familiarity with compute, network, and storage in Azure, as well as Azure Active Directory, part of Microsoft Entra.Audience profileThe Azure Security Engineer implements, manages, and monitors security for resources in Azure, multi-cloud, and hybrid environments as part of an end-to-end infrastructure. They recommend security components and configurations to protect identity & access, data, applications, and networks.Responsibilities for an Azure Security Engineer include managing the security posture, identifying and remediating vulnerabilities, performing threat modelling, and implementing threat protection. They may also participate in responding to security incidents.Azure Security Engineers work with architects, administrators, and developers to plan and implement solutions that meet security and compliance requirements.The Azure Security Engineer should have practical experience in administration of Microsoft Azure and hybrid environments. The Azure Security Engineer should have a strong familiarity with compute, network, and storage in Azure, as well as Azure Active Directory, part of Microsoft Entra.Manage identity and access (25-30%)Secure networking (20-25%)Secure compute, storage, and databases (20-25%)Manage security operations (25-30%)AZ-500 - Skills Measured - Manage identity and access (25-30%)Manage identities in Azure ADSecure users in Azure ADSecure directory groups in Azure ADRecommend when to use external identitiesSecure external identitiesImplement Azure AD Identity ProtectionManage authentication by using Azure ADConfigure Microsoft Entra Verified IDImplement multi-factor authentication (MFA)Implement passwordless authenticationImplement password protectionImplement single sign-on (SSO)Integrate single sign on (SSO) and identity providersRecommend and enforce modern authentication protocolsManage authorization by using Azure ADConfigure Azure role permissions for management groups, subscriptions, resource groups, and resourcesAssign built-in roles in Azure ADAssign built-in roles in AzureCreate and assign custom roles, including Azure roles and Azure AD rolesImplement and manage Microsoft Entra Permissions ManagementConfigure Azure AD Privileged Identity Management (PIM)Configure role management and access reviews by using Microsoft Entra Identity GovernanceImplement Conditional Access policiesManage application access in Azure ADManage access to enterprise applications in Azure AD, including OAuth permission grantsManage app registrations in Azure ADConfigure app registration permission scopesManage app registration permission consentManage and use service principalsManage managed identities for Azure resourcesRecommend when to use and configure an Azure AD Application Proxy, including authenticationSecure networking (20-25%)Plan and implement security for virtual networksPlan and implement Network Security Groups (NSGs) and Application Security Groups (ASGs)Plan and implement user-defined routes (UDRs)Plan and implement VNET peering or VPN gatewayPlan and implement Virtual WAN, including secured virtual hubSecure VPN connectivity, including point-to-site and site-to-siteImplement encryption over ExpressRouteConfigure firewall settings on PaaS resourcesMonitor network security by using Network Watcher, including NSG flow loggingPlan and implement security for private access to Azure resourcesPlan and implement virtual network Service EndpointsPlan and implement Private EndpointsPlan and implement Private Link servicesPlan and implement network integration for Azure App Service and Azure FunctionsPlan and implement network security configurations for an App Service Environment (ASE)Plan and implement network security configurations for an Azure SQL Managed InstancePlan and implement security for public access to Azure resourcesPlan and implement TLS to applications, including Azure App Service and API ManagementPlan, implement, and manage an Azure Firewall, including Azure Firewall Manager and firewall policiesPlan and implement an Azure Application GatewayPlan and implement an Azure Front Door, including Content Delivery Network (CDN)Plan and implement a Web Application Firewall (WAF)Recommend when to use Azure DDoS Protection StandardSecure compute, storage, and databases (20-25%)Plan and implement advanced security for computePlan and implement remote access to public endpoints, including Azure Bastion and JITConfigure network isolation for Azure Kubernetes Service (AKS)Secure and monitor AKSConfigure authentication for AKSConfigure security monitoring for Azure Container Instances (ACIs)Configure security monitoring for Azure Container Apps (ACAs)Manage access to Azure Container Registry (ACR)Configure disk encryption, including Azure Disk Encryption (ADE), encryption as host, and confidential disk encryptionRecommend security configurations for Azure API ManagementPlan and implement security for storageConfigure access control for storage accountsManage life cycle for storage account access keysSelect and configure an appropriate method for access to Azure FilesSelect and configure an appropriate method for access to Azure Blob StorageSelect and configure an appropriate method for access to Azure TablesSelect and configure an appropriate method for access to Azure QueuesSelect and configure appropriate methods for protecting against data security threats, including soft delete, backups, versioning, and immutable storageConfigure Bring your own key (BYOK)Enable double encryption at the Azure Storage infrastructure levelPlan and implement security for Azure SQL Database and Azure SQL Managed InstanceEnable database authentication by using Microsoft Azure ADEnable database auditingIdentify use cases for the Microsoft Purview governance portalImplement data classification of sensitive information by using the Microsoft Purview governance portalPlan and implement dynamic maskingImplement Transparent Database Encryption (TDE)Recommend when to use Azure SQL Database Always EncryptedManage security operations (25-30%)Plan, implement, and manage governance for securityCreate, assign, and interpret security policies and initiatives in Azure PolicyConfigure security settings by using Azure BlueprintDeploy secure infrastructures by using a landing zoneCreate and configure an Azure Key VaultRecommend when to use a Dedicated HSMConfigure access to Key Vault, including vault access policies and Azure Role Based Access ControlManage certificates, secrets, and keysConfigure key rotationConfigure backup and recovery of certificates, secrets, and keysManage security posture by using Microsoft Defender for CloudIdentify and remediate security risks by using the Microsoft Defender for Cloud Secure Score and InventoryAssess compliance against security frameworks and Microsoft Defender for CloudAdd industry and regulatory standards to Microsoft Defender for CloudAdd custom initiatives to Microsoft Defender for CloudConnect hybrid cloud and multi-cloud environments to Microsoft Defender for CloudIdentify and monitor external assets by using Microsoft Defender External Attack Surface ManagementConfigure and manage threat protection by using Microsoft Defender for CloudEnable workload protection services in Microsoft Defender for Cloud, including Microsoft Defender for Storage, Databases, Containers, App Service, Key Vault, Resource Manager, and DNSConfigure Microsoft Defender for ServersConfigure Microsoft Defender for Azure SQL DatabaseManage and respond to security alerts in Microsoft Defender for CloudConfigure workflow automation by using Microsoft Defender for CloudEvaluate vulnerability scans from Microsoft Defender for ServerConfigure and manage security monitoring and automation solutionsMonitor security events by using Azure MonitorConfigure data connectors in Microsoft SentinelCreate and customize analytics rules in Microsoft SentinelEvaluate alerts and incidents in Microsoft SentinelConfigure automation in Microsoft SentinelMS-500 - Candidates for this exam have functional experience with Microsoft 365 workloads and with Microsoft Azure Active Directory (Azure AD), part of Microsoft Entra. They have implemented security for Microsoft 365 environments, including hybrid environments. They have a working knowledge of Windows clients, Windows servers, Active Directory, and PowerShell.Implement and manage identity and access (25-30%)Implement and manage threat protection (30-35%)Implement and manage information protection (15-20%)Manage compliance in Microsoft 365 (20-25%)Implement and manage identity and access (25-30%)Plan and implement identity and access for Microsoft 365 hybrid environmentsChoose an authentication method to connect to a hybrid environmentPlan and implement pass-through authentication and password hash syncPlan and implement Azure AD synchronization for hybrid environmentsMonitor and troubleshoot Azure AD Connect eventsPlan and implement identities in Azure ADImplement Azure AD group membershipImplement password management, including self-service password reset and Azure AD Password ProtectionManage external identities in Azure AD and Microsoft 365 workloadsPlan and implement roles and role groupsAudit Azure ADImplement authentication methodsImplement multi-factor authentication (MFA) by using conditional access policiesManage and monitor MFAPlan and implement Windows Hello for Business, FIDO, and password less authenticationPlan and implement conditional accessPlan and implement conditional access policiesPlan and implement device compliance policiesTest and troubleshoot conditional access policiesConfigure and manage identity governanceImplement Azure AD Privileged Identity ManagementImplement and manage entitlement managementImplement and manage access reviewsImplement Azure AD Identity ProtectionImplement user risk policyImplement sign-in risk policyConfigure Identity Protection alertsReview and respond to risk eventsImplement and manage threat protection (30-35%)Secure identity by using Microsoft Defender for IdentityPlan a Microsoft Defender for Identity solutionInstall and configure Microsoft Defender for IdentityManage and monitor Microsoft Defender for IdentitySecure scoreAnalyze identity-related threats and risks identified in Microsoft 365 DefenderSecure endpoints by using Microsoft Defender for EndpointPlan a Microsoft Defender for Endpoint solutionImplement Microsoft Defender for EndpointManage and monitor Microsoft Defender for EndpointAnalyze and remediate threats and risks to endpoints identified in Microsoft 365 DefenderSecure endpoints by using Microsoft Endpoint ManagerPlan for device and application protectionConfigure and manage Microsoft Defender Application GuardConfigure and manage Windows Defender Application ControlConfigure and manage exploit protectionConfigure and manage device encryptionConfigure and manage application protection policiesMonitor and manage device security status using Microsoft Endpoint Manager admin centerAnalyze and remediate threats and risks to endpoints identified in Microsoft Endpoint ManagerSecure collaboration by using Microsoft Defender for Office 365Plan a Microsoft Defender for Office 365 solutionConfigure Microsoft Defender for Office 365Monitor for threats by using Microsoft Defender for Office 365Analyze and remediate threats and risks to collaboration workloads identified in Microsoft 365 DefenderConduct simulated attacks by using Attack simulation trainingDetect and respond to threats in Microsoft 365 by using Microsoft SentinelPlan a Microsoft Sentinel solution for Microsoft 365Implement and configure Microsoft Sentinel for Microsoft 365Manage and monitor Microsoft 365 security by using Microsoft SentinelRespond to threats using built-in playbooks in Microsoft SentinelSecure connections to cloud apps by using Microsoft Defender for Cloud AppsPlan Microsoft Defender for Cloud Apps implementationConfigure Microsoft Defender for Cloud AppsManage cloud app discoveryManage entries in the Microsoft Defender for Cloud Apps catalogManage apps in Microsoft Defender for Cloud AppsConfigure Microsoft Defender for Cloud Apps connectors and OAuth appsConfigure Microsoft Defender for Cloud Apps policies and templatesAnalyze and remediate threats and risks relating to cloud app connections identified in Microsoft 365 DefenderManage App governance in Microsoft Defender for Cloud AppsImplement and manage information protection (15-20%)Manage sensitive informationPlan a sensitivity label solutionCreate and manage sensitive information typesConfigure sensitivity labels and policiesPublish sensitivity labels to Microsoft 365 workloadsMonitor data classification and label usage by using Content explorer and Activity explorerApply labels to files and schematized data assets in Microsoft Purview Data MapImplement and manage Microsoft Purview Data Loss Prevention (DLP)Plan a DLP solutionCreate and manage DLP policies for Microsoft 365 workloadsImplement and manage Endpoint DLPMonitor DLPRespond to DLP alerts and notificationsPlan and implement Microsoft Purview Data lifecycle managementPlan for data lifecycle managementReview and interpret data lifecycle management reports and dashboardsConfigure retention labels, policies, and label policiesPlan and implement adaptive scopesConfigure retention in Microsoft 365 workloadsFind and recover deleted Office 365 dataManage compliance in Microsoft 365 (20-25%)Manage and analyze audit logs and reports in Microsoft PurviewPlan for auditing and reportingInvestigate compliance activities by using audit logsReview and interpret compliance reports and dashboardsConfigure alert policiesConfigure audit retention policiesPlan for, conduct, and manage eDiscovery casesRecommend eDiscovery Standard or PremiumPlan for content search and eDiscoveryDelegate permissions to use search and discovery toolsUse search and investigation tools to discover and respondManage eDiscovery casesManage regulatory and privacy requirementsPlan for regulatory compliance in Microsoft 365Manage regulatory compliance in the Microsoft Purview Compliance ManagerImplement privacy risk management in Microsoft PrivaImplement and manage Subject Rights Requests in Microsoft PrivaManage insider risk solutions in Microsoft 365Implement and manage Customer LockboxImplement and manage Communication compliance policiesImplement and manage Insider risk management policiesImplement and manage Information barrier policiesImplement and manage Privileged access management