|
所在平台: Udemy |
课程主页: https://www.udemy.com/course/microsoft-az-500-azure-security-engineer-associate/
课程评论:没有评论
课程名称:AZ-500:Microsoft Azure安全工程师助理 概述:本课程由Christopher Nett主讲,是一门精心编排的Udemy课程,专为旨在通过Microsoft AZ-500:Microsoft Azure安全工程师助理考试的IT专业人士设计。课程系统地从基础知识引导学生到Azure安全的高级概念。掌握Azure安全将帮助您在当今网络安全环境中的重要主题上发展专业技能。课程始终与微软最新的学习指南和考试目标保持一致,内容覆盖以下主要领域: 1. **身份和访问管理(25-30%)**: - 管理Microsoft Entra身份 - 保护用户和组,实施多因素认证(MFA) - 配置单一登录(SSO)及身份提供商的集成 - 管理和配置Microsoft Entra权限管理及条件访问政策 2. **网络安全(20-25%)**: - 计划和实施虚拟网络的安全性 - 配置网络安全组(NSGs)和应用安全组(ASGs) - 实施VPN连接及加密,监控网络安全 3. **计算、存储和数据库的安全性(20-25%)**: - 计划和实施计算的高级安全性 - 配置存储的访问控制及数据安全防护 - 管理Azure SQL数据库的安全性及审计 4. **安全操作管理(25-30%)**: - 计划和管理安全治理 - 创建和配置Azure Key Vault - 采用Microsoft Defender for Cloud进行安全监控和风险管理 通过本课程,您将获得通过AZ-500考试所需的全面知识和技能,掌握最新的安全技术和最佳实践,从而在网络安全领域建立信心与专业能力。
This AZ-500 course by Christopher Nett is a meticulously organized Udemy course designed for IT professionals aiming to pass the Microsoft AZ-500: Microsoft Azure Security Engineer Associate exam. This course systematically guides you from the basics to advanced concepts of Azure Security.By mastering Azure Security, you're developing expertise in essential topics in today's cybersecurity landscape.The course is always aligned with Microsoft's latest study guide and exam objectives:Manage identity and access (25-30%)Manage Microsoft Entra identitiesSecure Microsoft Entra usersSecure Microsoft Entra groupsRecommend when to use external identitiesSecure external identitiesImplement Microsoft Entra ID ProtectionManage Microsoft Entra authenticationImplement multi-factor authentication (MFA)Configure Microsoft Entra Verified IDImplement passwordless authenticationImplement password protectionImplement single sign-on (SSO)Integrate single sign on (SSO) and identity providersRecommend and enforce modern authentication methodsManage Microsoft Entra authorizationConfigure Azure role permissions for management groups, subscriptions, resource groups, and resourcesAssign Microsoft Entra built-in rolesAssign Azure built-in rolesCreate and assign custom roles, including Azure roles and Microsoft Entra rolesImplement and manage Microsoft Entra Permissions ManagementConfigure Microsoft Entra Privileged Identity ManagementConfigure role management and access reviews in Microsoft EntraImplement Conditional Access policiesManage Microsoft Entra application accessManage access to enterprise applications in Microsoft Entra ID, including OAuth permission grantsManage Microsoft Entra app registrationsConfigure app registration permission scopesManage app registration permission consentManage and use service principalsManage managed identities for Azure resourcesRecommend when to use and configure an Microsoft Entra Application Proxy, including authenticationSecure networking (20-25%)Plan and implement security for virtual networksPlan and implement Network Security Groups (NSGs) and Application Security Groups (ASGs)Plan and implement user-defined routes (UDRs)Plan and implement Virtual Network peering or VPN gatewayPlan and implement Virtual WAN, including secured virtual hubSecure VPN connectivity, including point-to-site and site-to-siteImplement encryption over ExpressRouteConfigure firewall settings on PaaS resourcesMonitor network security by using Network Watcher, including NSG flow loggingPlan and implement security for private access to Azure resourcesPlan and implement virtual network Service EndpointsPlan and implement Private EndpointsPlan and implement Private Link servicesPlan and implement network integration for Azure App Service and Azure FunctionsPlan and implement network security configurations for an App Service Environment (ASE)Plan and implement network security configurations for an Azure SQL Managed InstancePlan and implement security for public access to Azure resourcesPlan and implement Transport Layer Security (TLS) to applications, including Azure App Service and API ManagementPlan, implement, and manage an Azure Firewall, including Azure Firewall Manager and firewall policiesPlan and implement an Azure Application GatewayPlan and implement an Azure Front Door, including Content Delivery Network (CDN)Plan and implement a Web Application Firewall (WAF)Recommend when to use Azure DDoS Protection StandardSecure compute, storage, and databases (20-25%)Plan and implement advanced security for computePlan and implement remote access to public endpoints, including Azure Bastion and just-in-time (JIT) virtual machine Configure disk encryption, including Azure Disk Encryption (ADE), encryption at host, and confidential disk encryptionRecommend security configurations for Azure API ManagementPlan and implement security for storageConfigure access control for storage accountsManage life cycle for storage account access keysSelect and configure an appropriate method for access to Azure FilesSelect and configure an appropriate method for access to Azure Blob StorageSelect and configure an appropriate method for access to Azure TablesSelect and configure an appropriate method for access to Azure QueuesSelect and configure appropriate methods for protecting against data security threats, including soft delete, backups, versioning, and immutable storageConfigure Bring your own key (BYOK)Enable double encryption at the Azure Storage infrastructure levelPlan and implement security for Azure SQL Database and Azure SQL Managed InstanceEnable Microsoft Entra database authenticationEnable database auditingIdentify use cases for the Microsoft Purview governance portalImplement data classification of sensitive information by using the Microsoft Purview governance portalPlan and implement dynamic maskingImplement Transparent Data Encryption (TDE)Recommend when to use Azure SQL Database Always EncryptedManage security operations (25-30%)Plan, implement, and manage governance for securityCreate, assign, and interpret security policies and initiatives in Azure PolicyConfigure security settings by using Azure BlueprintsDeploy secure infrastructures by using a landing zoneCreate and configure an Azure Key VaultRecommend when to use a dedicated Hardware Security Module (HSM)Configure access to Key Vault, including vault access policies and Azure Role Based Access ControlManage certificates, secrets, and keysConfigure key rotationConfigure backup and recovery of certificates, secrets, and keysManage security posture by using Microsoft Defender for CloudIdentify and remediate security risks by using the Microsoft Defender for Cloud Secure Score and InventoryAssess compliance against security frameworks by using Microsoft Defender for CloudAdd industry and regulatory standards to Microsoft Defender for CloudAdd custom initiatives to Microsoft Defender for CloudConnect hybrid cloud and multi-cloud environments to Microsoft Defender for CloudIdentify and monitor external assets by using Microsoft Defender External Attack Surface ManagementConfigure and manage threat protection by using Microsoft Defender for CloudEnable workload protection services in Microsoft Defender for Cloud, including Microsoft Defender for Storage, Databases, Containers, App Service, Key Vault, and Resource ManagerConfigure Microsoft Defender for ServersConfigure Microsoft Defender for Azure SQL DatabaseManage and respond to security alerts in Microsoft Defender for CloudConfigure workflow automation by using Microsoft Defender for CloudEvaluate vulnerability scans from Microsoft Defender for ServerConfigure and manage security monitoring and automation solutionsMonitor security events by using Azure MonitorConfigure data connectors in Microsoft SentinelCreate and customize analytics rules in Microsoft SentinelEvaluate alerts and incidents in Microsoft SentinelConfigure automation in Microsoft Sentinel