|
所在平台: Udemy |
课程主页: https://www.udemy.com/course/microsoft-defender-for-endpoint-course-with-hands-on-sims/
课程评论:没有评论
课程名称:Microsoft Defender for Endpoint 实践课程 课程概述:本课程旨在提供超越一般Udemy课程的培训体验,教授Microsoft Defender for Endpoint的相关知识。课程由一名拥有超过20年经验的讲师授课,他培训过数千名学生,并且是认证的Microsoft培训师。课程以简明易懂的方式讲解概念,适合初学者。课程包含讲师指导的实践环节和模拟,适合有或没有经验的人参加。 课程内容包括: 1. 课程简介和欢迎信息 2. 理解Microsoft 365和Azure环境 3. Active Directory域的基础知识 4. 远程访问服务(RAS)、非军事区(DMZ)和虚拟化的基础知识 5. Microsoft云服务的基础知识 6. 设定实践操作的准备,创建试用帐户并设置虚拟机 7. 设备管理概念与Microsoft Entra的介绍 8. 端点安全和Microsoft Defender for Endpoint的基础知识 9. Microsoft 365 Defender门户和Microsoft Intune的关系 10. Defender for Endpoint的设置,包括设备发现和漏洞管理 11. 配置和政策管理,包括端点安全策略及下一代保护 12. 数据丢失防护(DLP)概念及配置 13. 自动化调查和修复(AIR)的实施 14. Kusto查询语言(KQL)的基础和应用 课程最终将颁发完成证书,确保学员掌握Microsoft Defender for Endpoint的实用技能,通过理论和实践的结合,提升网络安全防护能力。
We really hope you'll agree, this training is way more than the average course on Udemy! Have access to the following:Training from an instructor of over 20 years who has trained thousands of people and also a Microsoft Certified TrainerLecture that explains the concepts in an easy to learn method for someone that is just starting out with this materialInstructor led hands on and simulations to practice that can be followed even if you have little to no experienceTOPICS COVERED INCLUDING HANDS ON LECTURE AND PRACTICE TUTORIALS:IntroductionWelcome to the course!Understanding the Microsoft 365 and Azure EnvironmentA Solid Foundation of Active Directory DomainsA Solid Foundation of RAS, DMZ, and VirtualizationA Solid Foundation of the Microsoft Cloud ServicesIMPORTANT Using Assignments in the courseQuestions for John ChristopherCertificate of CompletionSetting up for hands onDONT SKIP: Before beginning your account setupCreating a trial Microsoft 365/Azure AccountUsing a Hyper-V virtual machine or an Azure virtual machineSetting up an Azure virtual machine for hands onHYPER-V: Getting Hyper-V Installed on WindowsHYPER-V: Creating a Virtual Switch in Hyper-VHYPER-V: Downloading the Windows 11 ISOHYPER-V: Installing a Windows 11 virtual machineDevice management support with Microsoft EntraOverview of device management of Microsoft device managements conceptsRegistering devices vs joining devices with Microsoft EntraConfiguring Microsoft Entra for device managementJoining our virtual machine to Microsoft EntraIntroduction to Endpoint Security & Microsoft Defender for EndpointWhat is Endpoint Security?High level overview of Microsoft Defender for EndpointLicensing and Plan Comparison (P1 vs P2)Microsoft 365 Defender Portal TourHow Defender for Endpoint relates to Microsoft IntuneIntroduction to Microsoft Intune for device managementSetting Up Defender for EndpointPrerequisites and Supported Operating SystemsCreating a Microsoft Defender Admin role for permissionsOnboarding a Windows device to Defender for EndpointMass automatic onboarding with Microsoft IntuneVerifying Windows devices have been onboardedImplementing device discoveryDefender for Endpoint Vulnerability ManagementWhat are Common Vulnerabilities and Exposures (CVEs)?Inspecting vulnerabilities on a specific deviceUsing the vulnerability management dashboard for high level overviewImproving security with the help of vulnerability recommendationsUtilizing remediation within vulnerability managementCreating and managing Device Groups for Defender for EndpointConfiguration and Policy ManagementHardening endpoint security by using Endpoint Security PoliciesAttack Surface Reduction (ASR) RulesWhat is Next-Gen Protection with Microsoft Defender for Endpoint?Understanding the local anti-virus settings on Windows 11Implementing Next-Gen Protection for devicesUnderstanding the local Defender Firewall settings on Windows 11Implementing Firewall Rule Policies using Defender for EndpointUsing Security Baselines in securing our devicesUtilizing Microsoft Purview Endpoint DLP (Data Loss Prevention)Understanding the concepts of DLP (Data Loss Prevention)Considering device requirements before using Endpoint DLPSettings for configuring Endpoint DLPConfiguring DLP policies with advanced rulesEnabling just-in-time (JIT) protectionHow to monitor for endpoint activitiesIncident Response and InvestigationWhat is Automated Investigation and Remediation (AIR)?Implementing Automated Investigation and Remediation (AIR) within device groupsTriggering incidents using a client device for testingInvestigating incidents generated by Defender managed devicesViewing alerts generated by Defender managed devicesManaging and classifying detected alertsKusto Query Language (KQL)What is Kusto Query Language (KQL)?Using the Microsoft KQL Demo environment, downloading resource materials and AIBasic KQL syntax for searching for informationSummarizing KQL results and filtering based on time rangesControlling KQL data displayed based on columns, amounts and charactersUsing KQL variables and combining output dataRunning Threat Hunting Queries with Advanced Hunting (KQL)Utilizing Microsoft's Sentinel and Defender repository of premade KQL Queries