AZ-500: Microsoft Azure Security Technologies - May 2025

所在平台: Udemy

课程主页: https://www.udemy.com/course/ms-az-500/

课程评论:没有评论

第一个写评论        关注课程

课程简介

课程名称:AZ-500:Microsoft Azure安全技术 - 2025年5月 课程概述: 本课程旨在帮助学员掌握Microsoft Azure环境中的安全技术,涵盖内容主要包括四大模块:安全身份与访问、安全网络、安全计算、存储和数据库,以及使用Microsoft Defender for Cloud与Microsoft Sentinel进行安全保护。 1. **安全身份与访问(15-20%)**:教授如何管理身份和访问的安全控制,包括Azure内置角色分配、自定义角色的管理、实施多重身份验证(MFA)、条件访问策略等。此外,还包括管理企业应用访问及服务主体的使用。 2. **安全网络(20-25%)**:内容包括虚拟网络的安全计划与实施、网络安全组和应用安全组的管理、VPN连接的安全保障、Azure防火墙的配置与管理等,确保网络架构的安全性和高效性。 3. **安全计算、存储和数据库(20-25%)**:学习如何为计算资源实施高级安全措施,包括虚拟机的远程访问、Kubernetes服务的安全监控、存储账号的访问控制、Azure SQL数据库的安全性提升等。 4. **使用Microsoft Defender for Cloud与Microsoft Sentinel进行安全保障(30-35%)**:教授如何实施和管理云治理政策、配置Azure Key Vault、管理安全风险、监控合规性,以及使用Microsoft Defender和Microsoft Sentinel进行威胁保护和自动化安全监控。 课程特别强调实用技能的培养,旨在使学员能够有效管理和保护Azure环境中的各种资源,确保其安全合规性。通过本课程的学习,学员将获得在Microsoft Azure上实施和管理安全策略的全面知识与实践经验。

课程评论(0条)

课程详情

Skills at a glanceSecure identity and access (15-20%)Secure networking (20-25%)Secure compute, storage, and databases (20-25%)Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel (30-35%)Secure identity and access (15-20%)Manage security controls for identity and accessManage Azure built-in role assignmentsManage custom roles, including Azure roles and Microsoft Entra rolesImplement and manage Microsoft Entra Permissions ManagementPlan and manage Azure resources in Microsoft Entra Privileged Identity Management, including settings and assignmentsImplement multi-factor authentication (MFA) for access to Azure resourcesImplement Conditional Access policies for cloud resources in AzureManage Microsoft Entra application accessManage access to enterprise applications in Microsoft Entra ID, including OAuth permission grantsManage Microsoft Entra app registrationsConfigure app registration permission scopesManage app registration permission consentManage and use service principalsManage managed identitiesSecure networking (20-25%)Plan and implement security for virtual networksPlan and implement Network Security Groups (NSGs) and Application Security Groups (ASGs)Manage virtual networks by using Azure Virtual Network ManagerPlan and implement user-defined routes (UDRs)Plan and implement Virtual Network peering or VPN gatewayPlan and implement Virtual WAN, including secured virtual hubSecure VPN connectivity, including point-to-site and site-to-siteImplement encryption over ExpressRouteConfigure firewall settings on Azure resourcesMonitor network security by using Network WatcherPlan and implement security for private access to Azure resourcesPlan and implement virtual network Service EndpointsPlan and implement Private EndpointsPlan and implement Private Link servicesPlan and implement network integration for Azure App Service and Azure FunctionsPlan and implement network security configurations for an App Service Environment (ASE)Plan and implement network security configurations for an Azure SQL Managed InstancePlan and implement security for public access to Azure resourcesPlan and implement Transport Layer Security (TLS) to applications, including Azure App Service and API ManagementPlan, implement, and manage an Azure Firewall, including Azure Firewall Manager and firewall policiesPlan and implement an Azure Application GatewayPlan and implement an Azure Front Door, including Content Delivery Network (CDN)Plan and implement a Web Application Firewall (WAF)Recommend when to use Azure DDoS Protection StandardSecure compute, storage, and databases (20-25%)Plan and implement advanced security for computePlan and implement remote access to virtual machines, including Azure Bastion and just-in-time (JIT)Configure network isolation for Azure Kubernetes Service (AKS)Secure and monitor AKSConfigure authentication for AKSConfigure security monitoring for Azure Container Instances (ACIs)Configure security monitoring for Azure Container Apps (ACAs)Manage access to Azure Container Registry (ACR)Configure disk encryption, including Azure Disk Encryption (ADE), encryption at host, and confidential disk encryptionRecommend security configurations for Azure API ManagementPlan and implement security for storageConfigure access control for storage accountsManage storage account access keysSelect and configure an appropriate method for access to Azure FilesSelect and configure an appropriate method for access to Azure Blob StorageSelect and configure appropriate methods for protecting against data security threats, including soft delete, backups, versioning, and immutable storageConfigure Bring your own key (BYOK)Enable double encryption at the Azure Storage infrastructure levelPlan and implement security for Azure SQL Database and Azure SQL Managed InstanceEnable Microsoft Entra database authenticationEnable database auditingPlan and implement dynamic maskingImplement Transparent Data Encryption (TDE)Recommend when to use Azure SQL Database Always EncryptedSecure Azure using Microsoft Defender for Cloud and Microsoft Sentinel (30-35%)Implement and manage enforcement of cloud governance policiesCreate, assign, and interpret policies and initiatives in Azure PolicyConfigure Azure Key Vault network settingsConfigure access to Key Vault, including vault access policies and Azure Role Based Access ControlManage certificates, secrets, and keysConfigure key rotationPerform backup and recovery of certificates, secrets, and keysImplement security controls to protect backupsImplement security controls for asset managementManage security posture by using Microsoft Defender for CloudIdentify and remediate security risks by using the Microsoft Defender for Cloud Secure Score and InventoryAssess compliance against security frameworks by using Microsoft Defender for CloudManage compliance standards in Microsoft Defender for CloudAdd custom standards to Microsoft Defender for CloudConnect hybrid cloud and multi-cloud environments to Microsoft Defender for Cloud, including Amazon Web Services (AWS) and Google Cloud Platform (GCP)Implement and use Microsoft Defender External Attack Surface Management (EASM)Configure and manage threat protection by using Microsoft Defender for CloudEnable workload protection services in Microsoft Defender for CloudConfigure Microsoft Defender for Servers, Microsoft Defender for Databases, and Microsoft Defender for StorageImplement and manage agentless scanning for virtual machines in Microsoft Defender for ServersImplement and manage Microsoft Defender Vulnerability Management for Azure virtual machinesConnect to and configure settings in Microsoft Defender for Cloud Devops Security, including GitHub, Azure DevOps, and GitLabConfigure and manage security monitoring and automation solutionsManage and respond to security alerts in Microsoft Defender for CloudConfigure workflow automation by using Microsoft Defender for CloudMonitor network security events and performance data by configuring data collection rules (DCRs) in Azure MonitorConfigure data connectors in Microsoft SentinelEnable analytics rules in Microsoft SentinelConfigure automation in Microsoft Sentinel

课程标签

0人关注该课程

主题相关的课程