|
所在平台: Udemy |
课程主页: https://www.udemy.com/course/ms_az_500/
课程评论:没有评论
课程名称:Microsoft Azure Security (AZ-500) 考试问题(截至2025年5月) 课程概述: 该课程旨在为学习者提供在 Microsoft Azure 环境中增强安全性的必要技能,内容涵盖多个方面。以下是关键主题的概述: 1. **安全身份和访问(15-20%)** - 管理身份和访问的安全控制 - 实施和管理 Microsoft Entra 权限管理 - 规划和管理 Azure 资源的特权身份管理 - 实施多因素认证(MFA)和条件访问策略 - 管理应用程序访问和服务主体 2. **安全网络(20-25%)** - 规划和实施虚拟网络的安全 - 管理网络安全组(NSG)和应用安全组(ASG) - 规划用户定义的路由、虚拟网络对等和VPN网关 - 实施 Azure 防火墙和网络安全监控 - 规划公共访问和安全的虚拟接入 3. **安全计算、存储和数据库(20-25%)** - 规划和实施高级计算安全 - 进行虚拟机的远程访问配置 - 管理 Azure Kubernetes 服务(AKS)的安全和监控 - 配置存储账户的访问控制和数据安全防护 - 实现 Azure SQL 数据库的透明数据加密(TDE) 4. **使用 Microsoft Defender for Cloud 和 Microsoft Sentinel 加强 Azure 安全(30-35%)** - 实施和管理云治理策略 - 使用 Microsoft Defender for Cloud 识别和修复安全风险 - 连接混合云和多云环境 - 配置 Microsoft Sentinel 中的安全监控和自动化解决方案 课程适合希望提升其在 Azure 环境中安全管理能力的学习者,帮助他们准备 AZ-500 考试。课程内容涵盖了从身份管理到网络安全、计算和存储安全,以及如何使用微软的安全工具来保护云环境的各个方面。
Skills at a glanceSecure identity and access (15-20%)Secure networking (20-25%)Secure compute, storage, and databases (20-25%)Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel (30-35%)Secure identity and access (15-20%)Manage security controls for identity and accessManage Azure built-in role assignmentsManage custom roles, including Azure roles and Microsoft Entra rolesImplement and manage Microsoft Entra Permissions ManagementPlan and manage Azure resources in Microsoft Entra Privileged Identity Management, including settings and assignmentsImplement multi-factor authentication (MFA) for access to Azure resourcesImplement Conditional Access policies for cloud resources in AzureManage Microsoft Entra application accessManage access to enterprise applications in Microsoft Entra ID, including OAuth permission grantsManage Microsoft Entra app registrationsConfigure app registration permission scopesManage app registration permission consentManage and use service principalsManage managed identitiesSecure networking (20-25%)Plan and implement security for virtual networksPlan and implement Network Security Groups (NSGs) and Application Security Groups (ASGs)Manage virtual networks by using Azure Virtual Network ManagerPlan and implement user-defined routes (UDRs)Plan and implement Virtual Network peering or VPN gatewayPlan and implement Virtual WAN, including secured virtual hubSecure VPN connectivity, including point-to-site and site-to-siteImplement encryption over ExpressRouteConfigure firewall settings on Azure resourcesMonitor network security by using Network WatcherPlan and implement security for private access to Azure resourcesPlan and implement virtual network Service EndpointsPlan and implement Private EndpointsPlan and implement Private Link servicesPlan and implement network integration for Azure App Service and Azure FunctionsPlan and implement network security configurations for an App Service Environment (ASE)Plan and implement network security configurations for an Azure SQL Managed InstancePlan and implement security for public access to Azure resourcesPlan and implement Transport Layer Security (TLS) to applications, including Azure App Service and API ManagementPlan, implement, and manage an Azure Firewall, including Azure Firewall Manager and firewall policiesPlan and implement an Azure Application GatewayPlan and implement an Azure Front Door, including Content Delivery Network (CDN)Plan and implement a Web Application Firewall (WAF)Recommend when to use Azure DDoS Protection StandardSecure compute, storage, and databases (20-25%)Plan and implement advanced security for computePlan and implement remote access to virtual machines, including Azure Bastion and just-in-time (JIT)Configure network isolation for Azure Kubernetes Service (AKS)Secure and monitor AKSConfigure authentication for AKSConfigure security monitoring for Azure Container Instances (ACIs)Configure security monitoring for Azure Container Apps (ACAs)Manage access to Azure Container Registry (ACR)Configure disk encryption, including Azure Disk Encryption (ADE), encryption at host, and confidential disk encryptionRecommend security configurations for Azure API ManagementPlan and implement security for storageConfigure access control for storage accountsManage storage account access keysSelect and configure an appropriate method for access to Azure FilesSelect and configure an appropriate method for access to Azure Blob StorageSelect and configure appropriate methods for protecting against data security threats, including soft delete, backups, versioning, and immutable storageConfigure Bring your own key (BYOK)Enable double encryption at the Azure Storage infrastructure levelPlan and implement security for Azure SQL Database and Azure SQL Managed InstanceEnable Microsoft Entra database authenticationEnable database auditingPlan and implement dynamic maskingImplement Transparent Data Encryption (TDE)Recommend when to use Azure SQL Database Always EncryptedSecure Azure using Microsoft Defender for Cloud and Microsoft Sentinel (30-35%)Implement and manage enforcement of cloud governance policiesCreate, assign, and interpret policies and initiatives in Azure PolicyConfigure Azure Key Vault network settingsConfigure access to Key Vault, including vault access policies and Azure Role Based Access ControlManage certificates, secrets, and keysConfigure key rotationPerform backup and recovery of certificates, secrets, and keysImplement security controls to protect backupsImplement security controls for asset managementManage security posture by using Microsoft Defender for CloudIdentify and remediate security risks by using the Microsoft Defender for Cloud Secure Score and InventoryAssess compliance against security frameworks by using Microsoft Defender for CloudManage compliance standards in Microsoft Defender for CloudAdd custom standards to Microsoft Defender for CloudConnect hybrid cloud and multi-cloud environments to Microsoft Defender for Cloud, including Amazon Web Services (AWS) and Google Cloud Platform (GCP)Implement and use Microsoft Defender External Attack Surface Management (EASM)Configure and manage threat protection by using Microsoft Defender for CloudEnable workload protection services in Microsoft Defender for CloudConfigure Microsoft Defender for Servers, Microsoft Defender for Databases, and Microsoft Defender for StorageImplement and manage agentless scanning for virtual machines in Microsoft Defender for ServersImplement and manage Microsoft Defender Vulnerability Management for Azure virtual machinesConnect to and configure settings in Microsoft Defender for Cloud Devops Security, including GitHub, Azure DevOps, and GitLabConfigure and manage security monitoring and automation solutionsManage and respond to security alerts in Microsoft Defender for CloudConfigure workflow automation by using Microsoft Defender for CloudMonitor network security events and performance data by configuring data collection rules (DCRs) in Azure MonitorConfigure data connectors in Microsoft SentinelEnable analytics rules in Microsoft SentinelConfigure automation in Microsoft Sentinel