SC-200 Exam Questions and Answers - Training Course Solution

所在平台: Udemy

课程主页: https://www.udemy.com/course/sc-200-exam-questions-and-answers-training-course-solution/

课程评论:没有评论

第一个写评论        关注课程

课程简介

课程名称:SC-200 考试题目与答案 - 培训课程解决方案 课程概述:SC-200 考试是针对微软安全运营分析师的认证。微软安全运营分析师与组织内的利益相关者合作,确保信息技术系统的安全。该角色的目标是通过快速修复环境中的主动攻击,降低组织风险,提供对威胁保护实践的改善建议,并将违反组织政策的行为上报给相关利益相关者。该考试主要考察候选人使用 Microsoft Sentinel、Microsoft Defender for Cloud、Microsoft 365 Defender 以及第三方安全产品进行威胁管理、监控和响应的能力。由于安全运营分析师需要使用这些工具的操作输出,因此在这些技术的配置和部署中也扮演着关键角色。 该职位的候选人应熟悉攻击向量、网络威胁、事件管理以及 Kusto 查询语言 (KQL),并对 Microsoft 365 和 Azure 服务有一定了解。成功通过认证考试的候选人可能有资格获得ACE大学学分。 技能考核: - 使用 Microsoft 365 Defender 缓解威胁(占 25-30%) - 使用 Microsoft Defender for Cloud 缓解威胁(占 20-25%) - 使用 Microsoft Sentinel 缓解威胁(占 50-55%) 课程内容包括: - 使用 Microsoft 365 Defender 保护生产环境,处理 Microsoft Teams、SharePoint 和 OneDrive 的威胁,回应和修复与电子邮件及数据丢失防护政策相关的警报,管理端点威胁,同时识别和修复 Azure Active Directory 相关的安全风险。 - 使用 Microsoft Defender for Cloud 进行云安全态势管理和工作负载保护,处理安全配置、合规政策以及安全警报。 - 使用 Microsoft Sentinel 设计并配置工作空间,管理警报和事件,进行威胁猎捕,分析威胁分析报告。 本考试将评估您完成以下技术任务的能力:使用 Microsoft 365 Defender、Microsoft Defender for Cloud 和 Microsoft Sentinel 缓解威胁。

课程评论(0条)

课程详情

Exam SC-200: Microsoft Security Operations AnalystThe Microsoft security operations analyst collaborates with organizational stakeholders to secure information technology systems for the organization. Their goal is to reduce organizational risk by rapidly remediating active attacks in the environment, advising on improvements to threat protection practices, and referring violations of organizational policies to appropriate stakeholders. SC-200 QuestionsResponsibilities include threat management, monitoring, and response by using a variety of security solutions across their environment. The SC-200 Study guide role primarily investigates, responds to, and hunts for threats using Microsoft Sentinel, Microsoft Defender for Cloud, Microsoft 365 Defender, and third-party security products. Since the security operations analyst consumes the operational output of these tools, they are also a critical stakeholder in the configuration and deployment of these technologies.Candidates for this role should be familiar with attack vectors, cyberthreats, incident management, and Kusto Query Language (KQL). Candidates should also be familiar with Microsoft 365 and Azure services.You may be eligible for ACE college credit if you pass this certification exam. See ACE college credit for certification exams for details.Skills measured· Mitigate threats using Microsoft 365 Defender (25-30%)· Mitigate threats using Microsoft Defender for Cloud (20-25%)· Mitigate threats using Microsoft Sentinel (50-55%)Mitigate threats using Microsoft 365 Defender (25-30%)Mitigate threats to the productivity environment by using Microsoft 365Defender• Investigate, respond, and remediate threats to Microsoft Teams, SharePoint, and OneDrive• Investigate, respond, and remediate threats to email by using Microsoft Defender for Office 365• Investigate and respond to alerts generated from Data Loss Prevention policies• Investigate and respond to alerts generated from insider risk policies• Identify, investigate, and remediate security risks by using Microsoft Defender for Cloud Apps• Configure Microsoft Defender for Cloud Apps to generate alerts and reports to detect threatsMitigate endpoint threats by using Microsoft Defender for Endpoint• Manage data retention, alert notification, and advanced features• Recommend security baselines for devices• Respond to incidents and alerts• Manage automated investigations and remediations• Assess and recommend endpoint configurations to reduce and remediate vulnerabilities by• using the Microsoft's threat and vulnerability management solution• Manage endpoint threat indicatorsMitigate identity threats• Identify and remediate security risks related to events for Microsoft Azure Active Directory• (Azure AD), part of Microsoft Entra• Identify and remediate security risks related to Azure AD Identity Protection events• Identify and remediate security risks related to Azure AD Conditional Access events• Identify and remediate security risks related to Active Directory Domain Services using MicrosoftDefender for IdentityManage extended detection and response (XDR) in Microsoft 365 Defender• Manage incidents across Microsoft 365 Defender products• Manage investigation and remediation actions in the Action Center• Perform threat hunting• Identify and remediate security risks using Microsoft Secure Score• Analyze threat analytics• Configure and manage custom detections and alertsMitigate threats using Microsoft Defender for Cloud (20-25%)Implement and maintain cloud security posture management and workloadprotection• Plan and configure Microsoft Defender for Cloud settings, including selecting target• subscriptions and workspaces• Configure Microsoft Defender for Cloud roles• Assess and recommend cloud workload protection• Identify and remediate security risks using the Microsoft Defender for Cloud Secure Score• Manage policies for regulatory compliance• Review and remediate security recommendationsPlan and implement the use of data connectors for ingestion of data sources inMicrosoft Defender for Cloud• Identify data sources to be ingested for Microsoft Defender for Cloud• Configure automated onboarding for Azure resources• Connect multi-cloud and on-premises resources• Configure data collectionsConfigure and respond to alerts and incidents in Microsoft Defender for Cloud• Validate alert configuration• Set up email notifications• Create and manage alert suppression rules• Design and configure workflow automation in Microsoft Defender for Cloud• Remediate alerts and incidents by using Microsoft Defender for Cloud recommendations• Manage security alerts and incidents• Analyze Microsoft Defender for Cloud threat intelligence reports• Manage user data discovered during an investigationMitigate threats using Microsoft Sentinel (50-55%)Design and configure a Microsoft Sentinel workspace• Plan a Microsoft Sentinel workspace• Configure Microsoft Sentinel roles• Design and configure Microsoft Sentinel data storage• Implement and use Content hub, repositories, and community resourcesThis exam measures your ability to accomplish the following technical tasks: mitigate threats using Microsoft 365 Defender; mitigate threats using Microsoft Defender for Cloud; and mitigate threats using Microsoft Sentinel.

课程标签

0人关注该课程

主题相关的课程