|
所在平台: Udemy |
课程主页: https://www.udemy.com/course/sc-200-microsoft-security-operations-analyst-practice-exam-j/
课程评论:没有评论
课程名称:SC-200:Microsoft 安全运营分析师实践考试 课程概述:本课程提供了针对 SC-200:Microsoft 安全运营分析师考试的练习题,这些问题经过精心和系统的开发,旨在帮助学习者满足考试要求并获得实际知识。根据 Microsoft SC-200 考试,测评的技能包括: 1. 管理安全运营环境(占 25-30%) 2. 配置保护和检测(占 15-20%) 3. 管理事件响应(占 35-40%) 4. 执行威胁狩猎(占 15-20%) 主要内容包括: - 配置 Microsoft Defender XDR 的保护和检测。 - 管理 Microsoft Defender for Cloud 中的设备组、权限和自动化级别。 - 在 Microsoft Sentinel 中规划和配置工作区,包括数据源的摄取和日志存储的管理。 - 配置安全政策,如 Microsoft Defender for Office 和 Endpoint 的安全政策。 - 响应和调查 Microsoft Defender XDR 中的警报及安全事件。 - 使用 Kusto 查询语言 (KQL) 进行威胁狩猎和事件分析。 推荐学习者通过 Microsoft Learn 平台上的 SC-200 课程进行学习,同时使用本练习题集来验证知识掌握情况。本课程旨在提升学员的实际操作能力和备考信心,祝大家考试顺利!
Practice questions for the SC-200: Microsoft Security Operations Analyst exam that have been carefully and methodically developed to assist the learner with meeting exam requirements and for real world knowledge.Skills measured on Microsoft SC-200 ExamManage a security operations environment (25-30%)Configure protections and detections (15-20%)Manage incident response (35-40%)Perform threat hunting (15-20%)Manage a security operations environment (25-30%)Configure settings in Microsoft Defender XDRConfigure a connection from Defender XDR to a Sentinel workspaceConfigure alert and vulnerability notification rulesConfigure Microsoft Defender for Endpoint advanced featuresConfigure endpoint rules settings, including indicators and web content filteringManage automated investigation and response capabilities in Microsoft Defender XDRConfigure automatic attack disruption in Microsoft Defender XDRManage assets and environmentsConfigure and manage device groups, permissions, and automation levels in Microsoft Defender for EndpointIdentify and remediate unmanaged devices in Microsoft Defender for EndpointManage resources by using Azure ArcConnect environments to Microsoft Defender for Cloud (by using multi-cloud account management)Discover and remediate unprotected resources by using Defender for CloudIdentify and remediate devices at risk by using Microsoft Defender Vulnerability ManagementDesign and configure a Microsoft Sentinel workspacePlan a Microsoft Sentinel workspaceConfigure Microsoft Sentinel rolesSpecify Azure RBAC roles for Microsoft Sentinel configurationDesign and configure Microsoft Sentinel data storage, including log types and log retentionManage multiple workspaces by using Workspace manager and Azure LighthouseIngest data sources in Microsoft SentinelIdentify data sources to be ingested for Microsoft SentinelImplement and use Content hub solutionsConfigure and use Microsoft connectors for Azure resources, including Azure Policy and diagnostic settingsConfigure bidirectional synchronization between Microsoft Sentinel and Microsoft Defender XDRPlan and configure Syslog and Common Event Format (CEF) event collectionsPlan and configure collection of Windows Security events by using data collection rules, including Windows Event Forwarding (WEF)Configure threat intelligence connectors, including platform, TAXII, upload indicators API, and MISPCreate custom log tables in the workspace to store ingested dataConfigure protections and detections (15-20%)Configure protections in Microsoft Defender security technologiesConfigure policies for Microsoft Defender for Cloud AppsConfigure policies for Microsoft Defender for OfficeConfigure security policies for Microsoft Defender for Endpoints, including attack surface reduction (ASR) rulesConfigure cloud workload protections in Microsoft Defender for CloudConfigure detection in Microsoft Defender XDRConfigure and manage custom detectionsConfigure alert tuningConfigure deception rules in Microsoft Defender XDRConfigure detections in Microsoft SentinelClassify and analyze data by using entitiesConfigure scheduled query rules, including KQLConfigure near-real-time (NRT) query rules, including KQLManage analytics rules from Content hubConfigure anomaly detection analytics rulesConfigure the Fusion ruleQuery Microsoft Sentinel data by using ASIM parsersManage and use threat indicatorsManage incident response (35-40%)Respond to alerts and incidents in Microsoft Defender XDRInvestigate and remediate threats to Microsoft Teams, SharePoint Online, and OneDriveInvestigate and remediate threats in email by using Microsoft Defender for OfficeInvestigate and remediate ransomware and business email compromise incidents identified by automatic attack disruptionInvestigate and remediate compromised entities identified by Microsoft Purview data loss prevention (DLP) policiesInvestigate and remediate threats identified by Microsoft Purview insider risk policiesInvestigate and remediate alerts and incidents identified by Microsoft Defender for CloudInvestigate and remediate security risks identified by Microsoft Defender for Cloud AppsInvestigate and remediate compromised identities in Microsoft Entra IDInvestigate and remediate security alerts from Microsoft Defender for IdentityManage actions and submissions in the Microsoft Defender portalRespond to alerts and incidents identified by Microsoft Defender for EndpointInvestigate timeline of compromised devicesPerform actions on the device, including live response and collecting investigation packagesPerform evidence and entity investigationEnrich investigations by using other Microsoft toolsInvestigate threats by using unified audit LogInvestigate threats by using Content SearchPerform threat hunting by using Microsoft Graph activity logsManage incidents in Microsoft SentinelTriage incidents in Microsoft SentinelInvestigate incidents in Microsoft SentinelRespond to incidents in Microsoft SentinelConfigure security orchestration, automation, and response (SOAR) in Microsoft SentinelCreate and configure automation rulesCreate and configure Microsoft Sentinel playbooksConfigure analytic rules to trigger automationTrigger playbooks manually from alerts and incidentsRun playbooks on On-premises resourcesPerform threat hunting (15-20%)Hunt for threats by using KQLIdentify threats by using Kusto Query Language (KQL)Interpret threat analytics in the Microsoft Defender portalCreate custom hunting queries by using KQLHunt for threats by using Microsoft SentinelAnalyze attack vector coverage by using the MITRE ATT & CK in Microsoft SentinelCustomize content gallery hunting queriesUse hunting bookmarks for data investigationsMonitor hunting queries by using LivestreamRetrieve and manage archived log dataCreate and manage search jobsAnalyze and interpret data by using workbooksActivate and customize Microsoft Sentinel workbook templatesCreate custom workbooks that include KQLConfigure visualizationsThe learner is recommended to work through the course on Microsoft Learn for SC-200 and use this set of questions to verifiy knowledge for the exam.As ever I take great pride in the practice question banks and if there are any issues or I can assist in any way please message me.Good luck with your exam!