|
所在平台: Udemy |
课程主页: https://www.udemy.com/course/sc-200-microsoft-security-operations-analyst-r/
课程评论:没有评论
课程名称:SC-200:微软安全运营分析师 概述:SC-200:微软安全运营分析师是一个精心设计的Udemy课程,旨在帮助IT专业人员顺利通过SC-200考试。该课程系统地从基础设置到高级实施,通过真实案例帮助学习者掌握微软安全运营生态系统的相关知识。通过SC-200认证,学员能够获得在微软安全运营领域的专业能力。课程始终与微软最新的学习指导和考试目标保持一致,内容涵盖以下几个主要方面: 1. **管理安全运营环境(20-25%)** - 配置Microsoft Defender XDR的保护和检测功能 - 管理事件响应和安全威胁 - 实现自动化调查和响应能力 2. **配置保护和检测(15-20%)** - 在Microsoft Defender安全技术中配置保护措施 - 配置Microsoft Defender for Endpoint、Office 365及云工作负载的安全策略 3. **管理事件响应(25-30%)** - 在Microsoft Defender门户中应对警报和事件 - 调查和修复通过自动攻击中断识别的威胁 - 使用Microsoft Sentinel响应和处理事件 4. **管理安全威胁(15-20%)** - 使用Microsoft Defender XDR和Sentinel进行威胁狩猎 - 创建和管理自定义狩猎查询与工作簿 - 通过Kusto查询语言(KQL)分析攻击向量 此外,课程还将教授如何设计和配置Microsoft Sentinel工作区、监控数据摄取、创建自动化规则和使用安全Copilot等。 通过完成本课程,学员将深入理解并能有效应对现代安全运营工作中面临的挑战。准备迎接SC-200考试的挑战,提升自身在微软安全领域的专业能力。
SC-200: Microsoft Security Operations Analyst, is a meticulously structured Udemy course aimed at IT professionals seeking to pass the SC-200 exam. This course systematically walks you through the initial setup to advanced implementation with real-world applications.By passing SC-200: Microsoft Security Operations Analyst, you're gaining proficiency in the highly recognized Microsoft security operations ecosystem.The course is always aligned with Microsoft's latest study guide and exam objectives:Manage a security operations environment (20-25%)Configure protections and detections (15-20%)Manage incident response (25-30%)Manage security threats (15-20%)Manage a security operations environmentConfigure settings in Microsoft Defender XDRConfigure alert and vulnerability notification rulesConfigure Microsoft Defender for Endpoint advanced featuresConfigure endpoint rules settingsManage automated investigation and response capabilities in Microsoft Defender XDRConfigure automatic attack disruption in Microsoft Defender XDRManage assets and environmentsConfigure and manage device groups, permissions, and automation levels in Microsoft Defender for EndpointIdentify unmanaged devices in Microsoft Defender for EndpointDiscover unprotected resources by using Defender for CloudIdentify and remediate devices at risk by using Microsoft Defender Vulnerability ManagementMitigate risk by using Exposure Management in Microsoft Defender XDRDesign and configure a Microsoft Sentinel workspacePlan a Microsoft Sentinel workspaceConfigure Microsoft Sentinel rolesSpecify Azure RBAC roles for Microsoft Sentinel configurationDesign and configure Microsoft Sentinel data storage, including log types and log retentionIngest data sources in Microsoft SentinelIdentify data sources to be ingested for Microsoft SentinelImplement and use Content hub solutionsConfigure and use Microsoft connectors for Azure resources, including Azure Policy and diagnostic settingsPlan and configure Syslog and Common Event Format (CEF) event collectionsPlan and configure collection of Windows Security events by using data collection rules, including Windows Event Forwarding (WEF)Create custom log tables in the workspace to store ingested dataMonitor and optimize data ingestionConfigure protections and detectionsConfigure protections in Microsoft Defender security technologiesConfigure policies for Microsoft Defender for Cloud AppsConfigure policies for Microsoft Defender for Office 365Configure security policies for Microsoft Defender for Endpoints, including attack surface reduction (ASR) rulesConfigure cloud workload protections in Microsoft Defender for CloudConfigure detections in Microsoft Defender XDRConfigure and manage custom detection rulesManage alerts, including tuning, suppression, and correlationConfigure deception rules in Microsoft Defender XDRConfigure detections in Microsoft SentinelClassify and analyze data by using entitiesConfigure and manage analytics rulesQuery Microsoft Sentinel data by using ASIM parsersImplement behavioral analyticsManage incident responseRespond to alerts and incidents in the Microsoft Defender portalInvestigate and remediate threats by using Microsoft Defender for Office 365Investigate and remediate ransomware and business email compromise incidents identified by automatic attack disruptionInvestigate and remediate compromised entities identified by Microsoft Purview data loss prevention (DLP) policiesInvestigate and remediate threats identified by Microsoft Purview insider risk policiesInvestigate and remediate alerts and incidents identified by Microsoft Defender for Cloud workload protectionsInvestigate and remediate security risks identified by Microsoft Defender for Cloud AppsInvestigate and remediate compromised identities that are identified by Microsoft Entra IDInvestigate and remediate security alerts from Microsoft Defender for IdentityRespond to alerts and incidents identified by Microsoft Defender for EndpointInvestigate device timelinesPerform actions on the device, including live response and collecting investigation packagesPerform evidence and entity investigationInvestigate Microsoft 365 activitiesInvestigate threats by using the unified audit logInvestigate threats by using Content SearchInvestigate threats by using Microsoft Graph activity logsRespond to incidents in Microsoft SentinelInvestigate and remediate incidents in Microsoft SentinelCreate and configure automation rulesCreate and configure Microsoft Sentinel playbooksRun playbooks on on-premises resourcesImplement and use Copilot for SecurityCreate and use promptbooksManage sources for Copilot for Security, including plugins and filesIntegrate Copilot for Security by implementing connectorsManage permissions and roles in Copilot for SecurityMonitor Copilot for Security capacity and costIdentify threats and risks by using Copilot for SecurityInvestigate incidents by using Copilot for SecurityManage security threatsHunt for threats by using Microsoft Defender XDRIdentify threats by using Kusto Query Language (KQL)Interpret threat analytics in the Microsoft Defender portalCreate custom hunting queries by using KQLHunt for threats by using Microsoft SentinelAnalyze attack vector coverage by using the MITRE ATT & CK matrixManage and use threat indicatorsCreate and manage huntsCreate and monitor hunting queriesUse hunting bookmarks for data investigationsRetrieve and manage archived log dataCreate and manage search jobsCreate and configure Microsoft Sentinel workbooksActivate and customize workbook templatesCreate custom workbooks that include KQLConfigure visualizations