Home > Store

Exam SC-200: Microsoft Security Operations Analyst (Video)

Online Video

Register your product to gain access to bonus material or receive a coupon.

Description

  • Copyright 2024
  • Edition: 1st
  • Online Video
  • ISBN-10: 0-13-828774-0
  • ISBN-13: 978-0-13-828774-0

This course covers the objectives in the SC-200 exam required to earn the Security Operations Analyst certification.

Overview:

SC-200 is a crucial exam to take because it can help you understand the advanced concepts of management of the security of the infrastructure with usage of Microsoft Defender XDR, Microsoft Defender for Cloud, and Microsoft Sentinel.

Skills covered in the exam:

  • Manage a security operations environment
  • Configure protections and detections
  • Manage incident response
  • Perform threat hunting

Through a mix of screen casting, slides, and demos, MVP and MCT certified Charbel Nemnom teaches you to use Microsoft Sentinel, Microsoft Defender for Cloud, Microsoft Defender XDR, and third-party security solutions.

Skill Level:

  • Intermediate

Learn How To:

  • Kickstart your exam preparation and build a foundation in security toward becoming a Microsoft Certified Security Operations Analyst Associate.
  • Secure your organizations digital assets and their environment whether on-premises or in the cloud.
  • Protect data from unauthorized access in today's volatile information security landscape.

Course Requirements:

  • Basic understanding of Microsoft 365/Azure cloud services/Windows and Linux operating systems/Microsoft Sentinel
  • Fundamental understanding of Microsoft security, compliance, and identity products

Who Should Take This Course:

  • Security Operations Analysts, Azure administrators, Windows and Linux operators
  • IT professionals looking to enhance their Microsoft Defender XDR, Microsoft Defender for Cloud, and Microsoft Sentinel knowledge

About Pearson Video Training:   

Pearson publishes expert-led video tutorials covering a wide selection of technology topics designed to teach you the skills you need to succeed. These professional and personal technology videos feature world-leading author instructors published by your trusted technology brands: Addison-Wesley, Cisco Press, Pearson IT Certification, Sams, and Que. Topics include IT Certification, Network Security, Cisco Technology, Programming, Web Development, Mobile Development, and more. Learn more about Pearson Video training at  http://www.informit.com/video.

 

Video Lessons are available for download for offline viewing within the streaming format. Look for the green arrow in each lesson.

Sample Content

Table of Contents

Introduction

Lesson 1: Configure Settings in Microsoft Defender XDR

1.1 Configure a connection from Defender XDR to a Sentinel workspace

1.2 Configure alert and vulnerability notification rules

1.3 Configure Microsoft Defender for Endpoint Advanced Features

1.4 Configure endpoint rules settings, including indicators and web content filtering

1.5 Manage automated investigation and response capabilities in Microsoft Defender XDR

1.6 Configure automatic attack disruption in Microsoft Defender XDR

Lesson 2: Manage Assets and Environments

2.1 Configure and manage device groups, permissions, and automation levels in Microsoft Defender for Endpoint

2.2 Identify and remediate unmanaged devices in Microsoft Defender for Endpoint

2.3 Manage resources by using Azure Arc

2.4 Connect environments to Microsoft Defender for Cloud (by using multi-cloud account management)

2.5 Discover and remediate unprotected resources by using Defender for Cloud

2.6 Identify and remediate devices at risk by using Microsoft Defender Vulnerability Management

Lesson 3: Design and Configure a Microsoft Sentinel Workspace

3.1 Plan a Microsoft Sentinel workspace

3.2 Configure Microsoft Sentinel roles

3.3 Specify Azure RBAC roles for Microsoft Sentinel configuration

3.4 Design and configure Microsoft Sentinel data storage, including log types and log retention

3.5 Manage multiple workspaces by using Workspace Manager and Azure Lighthouse

Lesson 4: Ingest Data Sources in Microsoft Sentinel

4.1 Identify data sources to be ingested for Microsoft Sentinel

4.2 Configure and use Microsoft connectors for Azure resources, including Azure Policy and diagnostic settings

4.3 Configure bidirectional synchronization between Microsoft Sentinel and Microsoft Defender XDR

4.4 Configure bidirectional synchronization between Microsoft Sentinel to Microsoft Defender for Cloud

4.5 Plan and configure Syslog and Common Event Format (CEF) event collections

4.6 Plan and configure collection of Windows Security events by using data collection rules, including Windows Event Forwarding (WEF)

4.7 Configure threat intelligence connectors, including platform, TAXII, upload indicators API, and MISP

4.8 Create custom log tables in the workspace to store ingested data

Lesson 5: Configure Protections in Microsoft Defender Security Technologies

5.1 Configure policies for Microsoft Defender for Cloud Apps

5.2 Configure policies for Microsoft Defender for Office

5.3 Configure security policies for Microsoft Defender for Endpoints, including attack surface reduction (ASR) rules

5.4 Configure cloud workload protections in Microsoft Defender for Cloud

Lesson 6: Configure Detection in Microsoft Defender XDR

6.1 Configure and manage custom detections

6.2 Configure alert tuning

6.3 Configure deception rules in Microsoft Defender XDR

Lesson 7: Configure Detections in Microsoft Sentinel

7.1 Classify and analyze data by using entities

7.2 Configure scheduled query rules, including KQL

7.3 Configure near-real-time (NRT) query rules, including KQL

7.4 Manage analytics rules from Content hub

7.5 Configure anomaly detection analytics rules

7.6 Configure the Fusion rule

7.7 Query Microsoft Sentinel data by using ASIM parsers

7.8 Manage and use threat indicators

Lesson 8: Respond to Alerts and Incidents in Microsoft Defender XDR

8.1 Investigate and remediate threats to Microsoft Teams, SharePoint Online, and OneDrive

8.2 Investigate and remediate threats in email by using Microsoft Defender for Office

8.3 Investigate and remediate ransomware and business email compromise incidents identified by automatic attack disruption

8.4 Investigate and remediate compromised entities identified by Microsoft Purview data loss prevention (DLP) policies

8.5 Investigate and remediate threats identified by Microsoft Purview insider risk policies

8.6 Investigate and remediate alerts and incidents identified by Microsoft Defender for Cloud

8.7 Investigate and remediate security risks identified by Microsoft Defender for Cloud Apps

8.8 Investigate and remediate compromised identities in Microsoft Entra ID

8.9 Investigate and remediate security alerts from Microsoft Defender for Identity

8.10 Manage actions and submissions in the Microsoft Defender portal

Lesson 9: Respond to Alerts and Incidents Identified by Microsoft Defender for Endpoint

9.1 Investigate timeline of compromised devices

9.2 Perform actions on the device, including live response and collecting investigation packages

9.3 Perform evidence and entity investigation

Lesson 10: Enrich Investigations by Using Other Microsoft Tools

10.1 Investigate threats by using unified audit log

10.2 Investigate threats by using Content Search

10.3 Perform threat hunting by using Microsoft Graph activity logs

Lesson 11: Manage Incidents in Microsoft Sentinel

11.1 Triage incidents in Microsoft Sentinel

11.2 Investigate incidents in Microsoft Sentinel

11.3 Respond to incidents in Microsoft Sentinel

Lesson 12: Configure Security Orchestration, Automation, and Response (SOAR) in Microsoft Sentinel

12.1 Create and configure automation rules

12.2 Create and configure Microsoft Sentinel playbooks

12.3 Configure analytic rules to trigger automation

12.4 Trigger playbooks manually from alerts and incidents

12.5 Run playbooks on On-premises resources

Lesson 13: Hunt for Threats by Using KQL

13.1 Identify threats by using Kusto Query Language (KQL)

13.2 Interpret threat analytics in the Microsoft Defender portal

13.3 Create custom hunting queries by using KQL

Lesson 14: Hunt for Threats by Using Microsoft Sentinel

14.1 Analyze attack vector coverage by using the MITRE ATT&CK in Microsoft Sentinel

14.2 Customize content gallery hunting queries

14.3 Use hunting bookmarks for data investigations

14.4 Monitor hunting queries by using Livestream

14.5 Retrieve and manage archived log data

14.6 Create and manage search jobs

Lesson 15: Analyze and Interpret Data by Using Workbooks

15.1 Activate and customize Microsoft Sentinel workbook templates

15.2 Create custom workbooks that include KQL

15.3 Configure visualizations

Summary

Updates

Submit Errata

More Information

vceplus-200-125    | boson-200-125    | training-cissp    | actualtests-cissp    | techexams-cissp    | gratisexams-300-075    | pearsonitcertification-210-260    | examsboost-210-260    | examsforall-210-260    | dumps4free-210-260    | reddit-210-260    | cisexams-352-001    | itexamfox-352-001    | passguaranteed-352-001    | passeasily-352-001    | freeccnastudyguide-200-120    | gocertify-200-120    | passcerty-200-120    | certifyguide-70-980    | dumpscollection-70-980    | examcollection-70-534    | cbtnuggets-210-065    | examfiles-400-051    | passitdump-400-051    | pearsonitcertification-70-462    | anderseide-70-347    | thomas-70-533    | research-1V0-605    | topix-102-400    | certdepot-EX200    | pearsonit-640-916    | itproguru-70-533    | reddit-100-105    | channel9-70-346    | anderseide-70-346    | theiia-IIA-CIA-PART3    | certificationHP-hp0-s41    | pearsonitcertification-640-916    | anderMicrosoft-70-534    | cathMicrosoft-70-462    | examcollection-cca-500    | techexams-gcih    | mslearn-70-346    | measureup-70-486    | pass4sure-hp0-s41    | iiba-640-916    | itsecurity-sscp    | cbtnuggets-300-320    | blogged-70-486    | pass4sure-IIA-CIA-PART1    | cbtnuggets-100-101    | developerhandbook-70-486    | lpicisco-101    | mylearn-1V0-605    | tomsitpro-cism    | gnosis-101    | channel9Mic-70-534    | ipass-IIA-CIA-PART1    | forcerts-70-417    | tests-sy0-401    | ipasstheciaexam-IIA-CIA-PART3    | mostcisco-300-135    | buildazure-70-533    | cloudera-cca-500    | pdf4cert-2v0-621    | f5cisco-101    | gocertify-1z0-062    | quora-640-916    | micrcosoft-70-480    | brain2pass-70-417    | examcompass-sy0-401    | global-EX200    | iassc-ICGB    | vceplus-300-115    | quizlet-810-403    | cbtnuggets-70-697    | educationOracle-1Z0-434    | channel9-70-534    | officialcerts-400-051    | examsboost-IIA-CIA-PART1    | networktut-300-135    | teststarter-300-206    | pluralsight-70-486    | coding-70-486    | freeccna-100-101    | digitaltut-300-101    | iiba-CBAP    | virtuallymikebrown-640-916    | isaca-cism    | whizlabs-pmp    | techexams-70-980    | ciscopress-300-115    | techtarget-cism    | pearsonitcertification-300-070    | testking-2v0-621    | isacaNew-cism    | simplilearn-pmi-rmp    | simplilearn-pmp    | educationOracle-1z0-809    | education-1z0-809    | teachertube-1Z0-434    | villanovau-CBAP    | quora-300-206    | certifyguide-300-208    | cbtnuggets-100-105    | flydumps-70-417    | gratisexams-1V0-605    | ituonline-1z0-062    | techexams-cas-002    | simplilearn-70-534    | pluralsight-70-697    | theiia-IIA-CIA-PART1    | itexamtips-400-051    | pearsonitcertification-EX200    | pluralsight-70-480    | learn-hp0-s42    | giac-gpen    | mindhub-102-400    | coursesmsu-CBAP    | examsforall-2v0-621    | developerhandbook-70-487    | root-EX200    | coderanch-1z0-809    | getfreedumps-1z0-062    | comptia-cas-002    | quora-1z0-809    | boson-300-135    | killtest-2v0-621    | learncia-IIA-CIA-PART3    | computer-gcih    | universitycloudera-cca-500    | itexamrun-70-410    | certificationHPv2-hp0-s41    | certskills-100-105    | skipitnow-70-417    | gocertify-sy0-401    | prep4sure-70-417    | simplilearn-cisa    |
http://www.pmsas.pr.gov.br/wp-content/    | http://www.pmsas.pr.gov.br/wp-content/    |