
Meet the enterprise security fundamentals instructor, a senior IT professional with over 10 years of cybersecurity and infrastructure experience and certifications, and learn what you will gain in the course.
Explore the enterprise security fundamentals course, including prerequisites and course structure. Learn red team and blue team concepts, breach response, and assessment through quizzes and a final exam.
Explore the current cybersecurity landscape, where attackers monetize breaches through ransomware and coin mining, while defenders use automation and cloud tools to detect and mitigate threats.
Adopt an assumed compromise approach to enterprise security, focusing on detection, response, and cloud-based analytics that monitor telemetry for anomalies, with just-in-time administration, network segmentation, and code integrity policies.
Explore the cost of breach in enterprise security by examining breach investigation, system rehabilitation, reputational damage, asset destruction, and compliance costs, plus the idea of proportional security and threat modeling.
Explore red team versus blue team exercises that simulate attacks and responses, train staff to detect and respond, and evolve from whiteboard scenarios to safe proofs of concept.
Explore the attacker's objective in red team vs blue team exercises, including persistence, data theft, extortion, ransomware, coin miner's malware, and destruction of systems.
Explore the red team's kill chain in enterprise security, from reconnaissance and weaponization to delivery, exploitation, installation, and command and control, ending with actions on objective.
Document vulnerabilities discovered in red team vs blue team exercises to enable remediation, rollbacks, and secure configurations across servers and network devices.
Block the red team from gaining a foothold, quickly detect and respond to red team activities, and use post-exercise reports to refine incident response and improve blue team processes.
Explore the blue team's kill chain—gather baseline data, detect and alert, investigate, plan and execute a measured response, and conduct post-incident analysis to improve defenses.
Explore techniques to restrict privilege escalation, including privileged access workstations, just enough administration, and just in time administration to limit privileged use and restricted administrative accounts.
Implement code integrity policies with AppLocker, Windows Defender Application Guard, and Windows Defender Device Guard to restrict lateral movement and apply network segmentation.
Discover how attack detection relies on centralized telemetry, logging, and SIEM to reveal intrusions, using IDS/IPS, machine learning, and cloud security analytics across Microsoft security tools.
Explore the CIA triad, confidentiality, integrity, and availability, and learn how these pillars protect data, configurations, and systems from unauthorized access and disruption in enterprise security.
Explore four core organization preparations to strengthen security posture: baseline posture, information classification, change tracking and auditing, and monitoring and reporting.
Develop clear organizational policies that assign security responsibilities and control measures. Learn pre incident, incident, and post incident processes, including patching, monitoring, data classification, and breach notifications.
In this course, we examine the concept of Red team – Blue team security professionals. You will practice Red team versus Blue team exercises, where one group of security pros (the red team) attacks some part or parts of a company’s security infrastructure, and an opposing group (the blue team) defends against the attack. Both teams work to strengthen a company’s defenses.
You'll learn how both the red and blue teams help the business attain a higher level of security, something the security industry is now calling the Purple team.
You will also learn the fundamental aspects of security in an Enterprise and overall like : CIA Triad concept or Assume Breach philosophy.
This course is designed to get you started as quickly as possible. There are a variety of self-paced learning activities. You will get:
Video lectures on each topic explaining each concept thoroughly with examples (and Demonstrations where applicable)
Review questions (quizz) at the end of each section
Final Exam at the end of the course - 50 questions to test your knowledge on the topics and concepts learned in the course
Links to official Microsoft resources/blogs/videos for further documentation.
What you'll learn ?
After completing this course, students will be able to:
Describe the current enterprise security landscape
Define the Assume Compromise approach
Practice Red team versus Blue team exercises
Develop organizational security preparation, processes, and responses
This course is the 1st course from a series of 9 courses which address all aspects to become a Microsoft Cyber Security Professional . This cyber security track is designed to teach you, or fill in the knowledge gaps, all the aspects and technologies to become a successful cyber security professional. The entire track addresses mostly Microsoft security technologies, including the latest cloud services made available by Microsoft like: Microsoft Defender Suite, Office 365 security features and services, Microsoft Graph, Azure Active Directory Security and many more.
Microsoft, Windows, Microsoft 365 and Microsoft Azure are either registered trademarks or trademarks of Microsoft Corporation in the United States and/or other countries. This course is not certified, accredited, affiliated with, nor endorsed by Microsoft Corporation.