
Meet the instructor, Christian Calinescu, as he introduces the final piece in the nine-course Microsoft cybersecurity professional track for planning and implementing a security incident response.
Plan and implement a security incident response by building a computer security incident response team, prioritizing actions, and understanding threat modeling and incident reporting.
Learn threat modeling as a systematic method and employ the stride method to identify threats from an attacker's view, map attack surfaces, and prioritize mitigations.
Explore the NIST cybersecurity framework, its identify, protect, detect, and respond functions, and how to tailor it to assets, governance, and risk management to reduce cyber risk.
Develop a robust incident response plan by assembling a CSIRT, defining containment and recovery procedures, and minimizing damage during incidents. Train with scenario exercises and validate backups.
Explore building a computer security incident response team (csirt) and its role in the incident response lifecycle, including preparation, detection and analysis, containment, eradication, recovery, and post-incident lessons.
Train and organize a computer security incident response team with clear roles, realistic scope, and documented workflows; establish communications, legal coordination, backups, and continual improvement through drills and lessons learned.
Document and review the security incident report (seer) within the post incident activity phase to mitigate incidents and prevent similar future occurrences.
Learn to complete a security incident response report as a post incident activity, detailing basic organizational information, incident overview, severity, and remediation steps to capture lessons learned.
This course is designed to help you manage an enterprise security incident, while avoiding common errors, increasing both the effectiveness and efficiency of your incident response efforts.
After completing this course, students will be able to:
Effectively prioritize the response to a security incident
Build a computer security incident response team (CSIRT)
Develop an incident response action plan
Post-incident activity
This course is designed to get you started as quickly as possible. There are a variety of self-paced learning activities. You will get:
Video lectures on each topic explaining each concept thoroughly with examples (and Demonstrations where applicable)
Review questions (quizz) at the end of each section
Final Exam at the end of the course - review questions to test your knowledge on the topics and concepts learned in the course
Links to official Microsoft resources/blogs/videos for further documentation
This course is the 9th course from a series of 9 courses which address all aspects to become a Microsoft Cyber Security Professional . This cyber security track is designed to teach you, or fill in the knowledge gaps, all the aspects and technologies to become a successful cyber security professional. The entire track addresses mostly Microsoft security technologies, including the latest cloud services made available by Microsoft like: Microsoft Defender Suite, Office 365 security features and services, Microsoft Graph, Azure Active Directory Security and many more.
Microsoft, Windows, Microsoft 365 and Microsoft Azure are either registered trademarks or trademarks of Microsoft Corporation in the United States and/or other countries. This course is not certified, accredited, affiliated with, nor endorsed by Microsoft Corporation.