
Meet your instructor, a seasoned security operations professional, as this course prepares you for the SC 200 certification and covers the outline, prerequisites, and expected learning.
Outline SC-200 Microsoft security operations analyst course structure, prerequisites, and audience, and learn to investigate, respond to, and hunt threats using Cousteau query language with Microsoft Defender and Microsoft Sentinel.
Configure the lab by installing Oracle VirtualBox, importing prebuilt VMs from OneDrive, and creating Microsoft 365 and Azure trial subscriptions for Defender for Endpoint, Defender for Cloud, and Microsoft Sentinel.
Learn threat protection with Microsoft 365 Defender, including Defender for Office 365, Defender for Identity, Defender for Endpoint, and Defender for Cloud Apps, to prevent, detect, and remediate cross-domain attacks.
Navigate the Microsoft 365 Defender incidents and alerts portal to investigate, correlate, and remediate across devices and users with automated investigations, advanced hunting, and threat experts.
Protect your organization with Microsoft Defender for Office 365's cloud-based email filtering, real-time link protection, and automated investigation and response, plus threat explorer and attack simulator insights for proactive defense.
Learn how Microsoft Defender for Identity, a cloud-based security solution for hybrid environments, uses on-premises Active Directory signals to detect anomalies, protect credentials, and investigate advanced threats across domain controllers.
Azure AD Identity Protection helps detect, investigate, and automatically remediate identity-based risks using user risk and sign-in risk policies, with self-remediation and administrator workflows.
Discover Microsoft Defender for Cloud Apps, a cloud access security broker that detects shadow IT and enforces data loss prevention with Azure Information Protection and conditional access app control.
Identify sensitive information across Exchange Online, SharePoint Online, OneDrive for Business, and Teams using data loss prevention alerts, and enforce protections like blocking access or notifying users.
Learn to manage insider risk in Microsoft 365 with policy templates and machine learning, using HR data connectors and Microsoft Graph to detect, alert, triage, and investigate risky employee behavior.
Explore Microsoft Defender for Endpoint, an endpoint protection platform that prevents, detects, and responds to advanced threats with threat and vulnerability management, attack surface reduction, automated investigations, and threat intelligence.
Deploy and configure the Microsoft Defender for Endpoint environment, onboard devices using supported methods, set data location and retention, enable preview features, and implement role-based access control and device groups.
Explore how to implement Windows security enhancements with attack surface reduction rules, deploy them via Microsoft Endpoint Manager, and use audit, block, and learn modes for safe endpoint hardening.
Investigate devices in Microsoft Defender for Endpoint by reviewing the device inventory, risk and exposure levels, health state, and alerts. Examine the timeline and security recommendations to guide remediation.
Perform actions on a device during investigations by isolating the device, restricting app execution, or running antivirus, and by collecting investigation packages and initiating live response sessions.
Explore evidence and entity investigations across files, user accounts, IP addresses, and domains, using malware analysis, VirusTotal, deep analysis, and Whois data within Microsoft Defender for Endpoint.
Configure automated investigation and remediation in Defender for Endpoint, including auto resolve alerts, allow or block files, and memory content analysis, plus automation uploads and folder exclusions.
Configure alerts and detections in Defender for Endpoint, including email notifications, suppression rules, and indicators of compromise such as IPs, domains, and files, with integration options and imports.
Threat and vulnerability management in Microsoft Defender for Endpoint enables real-time, agentless discovery and intelligent prioritization of vulnerabilities, enabling seamless remediation with Intune and Endpoint Configuration Manager.
Plan cloud workload protections with Microsoft Defender for Cloud, a CSPM and CWPP tool that continually assesses, hardens, and defends hybrid and cloud resources, with secure score and automated recommendations.
Explore Microsoft Defender for Cloud workload protections, including Defender for servers, app service, storage, and SQL. Learn how integrated threat protection, vulnerability assessment, and just-in-time access strengthen Azure workloads.
Learn how to connect Azure assets to Microsoft Defender for Cloud, using automatic provisioning and manual deployment, and manage asset inventory and extensions.
Connect non-Azure resources to Microsoft Defender for Cloud via Azure Arc, onboarding on-premises, AWS, and GCP resources, and manage hybrid workloads from a single pane of glass.
Learn how Microsoft Defender for Cloud creates, prioritizes, and investigates security alerts and incidents, using threat intelligence, behavioral analytics, and automated responses to remediate threats.
Construct KQL statements for Microsoft Sentinel using let bindings, where filters, and extend and project operators in pipeline-based tabular expressions to query security data.
Learn to analyze security event data with the summarize operator and its variants, generating by account and computer, counting, and making lists or sets, then render time series and charts.
Build multi-table queries in kql by using union and join operators to combine security event data across tables such as security event and security alert, including counting and wildcard unions.
Learn to work with string data in kql, extracting and parsing values from unstructured and structured fields using extract and parse operations, dot notation on dynamic fields, and json functions.
Microsoft Sentinel is a cloud-native SIEM in Azure that ingests data from sources, uses analytics and machine learning for threat detection, and automates responses with playbooks and Azure Logic Apps.
Create and manage Microsoft Sentinel workspaces by configuring a Log Analytics workspace, selecting deployment models (single tenant, regional mixed, multi-tenant with Lighthouse), and assigning reader, responder, and contributor RBAC roles.
Query logs in Microsoft Sentinel using the built-in query language, explore log analytics workspace tables like security alert and security incident, and use the logs window for Sentinel data.
Explore watch lists in Microsoft Sentinel, which store external data as name-value pairs to enrich events and enable correlation in rules, threat hunting, and playbooks.
Manage threat indicators in Microsoft Sentinel by importing indicators via data connectors, use them in analytic rules to detect threats, and visualize with the Threat Intelligence Workbook.
Connect data to Microsoft Sentinel by configuring data connectors for Microsoft 365 Defender, Azure services, and third-party sources. Ingest logs via CEF and syslog, and monitor connected hosts.
Learn to connect and configure the Microsoft 365 Defender connectors with Microsoft Sentinel, enabling automatic incident synchronization across Defender for Office 365, Defender for Endpoint, and other products.
Connect Microsoft services to Microsoft Sentinel using data connectors. Ingest Office 365, Azure Active Directory, and Azure Identity Protection logs to create incidents and support investigations.
Configure the security events connector to stream Windows events to a log analytics workspace, selecting all, common, minimal, or auditing sets, and install the legacy or Azure Monitor agent.
Connect CEF logs to Microsoft Sentinel by streaming Linux syslog messages through the Log Analytics agent for Linux to the Log Analytics workspace over TLS.
Connect syslog data sources to Microsoft Sentinel by installing the log analytics agent on Linux machines and configuring the syslog connector to collect selected facilities and severities.
Learn how to connect threat indicators to Microsoft Sentinel using threat intelligence connectors, ingesting indicators such as IP addresses, domains, URLs, or file hashes to enhance detection, alerting, and investigations.
Detect and investigate threats with Microsoft Sentinel Analytics. Use fusion, machine learning, behavior analytics, and anomaly detections through analytic rules to trigger alerts and incidents across connected data sources.
Explore security incident management in Microsoft Sentinel, from data connectors and log analytics to analytics rules, alerts, and incidents, including evidence, entities, the investigation graph, and ownership.
Automate threat response with Microsoft Sentinel playbooks built on Azure Logic Apps, using alert and incident triggers to send emails and notifications and streamline security operations.
Explore how entity behavior analytics in Microsoft Sentinel builds baselines for users, hosts, IPs, and domains to detect anomalies and prioritize investigations.
Learn how to use and customize workbooks in Microsoft Sentinel to visualize signals with templates, data connectors, tables, bar and pie charts, and tiles, and edit queries to tailor dashboards.
Explore threat hunting concepts in Microsoft Sentinel, emphasizing proactive, hypothesis-driven hunting, a structured hunting cycle, and evidence-based queries to detect not previously detected threats.
Learn to conduct threat hunting with Microsoft Sentinel by using built-in and custom hunting queries, filtering events, and turning findings into analytics rules and alerts.
Explore notebooks in Microsoft Sentinel for threat hunting with live code, data cleaning, and machine learning using Python libraries and Azure ML.
This course is a complete preparation for the SC-200 exam. ( Including hands-on Labs)
The Microsoft Security Operations Analyst collaborates with organizational stakeholders to secure information technology systems for the organization. Their goal is to reduce organizational risk by rapidly remediating active attacks in the environment, advising on improvements to threat protection practices, and referring violations of organizational policies to appropriate stakeholders.
Responsibilities include threat management, monitoring, and response by using a variety of security solutions across their environment. The role primarily investigates, responds to, and hunts for threats using Microsoft Sentinel, Microsoft Defender for Cloud, Microsoft 365 Defender, and third-party security products. Since the Security Operations Analyst consumes the operational output of these tools, they are also a critical stakeholder in the configuration and deployment of these technologies.
Don't be left behind. Be ahead of the curve by getting certified as a Microsoft Security Operations Analyst, and be ready for the opportunity to advance your career in Cybersecurity.
All video lectures will cover all SC-200 exam topics and include hands on demonstrations on each topic.
The course has been structured to follow the exact official Microsoft training plan. So if you want to pass your exam on your first attempt hit the enroll button now and you will get:
· Video lectures on each topic of the exam with demos that fully prepare you for your exam as well as ensuring you can administer all Microsoft security services and tools like a Pro
· Review questions at the end of each section (quizz) to test your knowledge on the topics learned in the section
· LABS at the end of each section. The labs follow the official Microsoft training labs and they are designed so you can practice yourself at your own pace when you aren't watching the videos. You will have step-by-step instructions available to complete each lab and instructions to prepare your lab environment and deploy the necesarry resources for the labs.
· Interactive pre-recorded demonstrations on some of the topics that cannot be covered in the lab environment
· Links to official Microsoft resources/blogs/videos for further documentation available for each lesson on each topic
This course curriculum follows the Microsoft's SC-200 exam study areas:
· Mitigate threats using Microsoft 365 Defender (25-30%)
· Mitigate threats using Microsoft Defender for Cloud (25-30%)
· Mitigate threats using Microsoft Sentinel (40-45%)
Microsoft, Windows, Microsoft 365 and Microsoft Azure are either registered trademarks or trademarks of Microsoft Corporation in the United States and/or other countries. This course is not certified, accredited, affiliated with, nor endorsed by Microsoft Corporation.