SC-200: Defend against cyberthreats with Microsoft's security operations platform

€295.00
| /

________________________________________________________________

Do you want to take this course in another training mode?
Contact us

Other modes: Telepresence - Classroom

________________________________________________________________

SC-200 Course: Defend against cyberthreats with Microsoft's security operations platform

Learn to investigate, hunt for, and respond to threats using Microsoft Sentinel, Microsoft Defender for Cloud, and Microsoft 365 Defender. In this course, you will learn to mitigate cyberthreats using these technologies. Specifically, you will configure and use Microsoft Sentinel, as well as the Kusto Query Language (KQL), to perform detection, analysis, and reporting. The course is designed for individuals in a security operations job role and helps students prepare for the SC-200: Microsoft Security Operations Analyst exam.

regalo

Virtual course with included certification exam as a gift. Don't miss this opportunity! The exam is valued at €126 + VAT and is included at no additional cost.

Promotion valid until December 31, 2026. One-attempt exam available only in Virtual - Remote Training mode. Not applicable to Self-Learning mode.

 

Level: Intermediate - Product: Azure Microsoft 365 - Role: Security Engineer, Security Operations Analyst

⏱️

Course duration:
100 hours

🔑

Access to the classroom:
3 months

Microsoft Security Operations Analyst - Cloud Security - SOC Analyst - Microsoft Defender - Azure Sentinel - Incident Response - Threat Detection - SIEM - SOAR

 

Course audience

The Microsoft Security Operations Analyst role collaborates with organizational stakeholders to secure the organization's information technology systems. Their goal is to reduce organizational risk by rapidly remediating active attacks in the environment, advising on improvements to threat protection procedures, and communicating organizational policy violations to relevant stakeholders. Responsibilities include managing and monitoring threats and responding to them using various security solutions in the environment. The role is primarily concerned with investigating and detecting threats, as well as responding to them, using Microsoft Sentinel, Microsoft Defender for Cloud, Microsoft 365 Defender, and third-party security products. Since the security operations analyst will be using the operational results of these tools, they are also a key stakeholder in the configuration and implementation of these technologies.

 

Course objectives

  • Investigate and mitigate threats: You will learn to use tools such as Microsoft Sentinel, Microsoft Defender XDR, and Microsoft Defender for Cloud to investigate, hunt for, and respond to threats.
  • Configure and manage Microsoft Sentinel: You will configure your environment in Microsoft Sentinel, manage log connections, and create queries using Kusto Query Language (KQL).
  • Manage threat mitigation: You will use Microsoft Defender XDR, Microsoft Purview, and Microsoft Defender for Endpoint to manage threat mitigation.
  • Threat hunting: You will perform advanced threat hunting using threat intelligence and KQL for detection, analysis, and reporting.

 

SC-200 Training Elements

  • SC-200: Mitigate threats using Microsoft Defender XDR (6 Modules)
  • SC-200: Mitigate threats using Microsoft Security Copilot (5 Modules)
  • SC-200: Mitigate threats using Microsoft Purview (4 Modules)
  • SC-200: Mitigate threats using Microsoft Defender for Endpoint (9 Modules)
  • SC-200: Mitigate threats using Microsoft Defender for Cloud (6 Modules)
  • SC-200: Building queries for Microsoft Sentinel using Kusto Query Language (KQL) (4 Modules)
  • SC-200: Configuring the Microsoft Sentinel environment (6 Modules)
  • SC-200: Connecting logs to Microsoft Sentinel (7 Modules)
  • SC-200: Creating detections and performing investigations using Microsoft Sentinel (8 Modules)
  • SC-200: Threat hunting in Microsoft Sentinel (4 Modules)

 

SC-200 Course Content: Defend against cyberthreats with Microsoft's security operations platform

Unit 1: Mitigating threats with Microsoft Defender XDR

Module objectives:

  • Microsoft Defender XDR: Microsoft Defender XDR is a solution that helps mitigate threats and risks using various tools and functionalities. 
  • Threat investigation: Microsoft Defender XDR provides tools for threat investigation, including the Microsoft Security Graph API and advanced hunting capabilities. 
  • Incident management: Microsoft Defender XDR enables incident management, including automatic attack disruption and alert investigation. 
  • Office 365 protection: Microsoft Defender for Office 365 provides capabilities for filtering, attack simulation, and risk remediation. 
  • Identity protection: Microsoft Defender for Identity and Entra ID Protection provide tools to protect identities, detect risks, and remediate threats.

Lessons:

  • Understanding threat protection with Microsoft Defender XDR
  • Mitigating incidents with Microsoft Defender XDR
  • Remediating risks with Defender for Office 365 in Microsoft Defender XDR
  • Microsoft Defender for Identity in Microsoft Defender XDR
  • Protecting identities with Entra ID Protection
  • Defender for Cloud Apps in Microsoft Defender XDR
  • Course Labs:
    • Lab 01: Mitigating threats with Microsoft Defender XDR

Unit 2: Introduction to Microsoft Security Copilot 

Module objectives:

  • How to describe Microsoft Copilot in Microsoft Defender XDR
  • How to describe Microsoft Copilot in Microsoft Purview
  • How to describe Microsoft Copilot in Microsoft Entra

Lessons:

  • Generative AI basics
  • Description of Microsoft Security Copilot
  • Description of Microsoft Security Copilot's core features
  • Description of Microsoft Security Copilot's integrated experiences

Unit 3: Mitigating threats with Microsoft Purview

Module objectives:

  • Microsoft Purview: Microsoft Purview provides compliance solutions to mitigate threats. 
  • Content Search: Content Search is a key feature in the Microsoft 365 Compliance Center for quick searches across all content. 
  • Auditing Solutions: Microsoft Purview provides two auditing solutions: Audit (Standard) and Audit (Premium). 
  • Audit (Standard): Audit (Standard) is enabled by default and provides the ability to log and search audited activities. 
  • Audit (Premium): Audit (Premium) builds on Audit (Standard) by providing advanced auditing functionalities. 

Lessons:

  • Microsoft Purview compliance solutions
  • Investigating and remediating compromised entities identified by Microsoft Purview data loss prevention (DLP) policies
  • Investigating and remediating insider risk threats identified by Microsoft Purview policies
  • Investigating threats using Content Search in Microsoft Purview
  • Investigating threats using Microsoft Purview Audit (Standard)
  • Investigating threats using Microsoft Purview Audit (Premium)

Unit 4: Mitigating threats with Microsoft Defender for Endpoint

Module objectives:

  • Defender for Endpoint:  Microsoft Defender for Endpoint is a platform designed to help enterprise networks prevent, detect, investigate, and respond to advanced threats on their endpoints. 
  • Threat Management: Defender for Endpoint provides advanced, near real-time, and actionable attack detections. 
    Device onboarding: Devices can be monitored using
  • Microsoft Defender for Endpoint through the Defender for Endpoint portal. 
  • Attack Surface Reduction: Attack surface reduction rules can be enabled on Windows devices to reduce the attack surface. 
  • Vulnerability Management: Defender Vulnerability Management uses built-in, agentless scanners to continuously monitor and detect risk across your organization, even when devices are not connected to the corporate network. 

Lessons:

  • Threat protection with Microsoft Defender for Endpoint
  • Implementing the Microsoft Defender for Endpoint environment
  • Implementing Windows security enhancements
  • Performing device investigations
  • Performing actions on a device
  • Performing evidence and entity investigations
  • Configuring and managing automation
  • Configuring alerts and detections
  • Using Threat and Vulnerability Management
  • Module Lab:
    • Lab 01: Mitigating threats with Microsoft Defender for Endpoint

Unit 5: Mitigating threats with Microsoft Defender for Cloud

Course objectives:

  • Defender for Cloud: Microsoft Defender for Cloud is a DevSecOps (Development Security Operations) solution that unifies security management at the code level across multicloud environments and multiple pipelines. 
  • Cloud security: Microsoft Defender for Cloud offers Cloud Security Posture Management (CSPM) and a Cloud Workload Protection Platform (CWPP). 
  • Workload protections: Microsoft Defender for Cloud offers workload protections for servers, containers, storage, databases, and other workloads. 
  • Hybrid cloud protection: Microsoft Defender for Cloud can protect hybrid cloud environments, including non-Azure machines and AWS and GCP accounts. 
  • Alert remediation: Microsoft Defender for Cloud provides actionable tasks to mitigate threats, prevent future attacks, and trigger automated responses. 

Lessons:

  • Explaining cloud workload protections in Microsoft Defender for Cloud
  • Connecting Azure resources to Microsoft Defender for Cloud
  • Connecting non-Azure resources to Microsoft Defender for Cloud
  • Managing cloud security posture
  • Microsoft Defender for Cloud workload protection
  • Remediating security alerts using Microsoft Defender for Cloud
  • Module Lab:
    • Lab 01: Mitigating threats with Microsoft Defender for Cloud

Unit 6: Building queries for Microsoft Sentinel using Kusto Query Language (KQL)

Module objectives:

  • KQL statements: Constructing KQL statements for Microsoft Sentinel. 
  • KQL operators: Using KQL operators such as summarize, render, union, join, and extend. 
  • KQL data extraction: Extracting data from unstructured and structured string fields using KQL. 
  • KQL functions: Creating functions and parsers using KQL. 
  • KQL Lab: Lab exercises to build queries for Microsoft Sentinel using KQL. 

Lessons:

  • Constructing KQL statements for Microsoft Sentinel
  • Using KQL to analyze query results
  • Using KQL to create multi-table statements
  • Working with string data using KQL statements
  • Module Labs: 
    • Lab 01: Building queries for Microsoft Sentinel using Kusto Query Language (KQL)

Unit 7: Configuring the Microsoft Sentinel environment

Module objectives:

  • Microsoft Sentinel: Microsoft Sentinel is a scalable, cloud-native solution that provides Security Information and Event Management (SIEM) and Security Orchestration, Automation, and Response (SOAR). 
  • Sentinel components: Microsoft Sentinel has several components, including data connectors, analytics, workbooks, analytics rules, hunting queries, notebooks, incidents and investigations, automation playbooks, and custom Azure Logic Apps connectors and watchlists. 
  • Using Sentinel: Microsoft Sentinel is a solution for performing security operations in on-premises and cloud environments. It can be used to collect event data from various sources and perform security operations on that data to identify suspicious activities. 
  • Sentinel watchlists: Microsoft Sentinel watchlists can be used to investigate threats, respond to incidents quickly, import business data, reduce alert fatigue, and enrich event data. 
  • Threat intelligence: Microsoft Sentinel allows you to manage threat indicators, view, sort, filter, and search imported threat indicators, and perform daily administrative tasks for threat intelligence.

Lessons:

  • Introduction to Microsoft Sentinel
  • Creating and managing Microsoft Sentinel workspaces
  • Querying logs in Microsoft Sentinel
  • Using watchlists in Microsoft Sentinel
  • Using threat intelligence in Microsoft Sentinel
  • The unified security operations platform
  • Module Lab:
    • Lab 1: Configuring the Microsoft Sentinel environment

Unit 8: Connecting logs to Microsoft Sentinel

Module objectives:

  • Sentinel connectors: Microsoft Sentinel provides various data connectors to connect logs and data sources
  • Content hub solutions: Content hub solutions include data connectors, parsers, workbooks, analytics rules, hunting queries, notebooks, watchlists, and playbooks
  • Data Collection Rules: Data Collection Rules (DCRs) are used to manage collection settings at scale, improve security and performance, and save costs.
  • Threat intelligence: The Threat Intelligence content hub solution provides connectors for TAXII platforms, Microsoft Defender Threat Intelligence, and Threat Intelligence
  • Microsoft Defender: Microsoft Sentinel provides built-in connectors for Microsoft Defender solutions, such as Microsoft Defender XDR, Microsoft Defender for Cloud, and Microsoft Defender for IoT

Lessons:

  • Content Management in Microsoft Sentinel
  • Connecting Data to Microsoft Sentinel using data connectors
  • Connecting Microsoft services to Microsoft Sentinel
  • Connecting Microsoft Defender XDR to Microsoft Sentinel
  • Connecting Windows hosts to Microsoft Sentinel
  • Connecting Common Event Format logs to Microsoft Sentinel
  • Connecting Syslog data sources to Microsoft Sentinel
  • Connecting threat indicators to Microsoft Sentinel
  • Module Lab:
    • Lab 01: Connecting logs to Microsoft Sentinel

Unit 9: Creating Detections and Performing Investigations with Microsoft Sentinel

Module Objectives:

  • Analytics Rules: Microsoft Sentinel analytics analyze data from various sources to identify correlations and anomalies. It also provides various types of analytics rules.
  • Automation: Microsoft Sentinel provides automation options such as automation rules and playbooks to automate incident handling.
  • Incident Management: Microsoft Sentinel provides incident management capabilities, including evidence and entity management, as well as incident investigation and resolution.
  • Data Normalization: Microsoft Sentinel provides data normalization capabilities, including the use of ASIM parsers and parameterized KQL functions.

Lessons

  • Threat detection with Microsoft Sentinel analytics
  • Automation in Microsoft Sentinel
  • Threat response with Microsoft Sentinel playbooks
  • Managing security incidents in Microsoft Sentinel
  • Entity behavior analytics in Microsoft Sentinel
  • Data normalization in Microsoft Sentinel
  • Querying, visualizing, and monitoring data in Microsoft Sentinel
  • Module Lab:
    • Lab 01: Creating Detections and Performing Investigations with Microsoft Sentinel

Unit 10: Performing Threat Hunting in Microsoft Sentinel

Module Objectives:

  • Threat Hunting: Learn how to perform threat hunting in Microsoft Sentinel using queries, bookmarks, live streaming, and MITRE ATT&CK
  • Hunting Tools: Use tools such as notebooks, hunting jobs, and external tools to hunt for threats in Microsoft Sentinel
  • Threat Hunting Hypothesis: Develop a threat hunting hypothesis that is feasible, narrow in scope, time-bound, useful, effective, and related to the threat model.

Lessons

  • Explanation of Threat Hunting Concepts in Microsoft Sentinel
  • Threat Hunting with Microsoft Sentinel
  • Using Hunting Jobs in Microsoft Sentinel
  • Optional: Threat Hunting with Notebooks in Microsoft Sentinel
  • Module Lab:
    • Lab 1: Threat Hunting in Microsoft Sentinel

 

Prerequisites

  • Basic knowledge of Microsoft Defender
  • Basic knowledge of Microsoft identity, compliance, and security products
  • Intermediate knowledge of Windows 11, Linux, and Windows Server
  • Familiarity with Microsoft Azure and Microsoft Defender portals and services
  • Familiarity with Azure Monitoring and Azure Log Analytics
  • Familiarity with Azure Virtual Machines
  • Basic knowledge of scripting concepts

 

Language

  • Course: English / Spanish
  • Labs: English / Spanish

 

Microsoft Certified: Security Operations Analyst Associate

Microsoft Associate certification

Microsoft Certified: Security Operations Analyst Associate

Manage security operations environments. Configure protections and detections. Manage incident responses. Perform threat hunting

Level: Intermediate
Role: Security Engineer, Security Operations Analyst
Product: Azure, Microsoft 365
Subject: Security

 

Related Microsoft Certification: Cybersecurity Architect Expert

Complete one prerequisite:

Pass one exam:

Get certified:

  • Microsoft Certified: Cybersecurity Architect Expert
Microsoft Expert certification

 

💡 Did you know this course is included in LaaS Cert?

Take this course and many more with our LaaS Cert annual license . Unlimited training for only €1,295!

✅ Microsoft, Linux-LPI, SCRUM, ITIL and Nanfor technical courses

✅ Personalized support always by your side

✅ 100% online, official and updated

Get your license now!

LaaS cert Formación ilimitada

Information related to training

Soporte siempre a tu lado

Training support

Always by your side

Modalidades Formativas

Training modalities

Self Learning - Virtual - In-person - Telepresence

bonificaciones

Bonuses

For companies