________________________________________________________________
Do you want to take this course in another training mode?
Contact us
Other modes: Telepresence - Classroom
________________________________________________________________
SC-200 Course: Defend against cyberthreats with Microsoft's security operations platform
Learn to investigate, hunt for, and respond to threats using Microsoft Sentinel, Microsoft Defender for Cloud, and Microsoft 365 Defender. In this course, you will learn to mitigate cyberthreats using these technologies. Specifically, you will configure and use Microsoft Sentinel, as well as the Kusto Query Language (KQL), to perform detection, analysis, and reporting. The course is designed for individuals in a security operations job role and helps students prepare for the SC-200: Microsoft Security Operations Analyst exam.
Virtual course with included certification exam as a gift. Don't miss this opportunity! The exam is valued at €126 + VAT and is included at no additional cost.
Promotion valid until December 31, 2026. One-attempt exam available only in Virtual - Remote Training mode. Not applicable to Self-Learning mode.
Level: Intermediate - Product: Azure Microsoft 365 - Role: Security Engineer, Security Operations Analyst
⏱️
Course duration:
100 hours
🔑
Access to the classroom:
3 months
Microsoft Security Operations Analyst - Cloud Security - SOC Analyst - Microsoft Defender - Azure Sentinel - Incident Response - Threat Detection - SIEM - SOAR
Course audience
The Microsoft Security Operations Analyst role collaborates with organizational stakeholders to secure the organization's information technology systems. Their goal is to reduce organizational risk by rapidly remediating active attacks in the environment, advising on improvements to threat protection procedures, and communicating organizational policy violations to relevant stakeholders. Responsibilities include managing and monitoring threats and responding to them using various security solutions in the environment. The role is primarily concerned with investigating and detecting threats, as well as responding to them, using Microsoft Sentinel, Microsoft Defender for Cloud, Microsoft 365 Defender, and third-party security products. Since the security operations analyst will be using the operational results of these tools, they are also a key stakeholder in the configuration and implementation of these technologies.
Course objectives
-
Investigate and mitigate threats: You will learn to use tools such as Microsoft Sentinel, Microsoft Defender XDR, and Microsoft Defender for Cloud to investigate, hunt for, and respond to threats.
-
Configure and manage Microsoft Sentinel: You will configure your environment in Microsoft Sentinel, manage log connections, and create queries using Kusto Query Language (KQL).
-
Manage threat mitigation: You will use Microsoft Defender XDR, Microsoft Purview, and Microsoft Defender for Endpoint to manage threat mitigation.
-
Threat hunting: You will perform advanced threat hunting using threat intelligence and KQL for detection, analysis, and reporting.
SC-200 Training Elements
- SC-200: Mitigate threats using Microsoft Defender XDR (6 Modules)
- SC-200: Mitigate threats using Microsoft Security Copilot (5 Modules)
- SC-200: Mitigate threats using Microsoft Purview (4 Modules)
- SC-200: Mitigate threats using Microsoft Defender for Endpoint (9 Modules)
- SC-200: Mitigate threats using Microsoft Defender for Cloud (6 Modules)
- SC-200: Building queries for Microsoft Sentinel using Kusto Query Language (KQL) (4 Modules)
- SC-200: Configuring the Microsoft Sentinel environment (6 Modules)
- SC-200: Connecting logs to Microsoft Sentinel (7 Modules)
- SC-200: Creating detections and performing investigations using Microsoft Sentinel (8 Modules)
- SC-200: Threat hunting in Microsoft Sentinel (4 Modules)
SC-200 Course Content: Defend against cyberthreats with Microsoft's security operations platform
Unit 1: Mitigating threats with Microsoft Defender XDR
Module objectives:
- Microsoft Defender XDR: Microsoft Defender XDR is a solution that helps mitigate threats and risks using various tools and functionalities.
- Threat investigation: Microsoft Defender XDR provides tools for threat investigation, including the Microsoft Security Graph API and advanced hunting capabilities.
- Incident management: Microsoft Defender XDR enables incident management, including automatic attack disruption and alert investigation.
- Office 365 protection: Microsoft Defender for Office 365 provides capabilities for filtering, attack simulation, and risk remediation.
- Identity protection: Microsoft Defender for Identity and Entra ID Protection provide tools to protect identities, detect risks, and remediate threats.
Lessons:
- Understanding threat protection with Microsoft Defender XDR
- Mitigating incidents with Microsoft Defender XDR
- Remediating risks with Defender for Office 365 in Microsoft Defender XDR
- Microsoft Defender for Identity in Microsoft Defender XDR
- Protecting identities with Entra ID Protection
- Defender for Cloud Apps in Microsoft Defender XDR
- Course Labs:
- Lab 01: Mitigating threats with Microsoft Defender XDR
Unit 2: Introduction to Microsoft Security Copilot
Module objectives:
- How to describe Microsoft Copilot in Microsoft Defender XDR
- How to describe Microsoft Copilot in Microsoft Purview
- How to describe Microsoft Copilot in Microsoft Entra
Lessons:
- Generative AI basics
- Description of Microsoft Security Copilot
- Description of Microsoft Security Copilot's core features
- Description of Microsoft Security Copilot's integrated experiences
Unit 3: Mitigating threats with Microsoft Purview
Module objectives:
- Microsoft Purview: Microsoft Purview provides compliance solutions to mitigate threats.
- Content Search: Content Search is a key feature in the Microsoft 365 Compliance Center for quick searches across all content.
- Auditing Solutions: Microsoft Purview provides two auditing solutions: Audit (Standard) and Audit (Premium).
- Audit (Standard): Audit (Standard) is enabled by default and provides the ability to log and search audited activities.
- Audit (Premium): Audit (Premium) builds on Audit (Standard) by providing advanced auditing functionalities.
Lessons:
- Microsoft Purview compliance solutions
- Investigating and remediating compromised entities identified by Microsoft Purview data loss prevention (DLP) policies
- Investigating and remediating insider risk threats identified by Microsoft Purview policies
- Investigating threats using Content Search in Microsoft Purview
- Investigating threats using Microsoft Purview Audit (Standard)
- Investigating threats using Microsoft Purview Audit (Premium)
Unit 4: Mitigating threats with Microsoft Defender for Endpoint
Module objectives:
- Defender for Endpoint: Microsoft Defender for Endpoint is a platform designed to help enterprise networks prevent, detect, investigate, and respond to advanced threats on their endpoints.
- Threat Management: Defender for Endpoint provides advanced, near real-time, and actionable attack detections.
Device onboarding: Devices can be monitored using
- Microsoft Defender for Endpoint through the Defender for Endpoint portal.
- Attack Surface Reduction: Attack surface reduction rules can be enabled on Windows devices to reduce the attack surface.
- Vulnerability Management: Defender Vulnerability Management uses built-in, agentless scanners to continuously monitor and detect risk across your organization, even when devices are not connected to the corporate network.
Lessons:
- Threat protection with Microsoft Defender for Endpoint
- Implementing the Microsoft Defender for Endpoint environment
- Implementing Windows security enhancements
- Performing device investigations
- Performing actions on a device
- Performing evidence and entity investigations
- Configuring and managing automation
- Configuring alerts and detections
- Using Threat and Vulnerability Management
- Module Lab:
- Lab 01: Mitigating threats with Microsoft Defender for Endpoint
Unit 5: Mitigating threats with Microsoft Defender for Cloud
Course objectives:
- Defender for Cloud: Microsoft Defender for Cloud is a DevSecOps (Development Security Operations) solution that unifies security management at the code level across multicloud environments and multiple pipelines.
- Cloud security: Microsoft Defender for Cloud offers Cloud Security Posture Management (CSPM) and a Cloud Workload Protection Platform (CWPP).
- Workload protections: Microsoft Defender for Cloud offers workload protections for servers, containers, storage, databases, and other workloads.
- Hybrid cloud protection: Microsoft Defender for Cloud can protect hybrid cloud environments, including non-Azure machines and AWS and GCP accounts.
- Alert remediation: Microsoft Defender for Cloud provides actionable tasks to mitigate threats, prevent future attacks, and trigger automated responses.
Lessons:
- Explaining cloud workload protections in Microsoft Defender for Cloud
- Connecting Azure resources to Microsoft Defender for Cloud
- Connecting non-Azure resources to Microsoft Defender for Cloud
- Managing cloud security posture
- Microsoft Defender for Cloud workload protection
- Remediating security alerts using Microsoft Defender for Cloud
- Module Lab:
- Lab 01: Mitigating threats with Microsoft Defender for Cloud
Unit 6: Building queries for Microsoft Sentinel using Kusto Query Language (KQL)
Module objectives:
- KQL statements: Constructing KQL statements for Microsoft Sentinel.
- KQL operators: Using KQL operators such as summarize, render, union, join, and extend.
- KQL data extraction: Extracting data from unstructured and structured string fields using KQL.
- KQL functions: Creating functions and parsers using KQL.
- KQL Lab: Lab exercises to build queries for Microsoft Sentinel using KQL.
Lessons:
- Constructing KQL statements for Microsoft Sentinel
- Using KQL to analyze query results
- Using KQL to create multi-table statements
- Working with string data using KQL statements
- Module Labs:
- Lab 01: Building queries for Microsoft Sentinel using Kusto Query Language (KQL)
Unit 7: Configuring the Microsoft Sentinel environment
Module objectives:
- Microsoft Sentinel: Microsoft Sentinel is a scalable, cloud-native solution that provides Security Information and Event Management (SIEM) and Security Orchestration, Automation, and Response (SOAR).
- Sentinel components: Microsoft Sentinel has several components, including data connectors, analytics, workbooks, analytics rules, hunting queries, notebooks, incidents and investigations, automation playbooks, and custom Azure Logic Apps connectors and watchlists.
- Using Sentinel: Microsoft Sentinel is a solution for performing security operations in on-premises and cloud environments. It can be used to collect event data from various sources and perform security operations on that data to identify suspicious activities.
- Sentinel watchlists: Microsoft Sentinel watchlists can be used to investigate threats, respond to incidents quickly, import business data, reduce alert fatigue, and enrich event data.
- Threat intelligence: Microsoft Sentinel allows you to manage threat indicators, view, sort, filter, and search imported threat indicators, and perform daily administrative tasks for threat intelligence.
Lessons:
- Introduction to Microsoft Sentinel
- Creating and managing Microsoft Sentinel workspaces
- Querying logs in Microsoft Sentinel
- Using watchlists in Microsoft Sentinel
- Using threat intelligence in Microsoft Sentinel
- The unified security operations platform
- Module Lab:
- Lab 1: Configuring the Microsoft Sentinel environment
Unit 8: Connecting logs to Microsoft Sentinel
Module objectives:
- Sentinel connectors: Microsoft Sentinel provides various data connectors to connect logs and data sources
- Content hub solutions: Content hub solutions include data connectors, parsers, workbooks, analytics rules, hunting queries, notebooks, watchlists, and playbooks
- Data Collection Rules: Data Collection Rules (DCRs) are used to manage collection settings at scale, improve security and performance, and save costs.
- Threat intelligence: The Threat Intelligence content hub solution provides connectors for TAXII platforms, Microsoft Defender Threat Intelligence, and Threat Intelligence
- Microsoft Defender: Microsoft Sentinel provides built-in connectors for Microsoft Defender solutions, such as Microsoft Defender XDR, Microsoft Defender for Cloud, and Microsoft Defender for IoT
Lessons:
- Content Management in Microsoft Sentinel
- Connecting Data to Microsoft Sentinel using data connectors
- Connecting Microsoft services to Microsoft Sentinel
- Connecting Microsoft Defender XDR to Microsoft Sentinel
- Connecting Windows hosts to Microsoft Sentinel
- Connecting Common Event Format logs to Microsoft Sentinel
- Connecting Syslog data sources to Microsoft Sentinel
- Connecting threat indicators to Microsoft Sentinel
- Module Lab:
- Lab 01: Connecting logs to Microsoft Sentinel
Unit 9: Creating Detections and Performing Investigations with Microsoft Sentinel
Module Objectives:
- Analytics Rules: Microsoft Sentinel analytics analyze data from various sources to identify correlations and anomalies. It also provides various types of analytics rules.
- Automation: Microsoft Sentinel provides automation options such as automation rules and playbooks to automate incident handling.
- Incident Management: Microsoft Sentinel provides incident management capabilities, including evidence and entity management, as well as incident investigation and resolution.
- Data Normalization: Microsoft Sentinel provides data normalization capabilities, including the use of ASIM parsers and parameterized KQL functions.
Lessons
- Threat detection with Microsoft Sentinel analytics
- Automation in Microsoft Sentinel
- Threat response with Microsoft Sentinel playbooks
- Managing security incidents in Microsoft Sentinel
- Entity behavior analytics in Microsoft Sentinel
- Data normalization in Microsoft Sentinel
- Querying, visualizing, and monitoring data in Microsoft Sentinel
- Module Lab:
- Lab 01: Creating Detections and Performing Investigations with Microsoft Sentinel
Unit 10: Performing Threat Hunting in Microsoft Sentinel
Module Objectives:
- Threat Hunting: Learn how to perform threat hunting in Microsoft Sentinel using queries, bookmarks, live streaming, and MITRE ATT&CK
- Hunting Tools: Use tools such as notebooks, hunting jobs, and external tools to hunt for threats in Microsoft Sentinel
- Threat Hunting Hypothesis: Develop a threat hunting hypothesis that is feasible, narrow in scope, time-bound, useful, effective, and related to the threat model.
Lessons
- Explanation of Threat Hunting Concepts in Microsoft Sentinel
- Threat Hunting with Microsoft Sentinel
- Using Hunting Jobs in Microsoft Sentinel
- Optional: Threat Hunting with Notebooks in Microsoft Sentinel
- Module Lab:
- Lab 1: Threat Hunting in Microsoft Sentinel
Prerequisites
- Basic knowledge of Microsoft Defender
- Basic knowledge of Microsoft identity, compliance, and security products
- Intermediate knowledge of Windows 11, Linux, and Windows Server
- Familiarity with Microsoft Azure and Microsoft Defender portals and services
- Familiarity with Azure Monitoring and Azure Log Analytics
- Familiarity with Azure Virtual Machines
- Basic knowledge of scripting concepts
Language
- Course: English / Spanish
- Labs: English / Spanish
Microsoft Certified: Security Operations Analyst Associate
Microsoft Certified: Security Operations Analyst Associate
Manage security operations environments. Configure protections and detections. Manage incident responses. Perform threat hunting
Level: Intermediate
Role: Security Engineer, Security Operations Analyst
Product: Azure, Microsoft 365
Subject: Security
Related Microsoft Certification: Cybersecurity Architect Expert
Complete one prerequisite:
Pass one exam:
Get certified:
- Microsoft Certified: Cybersecurity Architect Expert