Exam Ref SC-200 Microsoft Security Operations Analyst

Book description

Prepare for Microsoft Exam SC-200 and help demonstrate your real-world mastery of skills and knowledge required to work with stakeholders to secure IT systems, and to rapidly remediate active attacks. Designed for Windows administrators, Exam Ref focuses on the critical thinking and decision-making acumen needed for success at the Microsoft Certified Associate level.

Focus on the expertise measured by these objectives:

  • Mitigate threats using Microsoft 365 Defender

  • Mitigate threats using Azure Defender

  • Mitigate threats using Azure Sentinel

This Microsoft Exam Ref:

  • Organizes its coverage by exam objectives

  • Features strategic, what-if scenarios to challenge you

  • Assumes you have experience with threat management, monitoring, and/or response in Microsoft 365 environments

About the Exam

Exam SC-200 focuses on knowledge needed to detect, investigate, respond, and remediate threats to productivity, endpoints, identity, and applications; design and configure Azure Defender implementations; plan and use data connectors to ingest data sources into Azure Defender and Azure Sentinel; manage Azure Defender alert rules; configure automation and remediation; investigate alerts and incidents; design and configure Azure Sentinel workspaces; manage Azure Sentinel rules and incidents; configure SOAR in Azure Sentinel; use workbooks to analyze and interpret data; and hunt for threats in the Azure Sentinel portal.

About Microsoft Certification

Passing this exam fulfills your requirements for the Microsoft 365 Certified: Security Operations Analyst Associate certification credential, demonstrating your ability to collaborate with organizational stakeholders to reduce organizational risk, advise on threat protection improvements, and address violations of organizational policies.

See full details at: microsoft.com/learn

..

Table of contents

  1. Cover Page
  2. Title Page
  3. Copyright Page
  4. Contents at a glance
  5. Contents
  6. Acknowledgments
  7. About the authors
  8. Introduction
    1. Organization of this book
    2. Preparing for the exam
    3. Microsoft certification
    4. Errata, updates & book support
    5. Stay in touch
  9. Chapter 1. Mitigate threats using Microsoft 365 Defender
    1. Skill 1-1: Detect, investigate, respond, and remediate threats to the productivity environment using Microsoft Defender for Office 365
    2. Skill 1-2: Detect, investigate, respond, and remediate endpoint threats using Microsoft Defender for Endpoint
    3. Skill 1-3: Detect, investigate, respond, and remediate identity threats
    4. Skill 1-4: Manage cross-domain investigations in the Microsoft 365 Defender Security portal
    5. Thought experiment
    6. Thought experiment answers
    7. Chapter Summary
  10. Chapter 2. Mitigate threats using Azure Defender
    1. Skill 2-1: Design and configure an Azure Defender implementation
    2. Skill 2-2: Plan and implement the use of data connectors for ingestion of data sources in Azure Defender
    3. Skill 2-3: Manage Microsoft Defender for Cloud alert rules
    4. Skill 2-4: Configure automation and remediation
    5. Skill 2-5: Investigate Azure Defender alerts and incidents
    6. Thought experiment
    7. Thought experiment answers
    8. Chapter Summary
  11. Chapter 3. Mitigate threats using Azure Sentinel
    1. Skill 3-1: Design and configure an Azure Sentinel workspace
    2. Skill 3-2: Plan and implement the use of data connectors for the ingestion of data sources into Azure Sentinel
    3. Skill 3-3: Manage Azure Sentinel analytics rules
    4. Skill 3-4: Configure Security Orchestration, Automation, and Response (SOAR) in Azure Sentinel
    5. Skill 3-5: Manage Azure Sentinel incidents
    6. Skill 3-6: Use Azure Sentinel workbooks to analyze and interpret data
    7. Skill 3-7: Hunt for threats using the Azure Sentinel portal
    8. Thought experiment
    9. Thought experiment answers
    10. Chapter Summary
  12. Index
  13. Code Snippets

Product information

  • Title: Exam Ref SC-200 Microsoft Security Operations Analyst
  • Author(s): Yuri Diogenes, Jake Mowrer, Sarah Young
  • Release date: September 2021
  • Publisher(s): Microsoft Press
  • ISBN: 9780137568338