What You'll Learn

  • Implement incident response procedures
  • manage incidents
  • and automate responses using playbooks and logic apps.
  • Collect and analyze security data
  • build queries
  • create analytics rules
  • and investigate incidents using Microsoft Sentinel.
  • Use Microsoft security tools to assess
  • monitor
  • and strengthen an organization’s overall security posture.
  • Detect
  • investigate
  • and respond to threats using Microsoft Defender for Endpoint
  • Defender for Identity
  • and Defender for Office 365.

Requirements

  • Learners should have a foundational understanding of Microsoft security
  • compliance
  • and identity solutions
  • and familiarity with Microsoft 365 and Azure environments.

Description

Skills at a glance

  • Manage a security operations environment (20–25%)

  • Configure protections and detections (15–20%)

  • Manage incident response (25–30%)

  • Manage security threats (15–20%)

Manage a security operations environment

Configure settings in Microsoft Defender XDR

  • Configure alert and vulnerability notification rules

  • Configure Microsoft Defender for Endpoint advanced features

  • Configure endpoint rules settings

  • Manage automated investigation and response capabilities in Microsoft Defender XDR

  • Configure automatic attack disruption in Microsoft Defender XDR

Manage assets and environments

  • Configure and manage device groups, permissions, and automation levels in Microsoft Defender for Endpoint

  • Identify unmanaged devices in Microsoft Defender for Endpoint

  • Discover unprotected resources by using Defender for Cloud

  • Identify and remediate devices at risk by using Microsoft Defender Vulnerability Management

  • Mitigate risk by using Exposure Management in Microsoft Defender XDR

Design and configure a Microsoft Sentinel workspace

  • Plan a Microsoft Sentinel workspace

  • Configure Microsoft Sentinel roles

  • Specify Azure RBAC roles for Microsoft Sentinel configuration

  • Design and configure Microsoft Sentinel data storage, including log types and log retention

Ingest data sources in Microsoft Sentinel

  • Identify data sources to be ingested for Microsoft Sentinel

  • Implement and use Content hub solutions

  • Configure and use Microsoft connectors for Azure resources, including Azure Policy and diagnostic settings

  • Plan and configure Syslog and Common Event Format (CEF) event collections

  • Plan and configure collection of Windows Security events by using data collection rules, including Windows Event Forwarding (WEF)

  • Create custom log tables in the workspace to store ingested data

  • Monitor and optimize data ingestion

Configure protections and detections

Configure protections in Microsoft Defender security technologies

  • Configure policies for Microsoft Defender for Cloud Apps

  • Configure policies for Microsoft Defender for Office 365

  • Configure security policies for Microsoft Defender for Endpoints, including attack surface reduction (ASR) rules

  • Configure cloud workload protections in Microsoft Defender for Cloud

Configure detections in Microsoft Defender XDR

  • Configure and manage custom detection rules

  • Manage alerts, including tuning, suppression, and correlation

  • Configure deception rules in Microsoft Defender XDR

Configure detections in Microsoft Sentinel

  • Classify and analyze data by using entities

  • Configure and manage analytics rules

  • Query Microsoft Sentinel data by using ASIM parsers

  • Implement behavioral analytics

Manage incident response

Respond to alerts and incidents in the Microsoft Defender portal

  • Investigate and remediate threats by using Microsoft Defender for Office 365

  • Investigate and remediate ransomware and business email compromise incidents identified by automatic attack disruption

  • Investigate and remediate compromised entities identified by Microsoft Purview data loss prevention (DLP) policies

  • Investigate and remediate threats identified by Microsoft Purview insider risk policies

  • Investigate and remediate alerts and incidents identified by Microsoft Defender for Cloud workload protections

  • Investigate and remediate security risks identified by Microsoft Defender for Cloud Apps

  • Investigate and remediate compromised identities that are identified by Microsoft Entra ID

  • Investigate and remediate security alerts from Microsoft Defender for Identity

Respond to alerts and incidents identified by Microsoft Defender for Endpoint

  • Investigate device timelines

  • Perform actions on the device, including live response and collecting investigation packages

  • Perform evidence and entity investigation

Investigate Microsoft 365 activities

  • Investigate threats by using the unified audit log

  • Investigate threats by using Content Search

  • Investigate threats by using Microsoft Graph activity logs

Respond to incidents in Microsoft Sentinel

  • Investigate and remediate incidents in Microsoft Sentinel

  • Create and configure automation rules

  • Create and configure Microsoft Sentinel playbooks

  • Run playbooks on on-premises resources

Implement and use Microsoft Security Copilot

  • Create and use promptbooks

  • Manage sources for Security Copilot, including plugins and files

  • Integrate Security Copilot by implementing connectors

  • Manage permissions and roles in Security Copilot

  • Monitor Security Copilot capacity and cost

  • Identify threats and risks by using Security Copilot

  • Investigate incidents by using Security Copilot

Manage security threats

Hunt for threats by using Microsoft Defender XDR

  • Identify threats by using Kusto Query Language (KQL)

  • Interpret threat analytics in the Microsoft Defender portal

  • Create custom hunting queries by using KQL

Hunt for threats by using Microsoft Sentinel

  • Analyze attack vector coverage by using the MITRE ATT&CK matrix

  • Manage and use threat indicators

  • Create and manage hunts

  • Create and monitor hunting queries

  • Use hunting bookmarks for data investigations

  • Retrieve and manage archived log data

  • Create and manage search jobs

Create and configure Microsoft Sentinel workbooks

  • Activate and customize workbook templates

  • Create custom workbooks that include KQL

  • Configure visualizations


Who this course is for:

  • This certification is intended for security operations analysts and professionals working in a Security Operations Center (SOC) who are responsible for threat detection
  • incident response
  • and security monitoring in hybrid and cloud environments.
SC-200: Microsoft Security Operations Analyst May - 2025

Course Includes:

  • Price: FREE
  • Enrolled: 1457 students
  • Language: English
  • Certificate: Yes
  • Difficulty: Beginner
Coupon verified 01:13 AM (updated every 10 min)

Recommended Courses

MS-102: Microsoft 365 Administrator May - 2025
0
(0 Rating)
FREE

Crack the MS-102: 420+ Practice Questions with Explanations to Secure Your Microsoft 365 Administrator Certification

Enrolled
AZ-900: Microsoft Azure Fundamentals - May 2025
4.25
(4 Rating)
FREE

Crack the AZ-900: 410+ Practice Questions with Explanations to Secure Your Microsoft Azure Fundamentals Certification

Enrolled
PL-600: Microsoft Power Platform Solution Architect-May 2025
4.0
(1 Rating)
FREE

Crack the PL-600: 340+ Practice Questions with Explanations to Secure Your Power Platform Architect Certification

Enrolled
MB-310: Dynamics 365 Finance Functional Consultant - May2025
0
(0 Rating)
FREE

Crack the MB-310: 360+ Practice Questions with Explanations to Secure Your Dynamics 365 Finance Consultant Certification

Enrolled
MB-910: Microsoft Dynamics 365 Fundamentals (CRM) - May 2025
0
(0 Rating)
FREE

Crack the MB-910: 340+ Practice Questions with Explanations to Secure Your Microsoft Dynamics 365 CRM Certification

Enrolled
HR Маркетинг: Привлечение кандидатов через digital-каналы
0
(0 Rating)
FREE

Digital marketing, рекрутинг, бренд работодателя, соцсети, геймификация, контент, реклама, Tilda, аналитика HR, ATS, чат

Enrolled
PL-400: Microsoft Power Platform Developer - Jun/2025
0
(0 Rating)
FREE

Crack the PL-400: 360+ Practice Questions with Explanations to Secure Your Power Platform Developer Certification

Enrolled
PL-500: Power Automate RPA Developer - Jun/2025
0
(0 Rating)
FREE

Crack the PL-500: 360+ Practice Questions with Explanations to Secure Your Power Automate RPA Developer Certification

Enrolled
DP-900: Microsoft Azure Data Fundamental May - 2025
0
(0 Rating)
FREE

Crack the DP-900: 410+ Practice Questions with Explanations to Secure Your Microsoft Azure Data Certification

Enrolled

Previous Courses

Salesforce Admin Certification-Practise Test Questions
5.0
(5 Rating)
FREE

Salesforce Admin Exam Prep: Master Setup, Security, Automation & Reporting with Real Practice Tests

Enrolled
DP-100: Designing and Implementing a Data Science - May 2025
3.6666667
(2 Rating)
FREE

Crack the DP-100: 350+ Practice Questions with Explanations to Secure Your Microsoft Azure Data Science Certification

Enrolled
AZ-500: Microsoft Azure Security Technologies - May 2025
0
(0 Rating)
FREE

Crack the AZ-500: 370+ Practice Questions with Explanations to Secure Your Microsoft Azure Security Certification

Enrolled
AI-900: Microsoft Azure AI Fundamentals - May 2025
5.0
(1 Rating)
FREE

Crack the AI-900: 370+ Practice Questions with Explanations to Secure Your Microsoft Azure AI Fundamentals Certification

Enrolled
Data Based Decision Making and Cost-Benefit Analysis (CBA)
4.775
(18 Rating)
FREE

Data-Based Decision Making, Analyzing and Interpreting Data, Cost-Benefit Analysis (CBA), Data Driven Technologies

Enrolled
ONE DAY CODE | PHP Programming with Examples in One Day
4.25
(151 Rating)
FREE

100% PHP Bootcamp | Become a Web Developer with PHP Programming in ONE DAY | Learn Programming with Real Coding

Enrolled
Sales & Service Data Analysis & Analytics Expert Certificate
4.392857
(42 Rating)
FREE

Sales & Service Data Analysis, Data Based Decision Making, Data Collection, Data Analytics, Sales Forecasting

Enrolled
AMAZING | JavaScript Programming with Examples in One Day
4.32
(205 Rating)
FREE

JavaScript Bootcamp | Learning to JavaScript Programming with Programming Examples in One Day | Source Code Available

Enrolled
A Complete Guide to Java Programming with Examples
4.33
(320 Rating)
FREE
Category
Development, Programming Languages, Java
  • English
  • 28223 Students
A Complete Guide to Java Programming with Examples
4.33
(320 Rating)
FREE

100% Java Bootcamp | Learning to Java Programming in ONE DAY with Programming Examples | Source Code Available

Enrolled

Total Number of 100% Off coupon added

Till Date We have added Total 1902 Free Coupon. Total Live Coupon: 1902

Confused which course 100% Off coupon is live? Click Here

For More Updates Join Our Telegram Channel.