Microsoft Security Operations Analyst

Join Microsoft Security Operations Analyst, Exam SC-200 Instructor-led batches in Pune, India

24 hours or 6 weekends 
In Shared or 1 to 1  
Shared batch fee: Rs. 29900 ($469 USD)
1 to 1: Rs. 44000 ($690 USD)

Please WhatsApp us on number +91-8888092582 before sending payment.

GPay, PhonePe, Paytm or Amazon Pay on +91-8888092582. Please view our refund policy »

SC-200: Exam SC-200: Microsoft Security Operations Analyst training in Pune You will get an experience investigating, responding to, and hunting for threats using Microsoft Sentinel, Microsoft Defender for Cloud, Microsoft 365 Defender, and third-party security products. As a security operations analyst, you will also have knowledge of configuring and deploying these technologies.

You will learn to mitigate threats using Microsoft 365 Defender; mitigate threats using Microsoft Defender for Cloud; and mitigate threats using Microsoft Sentinel.

Prerequisites

  • IT professionals with minimum 1 year experience
  • Working knowledge of networking, server administration, DNS, and PowerShell
  • Should know the Windows Server, domain environment, Active Directory administration. Complete our Windows administration course.
Skills measured:
  • Mitigate threats using Microsoft 365 Defender (25–30%)
  • Mitigate threats using Microsoft Defender for Cloud (20–25%)
  • Mitigate threats using Microsoft Sentinel (50–55%)
Sr. Details

1

Mitigate threats using Microsoft 365 Defender (25—30%)

Mitigate threats to the productivity environment by using Microsoft 365 Defender
  • Investigate, respond, and remediate threats to Microsoft Teams, SharePoint, and OneDrive
  • Investigate, respond, and remediate threats to email by using Microsoft Defender for Office 365
  • Investigate and respond to alerts generated from Data Loss Prevention policies
  • Investigate and respond to alerts generated from insider risk policies
  • Identify, investigate, and remediate security risks by using Microsoft Defender for Cloud Apps
  • Configure Microsoft Defender for Cloud Apps to generate alerts and reports to detect threats

Mitigate endpoint threats by using Microsoft Defender for Endpoint
  • Manage data retention, alert notification, and advanced features
  • Recommend security baselines for devices
  • Respond to incidents and alerts
  • Manage automated investigations and remediations
  • Assess and recommend endpoint configurations to reduce and remediate vulnerabilities by using the Microsoft's threat and vulnerability management solution
  • Manage endpoint threat indicators

Mitigate identity threats
  • Identify and remediate security risks related to Azure AD Identity Protection events
  • Identify and remediate security risks related to conditional access events
  • Identify and remediate security risks related to Azure Active Directory events
  • Identify and remediate security risks related to Active Directory Domain Services using Microsoft Defender for Identity

Manage extended detection and response (XDR) in Microsoft 365 Defender
  • Manage incidents across Microsoft 365 Defender products
  • Manage investigation and remediation actions in the Action Center
  • Perform threat hunting
  • Identify and remediate security risks using Microsoft Secure Score
  • Analyze threat analytics
  • Configure and manage custom detections and alerts

2

Mitigate threats using Microsoft Defender for Cloud (20—25%)

Implement and maintain cloud security posture management and workload protection
  • Plan and configure Microsoft Defender for Cloud settings, including selecting target subscriptions and workspaces
  • Configure Microsoft Defender for Cloud roles
  • Assess and recommend cloud workload protection
  • Identify and remediate security risks using the Microsoft Defender for Cloud Secure Score
  • Manage policies for regulatory compliance
  • Review and remediate security recommendations

Plan and implement the use of data connectors for ingestion of data sources in Microsoft Defender for Cloud
  • Identify data sources to be ingested for Microsoft Defender for Cloud
  • Configure automated onboarding for Azure resources
  • Connect multi-cloud and on-premises resources
  • Configure data collections

Configure and respond to alerts and incidents in Microsoft Defender for Cloud
  • Validate alert configuration
  • Set up email notifications
  • Create and manage alert suppression rules
  • Design and configure workflow automation in Microsoft Defender for Cloud
  • Remediate alerts and incidents by using Microsoft Defender for Cloud recommendations
  • Manage security alerts and incidents
  • Analyze Microsoft Defender for Cloud threat intelligence reports
  • Manage user data discovered during an investigation

3

Mitigate threats using Microsoft Sentinel (50—55%)

Design and configure a Microsoft Sentinel workspace
  • Plan a Microsoft Sentinel workspace
  • Configure Microsoft Sentinel roles
  • Design and configure Microsoft Sentinel data storage
  • Implement and use Content hub, repositories, and community resources

Plan and implement the use of data connectors for ingestion of data sources in Microsoft Sentinel
  • Identify data sources to be ingested for Microsoft Sentinel
  • Identify the prerequisites for a Microsoft Sentinel data connector
  • Configure and use Microsoft Sentinel data connectors
  • Configure Microsoft Sentinel data connectors by using Azure Policy
  • Configure Microsoft Sentinel connectors for Microsoft 365 Defender and Microsoft Defender for Cloud
  • Design and configure Syslog and CEF event collections
  • Design and configure Windows Security event collections
  • Configure custom threat intelligence connectors

Manage Microsoft Sentinel analytics rules
  • Design and configure analytics rules
  • Activate Microsoft security analytics rules
  • Configure built-in scheduled queries
  • Configure custom scheduled queries
  • Define incident creation logic
  • Manage and use watchlists
  • Manage and use threat indicators

Perform data classification and normalization
  • Classify and analyze data by using entities
  • Create custom logs in Azure Log Analytics to store custom data
  • Query Microsoft Sentinel data by using Advanced SIEM Information Model (ASIM) parsers
  • Develop and manage ASIM parsers

Configure Security Orchestration, Automation, and Response (SOAR) in Microsoft Sentinel
  • Configure automation rules
  • Create and configure Microsoft Sentinel playbooks
  • Configure alerts and incidents to trigger automation
  • Use automation to remediate threats
  • Use automation to manage incidents

Manage Microsoft Sentinel incidents
  • Triage incidents in Microsoft Sentine
  • Investigate incidents in Microsoft Sentinel
  • Respond to incidents in Microsoft Sentinel
  • Investigate multi-workspace incidents
  • Identify advanced threats with Entity Behavior Analytics

Use Microsoft Sentinel workbooks to analyze and interpret data
  • Activate and customize Microsoft Sentinel workbook templates
  • Create custom workbooks
  • Configure advanced visualizations
  • View and analyze Microsoft Sentinel data using workbooks
  • Track incident metrics using the security operations efficiency workbook

Hunt for threats using Microsoft Sentinel
  • Create custom hunting queries
  • Run hunting queries manually
  • Monitor hunting queries by using Livestream
  • Configure and use MSTICPy in notebooks
  • Perform hunting by using notebooks
  • Track query results with bookmarks
  • Use hunting bookmarks for data investigations
  • Convert a hunting query to an analytical rule
After completing this training, you can appear the "Exam SC-200: Microsoft Security Operations Analyst". Exam details for Microsoft Security Operations Analyst (Exam SC-200):
  • Exam pricing:$165 USD per exam. In India current Microsoft exam fee is $80 per exam. Worldwide it may vary.
  • Total exam is of 1000 marks and you need to earn 700 marks to pass the exam.
  • You will get 55 to 60 questions in an approximate 2-2½ hours of duration and may change per exam basis.
  • Exam formats and question types: Mostly single or multiple choice, drag and drop, repeated answer choices and hands-on labs.
Click to view current exam offer »

Student Testimonials

Questions? Ask us: