Close
Contact Us info@learnquest.com

??WelcomeName??
??WelcomeName??
« Important Announcement » Contact Us 877-206-0106 | USA Flag
Close
Close
Close
photo

Thank you for your interest in LearnQuest.

Your request is being processed and LearnQuest or a LearnQuest-Authorized Training Provider will be in touch with you shortly.

photo

Thank you for your interest in Private Training.

We look forward to helping you develop the perfect training solution to help you meet your company's goals.

For immediate assistance, speak with one of our representatives using the chat module below. Otherwise, LearnQuest or a LearnQuest-Authorized Training Provider will be in touch with you shortly.

Close
photo

Thank you for your interest in LearnQuest!

Now, you will be able to stay up-to-date on our latest course offerings, promotions, and training discounts. Watch your inbox for upcoming special offers.

title

Date: xxx

Location: xxx

Time: xxx

Price: xxx

Please take a moment to fill out this form. We will get back to you as soon as possible.

All fields marked with an asterisk (*) are mandatory.

Microsoft Security Operations Analyst

Price
165 USD
Not Applicable
LQEX-MOC-SC-200
Exam Vouchers
Microsoft

AWS Training Pass

Take advantage of flexible training options with the AWS Training Pass and get Authorized AWS Training for a full year.

Learn More

Prices reflect a 22.5% discount for IBM employees (wherever applicable).
Prices reflect a 24% discount for Kyndryl employees (wherever applicable).
Prices reflect the Accenture employee discount.
Prices shown are the special AWS Partner Prices.
Prices reflect the Capgemini employee discount.
Prices reflect the UPS employee discount.
Prices reflect the ??democompanyname?? employee discount.
GSA Private/Onsite Price: ??gsa-private-price??
For GSA pricing, please go to GSA Advantage.
 

Class Schedule

Delivery Formats

Sort results

Filter Classes

Guaranteed to Run

Modality

Location

Language

Date

View Global Schedule

Course Description

Overview

This exam measures your ability to accomplish the following technical tasks: mitigate threats using Microsoft 365 Defender; mitigate threats using Microsoft Defender for Cloud; and mitigate threats using Microsoft Sentinel.

You may be eligible for ACE college credit if you pass this certification exam.

Passing score: 700.
 

Objectives


 

Audience

  • The Microsoft security operations analyst collaborates with organizational stakeholders to secure information technology systems for the organization. Their goal is to reduce organizational risk by rapidly remediating active attacks in the environment, advising on improvements to threat protection practices, and referring violations of organizational policies to appropriate stakeholders.
  • Responsibilities include threat management, monitoring, and response by using a variety of security solutions across their environment. The role primarily investigates, responds to, and hunts for threats using Microsoft Sentinel, Microsoft Defender for Cloud, Microsoft 365 Defender, and third-party security products. Since the security operations analyst consumes the operational output of these tools, they are also a critical stakeholder in the configuration and deployment of these technologies.

Prerequisites

    • Candidates for this role should be familiar with attack vectors, cyberthreats, incident management, and Kusto Query Language (KQL). Candidates should also be familiar with Microsoft 365 and Azure services.

Topics

Mitigate threats using Microsoft 365 Defender (25—30%) Mitigate threats to the productivity environment by using Microsoft 365 Defender
  • Investigate, respond, and remediate threats to Microsoft Teams, SharePoint, and OneDrive
  • Investigate, respond, and remediate threats to email by using Microsoft Defender for Office 365
  • Investigate and respond to alerts generated from Data Loss Prevention policies
  • Investigate and respond to alerts generated from insider risk policies
  • Identify, investigate, and remediate security risks by using Microsoft Defender for Cloud Apps
  • Configure Microsoft Defender for Cloud Apps to generate alerts and reports to detect threats
Mitigate endpoint threats by using Microsoft Defender for Endpoint
  • Manage data retention, alert notification, and advanced features
  • Recommend security baselines for devices
  • Respond to incidents and alerts
  • Manage automated investigations and remediations
  • Assess and recommend endpoint configurations to reduce and remediate vulnerabilities by using the Microsoft's threat and vulnerability management solution
  • Manage endpoint threat indicators
Mitigate identity threats
  • Identify and remediate security risks related to Azure AD Identity Protection events
  • Identify and remediate security risks related to conditional access events
  • Identify and remediate security risks related to Azure Active Directory events
  • Identify and remediate security risks related to Active Directory Domain Services using Microsoft Defender for Identity
Manage extended detection and response (XDR) in Microsoft 365 Defender
  • Manage incidents across Microsoft 365 Defender products
  • Manage investigation and remediation actions in the Action Center
  • Perform threat hunting
  • Identify and remediate security risks using Microsoft Secure Score
  • Analyze threat analytics
  • Configure and manage custom detections and alerts
Mitigate threats using Microsoft Defender for Cloud (20—25%) Implement and maintain cloud security posture management and workload protection
  • Plan and configure Microsoft Defender for Cloud settings, including selecting target subscriptions and workspaces
  • Configure Microsoft Defender for Cloud roles
  • Assess and recommend cloud workload protection
  • Identify and remediate security risks using the Microsoft Defender for Cloud Secure Score
  • Manage policies for regulatory compliance
  • Review and remediate security recommendations
Plan and implement the use of data connectors for ingestion of data sources in Microsoft Defender for Cloud
  • Identify data sources to be ingested for Microsoft Defender for Cloud
  • Configure automated onboarding for Azure resources
  • Connect multi-cloud and on-premises resources
  • Configure data collections
Configure and respond to alerts and incidents in Microsoft Defender for Cloud
  • Validate alert configuration
  • Set up email notifications
  • Create and manage alert suppression rules
  • Design and configure workflow automation in Microsoft Defender for Cloud
  • Remediate alerts and incidents by using Microsoft Defender for Cloud recommendations
  • Manage security alerts and incidents
  • Analyze Microsoft Defender for Cloud threat intelligence reports
  • Manage user data discovered during an investigation
Mitigate threats using Microsoft Sentinel (50—55%) Design and configure a Microsoft Sentinel workspace
  • Plan a Microsoft Sentinel workspace
  • Configure Microsoft Sentinel roles
  • Design and configure Microsoft Sentinel data storage
  • Implement and use Content hub, repositories, and community resources
Plan and implement the use of data connectors for ingestion of data sources in Microsoft Sentinel
  • Identify data sources to be ingested for Microsoft Sentinel
  • Identify the prerequisites for a Microsoft Sentinel data connector
  • Configure and use Microsoft Sentinel data connectors
  • Configure Microsoft Sentinel data connectors by using Azure Policy
  • Configure Microsoft Sentinel connectors for Microsoft 365 Defender and Microsoft Defender for Cloud
  • Design and configure Syslog and CEF event collections
  • Design and configure Windows Security event collections
  • Configure custom threat intelligence connectors
Manage Microsoft Sentinel analytics rules
  • Design and configure analytics rules
  • Activate Microsoft security analytics rules
  • Configure built-in scheduled queries
  • Configure custom scheduled queries
  • Define incident creation logic
  • Manage and use watchlists
  • Manage and use threat indicators
Perform data classification and normalization
  • Classify and analyze data by using entities
  • Create custom logs in Azure Log Analytics to store custom data
  • Query Microsoft Sentinel data by using Advanced SIEM Information Model (ASIM) parsers
  • Develop and manage ASIM parsers
Configure Security Orchestration, Automation, and Response (SOAR) in Microsoft Sentinel
  • Configure automation rules
  • Create and configure Microsoft Sentinel playbooks
  • Configure alerts and incidents to trigger automation
  • Use automation to remediate threats
  • Use automation to manage incidents
Manage Microsoft Sentinel incidents
  • Triage incidents in Microsoft Sentinel
  • Investigate incidents in Microsoft Sentinel
  • Respond to incidents in Microsoft Sentinel
  • Investigate multi-workspace incidents
  • Identify advanced threats with Entity Behavior Analytics
Use Microsoft Sentinel workbooks to analyze and interpret data
  • Activate and customize Microsoft Sentinel workbook templates
  • Create custom workbooks
  • Configure advanced visualizations
  • View and analyze Microsoft Sentinel data using workbooks
  • Track incident metrics using the security operations efficiency workbook
Hunt for threats using Microsoft Sentinel
  • Create custom hunting queries
  • Run hunting queries manually
  • Monitor hunting queries by using Livestream
  • Configure and use MSTICPy in notebooks
  • Perform hunting by using notebooks
  • Track query results with bookmarks
  • Use hunting bookmarks for data investigations
  • Convert a hunting query to an analytical rule
Top 20 Training Industry Company - IT Training

Need Help?

Call us at 877-206-0106 or e-mail us at info@learnquest.com

Personalized Solutions

Need a personalized solution for your Training? Contact us, and one of our training advisors will help you find the best solution.

Contact Us

Need Help?

Do you have a question about the courses, instruction, or materials covered? Do you need help finding which course is best for you? We are here to help!

Talk to us

LearnPass Year-End Offer

Get Up to 25% Additional Training Funds Before the Year Ends!

Act Now

Self-Paced Training Info

Learn at your own pace with anytime, anywhere training

  • Same in-demand topics as instructor-led public and private classes.
  • Standalone learning or supplemental reinforcement.
  • e-Learning content varies by course and technology.
  • View the Self-Paced version of this outline and what is included in the SPVC course.
  • Learn more about e-Learning

Course Added To Shopping Cart

bla

bla

bla

bla

bla

bla

Exam Terms & Conditions

Vouchers expire 12 months from the date they are issued, unless otherwise specified in the terms and conditions. Voucher expiration dates cannot be extended. All sales are final.
Please refer to the full terms and conditions here.

Exam Terms & Conditions

??exam-warning??
??group-training-form-area??
??how-can-we-help-you-area??
??personalized-form-area??
??request-quote-area??

Sorry, there are no classes that meet your criteria.

Please contact us to schedule a class.
Close

self-paced
STOP! Before You Leave

Save 0% on this course!

Take advantage of our online-only offer & save 0% on any course !

Promo Code skip0 will be applied to your registration

Close
Nothing yet
here's the message from the cart

To view the cart, you can click "View Cart" on the right side of the heading on each page
Add to cart clicker.

Purchase Information

??elearning-coursenumber?? ??coursename??
View Cart

title

Date: xxx

Location: xxx

Time: xxx

Price: xxx

Please take a moment to fill out this form. We will get back to you as soon as possible.

All fields marked with an asterisk (*) are mandatory.

If you would like to request a quote for 5 or more students, please contact CustomerService@learnquest.com to be assigned an account representative.

Need more Information?

Speak with our training specialists to continue your learning journey.

 

Delivery Formats

Close

By submitting this form, I agree to LearnQuest's Terms and Conditions

heres the new schedule
This website uses third-party profiling cookies to provide services in line with the preferences you reveal while browsing the Website. By continuing to browse this Website, you consent to the use of these cookies. If you wish to object such processing, please read the instructions described in our Privacy Policy.
Your use of this LearnQuest site affirms your consent to our use of session and persistent cookies to track how you use our website.