SecurityIntermediate
SC-200 Security Operations Analyst Associate
5 (114 reviews) 129 students 6 Weeks Intermediate

Instructor
Category
Security
Rating
5 (114)
Students
129
Language
English
Duration
6 Weeks
What you'll cover
1Security Operations Environment+
- Configure and manage Microsoft security solutions
- Understand Microsoft Defender XDR
- Configure Microsoft Sentinel
- Connect security data sources and services
- Manage security operations workflows
- Monitor and improve the security operations environment
2Microsoft Defender XDR+
- Investigate security alerts and incidents
- Analyze threats across Microsoft Defender XDR
- Investigate compromised identities and entities
- Use Microsoft Defender for Office 365
- Investigate Microsoft Defender for Cloud Apps alerts
- Manage and remediate security incidents
3Microsoft Defender for Endpoint+
- Investigate device alerts and incidents
- Analyze device timelines and security events
- Perform endpoint investigation and remediation
- Use live response on compromised devices
- Collect investigation packages and evidence
- Respond to endpoint threats and attack disruption
4Microsoft Sentinel and KQL+
- Configure Microsoft Sentinel workspaces
- Connect Microsoft and third-party data sources
- Create KQL queries for security analysis
- Build analytics and detection rules
- Investigate incidents and security events
- Use automation and playbooks for response
5Threat Detection and Incident Response+
- Investigate security alerts and incidents
- Analyze evidence, entities, and attack patterns
- Investigate multi-stage and lateral-movement attacks
- Respond to threats across cloud and on-premises environments
- Use case management for security incidents
- Apply Microsoft Security Copilot for investigation suppor
6Threat Hunting and Advanced Investigation+
- Perform proactive threat hunting
- Create Advanced Hunting queries with KQL
- Identify suspicious activities and attack patterns
- Analyze threat analytics and entity relationships
- Use hunting graphs and Sentinel Graph
- Use notebooks and advanced hunting capabilities
