Defend against cyberthreats with Microsoft's security operations platform (SC-200T00)

H9P86S

Course ID

H9P86S

Duration

4 days

Format

ILT/VILT

Overview

Learn how to investigate, respond to, and hunt for threats using Microsoft Sentinel, Microsoft Defender XDR and MicrosoftDefender for Cloud. In this course you will learn how to mitigate cyberthreats using these technologies. Specifically, you will configure and use Microsoft Sentinel as well as utilize Kusto Query Language (KQL) to perform detection, analysis, and reporting. The course was designed for people who work in a Security Operations job role and helps learners prepare for the exam SC-200: Microsoft Security Operations Analyst.

Course ID

H9P86S

Duration

4 days

Format

ILT/VILT

  • Audience

    The Microsoft Security Operations Analyst collaborates with organizational stakeholders to secure information technology systems for the organization. Their goal is to reduce organizational risk by rapidly remediating active attacks in the environment, advising on improvements to threat protection practices, and referring violations of organizational policies to appropriate stakeholders. Responsibilities include threat management, monitoring, and response by using a variety of security solutions across their environment. The role primarily investigates, responds to, and hunts for threats using Microsoft Sentinel, Microsoft Defender XDR, Microsoft Defender for Cloud, and third-party security products. Since the Security Operations Analyst consumes the operational output of these tools, they are also a critical stakeholder in the configuration and deployment of these technologies.

  • Objectives

    After completing this course, you should be able to:

    • Protect data within Microsoft 365 collaboration environments from internal and external threats
    • Manage security alerts and respond to incidents by investigating activities, responding to DLP alerts, and managing insider risk cases
    • Protect data used by AI services within Microsoft environments and implement controls to safeguard content in these environments
  • Certifications and related exams

    This course prepares you for the following certification exam:

    • Microsoft Certified: Information Security Administrator Associate
Divider
  • Course outline

Module 1: Implement Microsoft Purview Information Protection


  • Protect sensitive data in a digital world
  • Classify data for protection and governance
  • Review and analyze data classification and protection
  • Create and manage sensitive information types
  • Create and configure sensitivity labels with Microsoft Purview
  • Apply sensitivity labels for data protection
  • Classify and protect on-premises data with Microsoft Purview
  • Understand Microsoft 365 encryption
  • Protect email with Microsoft Purview message encryption

Module 2: Implement and Manage Microsoft Purview Data Loss Prevention


  • Prevent data loss in Microsoft Purview
  • Implement endpoint data loss prevention (DLP) with Microsoft Purview
  • Configure DLP policies for Microsoft Defender for cloud apps and power platform
  • Investigate and respond to Microsoft Purview data loss prevention alerts

Module 3: Implement and Manage Microsoft Purview Insider Risk Management


  • Understand Microsoft Purview insider risk management
  • Prepare for Microsoft Purview insider risk management
  • Create and manage insider risk management policies
  • Investigate insider risk alerts and related activity
  • Implement adaptive protection in insider risk management

Module 4: Protect Data in AI Environments


  • Discover AI interactions with Microsoft Purview
  • Protect sensitive data from AI-related risks
  • Govern AI usage with Microsoft Purview
  • Assess and mitigate AI risks with Microsoft Purview

Module 5: Implement and Manage Retention and Recovery

  • Understand retention in Microsoft Purview
  • Implement and manage retention and recovery in Microsoft Purview

Module 6: Audit & Search Activity

  • Search and investigate with Microsoft Purview audit
  • Search for content with Microsoft Purview eDiscovery

5 reasons to choose HPE as your training partner

  1. Learn HPE and in-demand IT industry technologies from expert instructors.
  2. Build career-advancing power skills.
  3. Enjoy personalized learning journeys aligned to your company’s needs.
  4. Choose how you learn: in-person , virtually , or online —anytime, anywhere.
  5. Sharpen your skills with access to real environments in virtual labs .

Explore our simplified purchase options, including HPE Education Services – Learning Credits .

Recommended for you