Microsoft Security Operations Analyst Certification Course (SC-200)
Schedule
Wed, 26 Feb, 2025 at 09:00 am to Fri, 28 Feb, 2025 at 05:00 pm
UTC-05:00Location
Point Comfort Group | Indianapolis, IN
![Microsoft Security Operations Analyst Certification Course (SC-200)](https://cdn.happeningnext.com/events7/banners/3fdef5ccbeb33c3433d1715cd9cebc2b2a4cdcb46e2e5c0e42bed2f8429629a9-rimg-w1200-h675-dcffffff-gmir.jpg?v=1739018890)
About this Event
Microsoft Security Operations Analyst Certification Course (SC-200)
KEP Training is excited to offer the 3-day remote Microsoft Security Operations Analyst (SC-200) course, led by expert trainer Doyle Turner from Incremental Systems.
Duration: 3 Days
Delivery Method: Students can attend virtually or in-person in Indianapolis, IN.
Target Audience: Security operations analysts, IT professionals, and anyone preparing for the Microsoft Security Operations Analyst certification (SC-200).
Day 1: Understanding the Role and Core Concepts
Module 1: Introduction to Microsoft Security Operations
Overview of Security Operations Center (SOC)
Understanding the role of a Security Operations Analyst
Key concepts: Zero Trust, Defense in Depth, Incident Response lifecycle
Module 2: Introduction to Microsoft Sentinel
Overview of Microsoft Sentinel
Configuring Microsoft Sentinel workspaces
Data connectors: Ingesting data from Microsoft and third-party sources
Module 3: Managing Microsoft Sentinel
Creating and managing Analytics Rules
Incident creation and investigation basics
Building and visualizing workbooks for data insights
Lab:
Setting up a Microsoft Sentinel workspace and configuring data connectors
Creating analytics rules and exploring incidents
Day 2: Advanced Threat Detection and Incident Response
Module 4: Threat Hunting with Microsoft Sentinel
Understanding threat hunting principles
KQL (Kusto Query Language) for hunting
Building queries for threat analysis
Module 5: Automating Responses with Playbooks
Introduction to Logic Apps
Configuring and managing playbooks for automated responses
Real-world examples of automated incident handling
Module 6: Understanding Microsoft Defender Suite
Overview of Microsoft Defender for Endpoint, Office 365, Identity, and Cloud Apps
Integrating Defender tools with Microsoft Sentinel
Lab:
Hands-on threat hunting using KQL
Configuring a playbook to respond to a phishing attack
Day 3: Securing Environments and Exam Preparation
Module 7: Securing the Microsoft Environment
Understanding security policies and compliance requirements
Hardening identity and access management with Azure AD
Leveraging conditional access policies and MFA for security
Module 8: Incident Response and Forensics
Managing incidents across tools: Sentinel, Defender, and Azure
Post-incident analysis and forensics
Using advanced analytics to identify root causes
Module 9: Preparing for the SC-200 Exam
Overview of the SC-200 exam objectives
Practice exam questions and scenarios
Study strategies and tips from a Microsoft-certified expert
Lab:
Conducting a simulated incident investigation and response
Final exam practice lab
Course Wrap-Up
Key takeaways and next steps
Resources for continued learning: Microsoft Learn, blogs, and communities
Q&A session with the instructor
Where is it happening?
Point Comfort Group, 306 Prospect Street, Ste. 100, Indianapolis, United StatesEvent Location & Nearby Stays:
USD 850.17 to USD 1063.58
![Anna Kepshire, KEP Training](https://cdn.happeningnext.com/events6/banners/1545256e4cb8457c41d75c62f365fc6dc3b88f006a64f1c261c30f1fb6df0f16-rimg-w400-h400-gmir.png?v=1589408233)