SC-5001: Configure SIEM security operations using Microsoft



Kursarrangør: Glasspaper AS
Sted: Oslo, Helsfyr
Oslo
Kursadresse: Brynsveien 12, 0667 Oslo (kart)
Type:Åpent kurs / gruppeundervisning
Studie / yrkesutdanning
Undervisningstid: kl 09:00 - 16:00
Varighet: 1 day
Pris: 9.500
Neste kurs: 20.09.2024 | Vis alle kursdatoer

We provide course about SC-5001: Configure SIEM security operations using Microsoft Sentinel. This one-day, instructor-led training is recommended as preparation for the assessment Configure SIEM security operations using Microsoft Sentinel.

Course description:
Get started with Microsoft Sentinel security operations by configuring the Microsoft Sentinel workspace, connecting Microsoft services and Windows security events to Microsoft Sentinel, configuring Microsoft Sentinel analytics rules, and responding to threats with automated responses.

Course content:
Module 1 - Create and manage Microsoft Sentinel workspaces:
• Learn about the architecture of Microsoft Sentinel workspaces to ensure you configure your system to meet your organization's security operations requirements.

Module 2 - Microsoft services to Microsoft Sentinel:
• Learn how to connect Microsoft 365 and Azure service logs to Microsoft Sentinel

Module 3 - Connect Windows hosts to Microsoft Sentinel:
• One of the most common logs to collect is Windows security events. Learn how Microsoft Sentinel makes this easy with the Security Events connector.

Module 4 - Threat detection with Microsoft Sentinel analytics:
• In this module, you learned how Microsoft Sentinel Analytics can help the SecOps team identify and stop cyber attacks

Module 5 - Automation in Microsoft Sentinel:
• By the end of this module, you'll be able to use automation rules in Microsoft Sentinel to automated incident management

Module 6 - Configure SIEM security operations using Microsoft Sentinel:
• In this module, you learned how to configure SIEM security operations using Microsoft Sentinel

Target audience:
Security engineer, security operations analyst

Level:
• Intermediate level

Prerequisites:
• Fundamental understanding of Microsoft Azure
• Basic understanding of Microsoft Sentinel
• Experience using Kusto Query Language (KQL) in Microsoft Sentinel

Language:
• English course material, english or norwegian speaking instructor