Exam cram series for SC-200 exam

Well, finally it’s time for a new part to my study series for Microsoft Security certifications. I have published guides for SC-100 and SC-300 and now it’s times for the “little” ‘sis between.

Hopefully you will find this helpful, giving back to the community, once again!

Candidates for the SC-200 exam should have a foundational understanding of security and compliance concepts, and should be familiar with attack vectors, cyberthreats, incident management, and Kusto Query Language (KQL).

Knowledge of Microsoft 365 and Azure services is also important, as the exam focuses on the security, compliance, and identity features and capabilities of the Microsoft 365 platform. It’s also important to have knowledge on cloud security, governance, risk management, compliance and regulatory requirements that are relevant to the Microsoft 365 platform.

Additionally, Familiarity with: Azure portal, Microsoft Defender for Cloud, Purview Information Protection, Microsoft Defender for Identity, Microsoft Sentinel, Azure Policy, Azure Policy Insights, Azure AD, Azure AD Identity Governance and Protection, Azure AD Conditional Access, Azure AD Privileged Identity Management (PIM) will be beneficial.

Let us begin!

Outline

SC-200 is just about to be updated and these are the skills measured from February 7th 2023 onward.

Mitigate threats using Microsoft 365 Defender (25–30%)

Mitigate threats to the productivity environment by using Microsoft 365 Defender

Mitigate endpoint threats by using Microsoft Defender for Endpoint

Mitigate identity threats

Manage extended detection and response (XDR) in Microsoft 365 Defender

Mitigate threats using Microsoft Defender for Cloud (20–25%)

Implement and maintain cloud security posture management and workload protection

Plan and implement the use of data connectors for ingestion of data sources in Microsoft Defender for Cloud

Configure and respond to alerts and incidents in Microsoft Defender for Cloud

Mitigate threats using Microsoft Sentinel (50–55%)

Design and configure a Microsoft Sentinel workspace

Plan and implement the use of data connectors for ingestion of data sources in Microsoft Sentinel

Manage Microsoft Sentinel analytics rules

Perform data classification and normalization

Configure Security Orchestration, Automation, and Response (SOAR) in Microsoft Sentinel

Manage Microsoft Sentinel incidents

Use Microsoft Sentinel workbooks to analyze and interpret data

Hunt for threats using Microsoft Sentinel

Final words

Prepare Yourself and take Your time during the test. I always dedicate my tests for Sundays, for some reason it has been an excellent day for me to focus.

I have heard some take these inside test facilities and that’s OK, what ever suits you!

#Neverstoplearning #Sharingiscaring

Author: Harri Jaakkonen

Leave a Reply

Your email address will not be published. Required fields are marked *