Configure SIEM security operations using Microsoft Sentinel (SC-5001)

 

Course Overview

Get started with Microsoft Sentinel security operations by configuring the Microsoft Sentinel workspace, connecting Microsoft services and Windows security events to Microsoft Sentinel, configuring Microsoft Sentinel analytics rules, and responding to threats with automated responses.

Prerequisites

  • Fundamental understanding of Microsoft Azure
  • Basic understanding of Microsoft Sentinel
  • Experience using Kusto Query Language (KQL) in Microsoft Sentinel

Course Content

  • Create and manage Microsoft Sentinel workspaces
  • Connect Microsoft services to Microsoft Sentinel
  • Connect Windows hosts to Microsoft Sentinel
  • Threat detection with Microsoft Sentinel analytics
  • Automation in Microsoft Sentinel
  • Configure SIEM security operations using Microsoft Sentinel
 

Beschikbare data

Gegarandeerde training:   The course is guaranteed to run regardless of the number of participants. This excludes unforeseeable events (e.g. accident, illness of the trainer) which make it impossible to carry out the course.
Instructor-led Online Training::   Course conducted online in a virtual classroom.

Engels

Tijdzone: Midden-Europese Zomertijd (MEZT)

Online training 9:00 – 17:00 Tijdzone: Midden-Europese Zomertijd (MEZT) Taal: Engels Gegarandeerde doorgang

1 uur tijdsverschil

Online training 9:00 – 13:00 Tijdzone: Greenwich Mean Time (GMT) Taal: Engels
Online training 9:00 – 12:00 Tijdzone: Greenwich Mean Time (GMT) Taal: Engels
Online training 9:00 – 12:00 Tijdzone: British Summer Time (BST) Taal: Engels
Online training 9:00 – 12:00 Tijdzone: British Summer Time (BST) Taal: Engels