{"product_id":"microsoft-security-operations-analyst-training-sc-200","title":"Defend Against Cyberthreats with Microsoft’s Security Operations Platform (SC-200)","description":"\u003cdiv\u003e\n\u003cp\u003eLearn how to investigate, respond to, and remediate threats using Microsoft's security operations tools and services. In this hands-on course, you'll use Microsoft Defender XDR, Microsoft Sentinel, Microsoft Defender for Endpoint, Microsoft Defender for Cloud, Microsoft Security Copilot, and Microsoft Purview to identify threats, analyze attack activity, and support incident response activities across hybrid and cloud environments.\u003c\/p\u003e\r\n\u003cp\u003eYou'll learn how to collect and analyze security data, create detections, investigate incidents, automate response actions, and proactively hunt for threats using Microsoft Sentinel and Kusto Query Language (KQL). The course also covers identity protection, endpoint security, cloud workload protection, data security investigations, and the use of AI-powered security tools to improve analyst productivity and investigation workflows.\u003c\/p\u003e\r\n\u003cp\u003eThis course helps prepare students for the Microsoft Certified: Security Operations Analyst Associate certification.\u003c\/p\u003e\n\u003c\/div\u003e\u003cdiv\u003e\n\u003ch3\u003eDefend Against Cyberthreats with Microsoft’s Security Operations Platform (SC-200) Benefits\u003c\/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003eYou Will Learn How To\u003c\/strong\u003e\u003c\/p\u003e\n\u003cp\u003eAfter completing this course, you will be able to:\u003c\/p\u003e\n\u003cul type=\"disc\"\u003e\n\u003cli\u003eMitigate threats using Microsoft Defender XDR\u003c\/li\u003e\n\u003cli\u003eInvestigate and remediate incidents across Microsoft security solutions\u003c\/li\u003e\n\u003cli\u003eUse Microsoft Security Copilot to support security operations workflows\u003c\/li\u003e\n\u003cli\u003eInvestigate data security and insider risk activities using Microsoft Purview\u003c\/li\u003e\n\u003cli\u003eProtect and investigate endpoints using Microsoft Defender for Endpoint\u003c\/li\u003e\n\u003cli\u003eSecure cloud workloads using Microsoft Defender for Cloud\u003c\/li\u003e\n\u003cli\u003eCreate and optimize Kusto Query Language (KQL) queries for Microsoft Sentinel\u003c\/li\u003e\n\u003cli\u003eConfigure and manage Microsoft Sentinel environments\u003c\/li\u003e\n\u003cli\u003eConnect data sources and security logs to Microsoft Sentinel\u003c\/li\u003e\n\u003cli\u003eCreate detections, automate response actions, and investigate incidents\u003c\/li\u003e\n\u003cli\u003ePerform proactive threat hunting using Microsoft Sentinel\u003c\/li\u003e\n\u003cli\u003eAnalyze security alerts, evidence, and threat intelligence to identify malicious activity\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003c\/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003ePrerequisites\u003c\/strong\u003e\u003c\/p\u003e\n\u003cp\u003eBefore attending this course, students should have:\u003c\/p\u003e\n\u003cp\u003e•    A basic understanding of Microsoft security technologies\u003cbr\u003e•    Familiarity with networking concepts and operating systems\u003cbr\u003e•    Knowledge of cloud computing concepts\u003cbr\u003e•    Experience with security operations concepts such as monitoring, investigation, and incident response\u003c\/p\u003e\n\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003c\/div\u003e\u003cdiv\u003e\u003ch3\u003eDefend Against Cyberthreats with Microsoft’s Security Operations Platform (SC-200) Training Outline\u003c\/h3\u003e\u003c\/div\u003e\u003cdiv\u003e\n\u003ch4\u003eCourse Outline\u003c\/h4\u003e\n\u003cp\u003e\u003cstrong\u003eMitigate Threats Using Microsoft Defender XDR\u003c\/strong\u003e\u003cbr\u003e•    Introduction to Microsoft Defender XDR threat protection\u003cbr\u003e•    Mitigate incidents using Microsoft Defender\u003cbr\u003e•    Remediate threats using Microsoft Defender\u003cbr\u003e•    Manage Microsoft Entra Identity Protection\u003cbr\u003e•    Safeguard your environment with Microsoft Defender for Identity\u003cbr\u003e•    Secure your cloud apps and services with Microsoft Defender for Cloud Apps\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003eMitigate Threats Using Microsoft Security Copilot\u003c\/strong\u003e\u003cbr\u003e•    Introduction to generative AI and agents\u003cbr\u003e•    Describe Microsoft Security Copilot\u003cbr\u003e•    Describe the core features of Microsoft Security Copilot\u003cbr\u003e•    Describe the embedded experiences of Microsoft Security Copilot\u003cbr\u003e•    Experience Security Copilot through guided simulations\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003eMitigate Threats Using Microsoft Purview\u003c\/strong\u003e\u003cbr\u003e•    Investigate and respond to Microsoft Purview Data Loss Prevention alerts\u003cbr\u003e•    Investigate insider risk alerts and related activity\u003cbr\u003e•    Search and investigate with Microsoft Purview Audit\u003cbr\u003e•    Search for content with Microsoft Purview eDiscovery\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003eMitigate Threats Using Microsoft Defender for Endpoint\u003c\/strong\u003e\u003cbr\u003e•    Protect against threats with Microsoft Defender for Endpoint\u003cbr\u003e•    Deploy the Microsoft Defender for Endpoint environment\u003cbr\u003e•    Implement Windows security enhancements\u003cbr\u003e•    Perform device investigations\u003cbr\u003e•    Perform device response actions\u003cbr\u003e•    Investigate evidence and entities\u003cbr\u003e•    Configure and manage automation\u003cbr\u003e•    Configure alerts and detections\u003cbr\u003e•    Utilize Vulnerability Management\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003eMitigate Threats Using Microsoft Defender for Cloud\u003c\/strong\u003e\u003cbr\u003e•    Plan cloud workload protections\u003cbr\u003e•    Connect Azure resources\u003cbr\u003e•    Connect non-Azure resources\u003cbr\u003e•    Manage cloud security posture\u003cbr\u003e•    Understand workload protection capabilities\u003cbr\u003e•    Remediate security alerts\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003eCreate Queries for Microsoft Sentinel Using Kusto Query Language\u003c\/strong\u003e\u003cbr\u003e•    Construct KQL statements\u003cbr\u003e•    Analyze query results\u003cbr\u003e•    Build multi-table queries\u003cbr\u003e•    Work with Microsoft Sentinel data using KQL\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003eConfigure Your Microsoft Sentinel Environment\u003c\/strong\u003e\u003cbr\u003e•    Introduction to Microsoft Sentinel\u003cbr\u003e•    Create and manage Sentinel workspaces\u003cbr\u003e•    Query logs in Microsoft Sentinel\u003cbr\u003e•    Use watchlists\u003cbr\u003e•    Utilize threat intelligence\u003cbr\u003e•    Integrate Microsoft Defender XDR with Microsoft Sentinel\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003eConnect Logs to Microsoft Sentinel\u003c\/strong\u003e\u003cbr\u003e•    Connect data using data connectors\u003cbr\u003e•    Connect Microsoft services\u003cbr\u003e•    Connect Microsoft Defender XDR\u003cbr\u003e•    Connect Windows hosts\u003cbr\u003e•    Connect Common Event Format (CEF) logs\u003cbr\u003e•    Connect Syslog data sources\u003cbr\u003e•    Connect threat intelligence indicators\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003eCreate Detections and Perform Investigations Using Microsoft Sentinel\u003c\/strong\u003e\u003cbr\u003e•    Threat detection with analytics rules\u003cbr\u003e•    Automation in Microsoft Sentinel\u003cbr\u003e•    Threat response with playbooks\u003cbr\u003e•    Security incident management\u003cbr\u003e•    Behavioral analytics\u003cbr\u003e•    Data normalization\u003cbr\u003e•    Query, visualize, and monitor data\u003cbr\u003e•    Manage Microsoft Sentinel content\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003ePerform Threat Hunting in Microsoft Sentinel\u003c\/strong\u003e\u003cbr\u003e•    Explain threat hunting concepts\u003cbr\u003e•    Threat hunting with Microsoft Sentinel\u003cbr\u003e•    Use Search Jobs\u003cbr\u003e•    Hunt for threats using notebooks\u003c\/p\u003e\n\u003c\/div\u003e","brand":"Microsoft","offers":[{"title":"269C49US \/ 2026-09-08T09:00:00 \/ Online","offer_id":44748299829384,"sku":"US-8591-IL","price":2080.0,"currency_code":"USD","in_stock":true},{"title":"26BB65US \/ 2026-11-03T09:00:00 \/ Herndon, VA","offer_id":44748299894920,"sku":"US-8591-IL","price":2080.0,"currency_code":"USD","in_stock":true},{"title":"271B53US \/ 2027-01-12T09:00:00 \/ Herndon, VA","offer_id":44748299927688,"sku":"US-8591-IL","price":2080.0,"currency_code":"USD","in_stock":true},{"title":"273B31US \/ 2027-03-09T09:00:00 \/ Herndon, VA","offer_id":44872449425544,"sku":"US-8591-IL","price":2080.0,"currency_code":"USD","in_stock":true},{"title":"275B50US \/ 2027-05-11T09:00:00 \/ Herndon, VA","offer_id":45575829291144,"sku":"US-8591-IL","price":2080.0,"currency_code":"USD","in_stock":true}],"url":"https:\/\/kpit.learningtree.com\/products\/microsoft-security-operations-analyst-training-sc-200","provider":"Learning Tree International","version":"1.0","type":"link"}