SC-5001 Configure SIEM security operations using Microsoft Sentinel

Price
Net:
VAT:

Price
Price on Request

Duration
1 day

For companies and job seekers:
this course is 100% fundable!
 

Location

Course Language
English

Training Solutions
Online Live

Today, security incidents occur in a distributed, dynamic, and often simultaneous manner. Centralized evaluation provides an overview and turns data into usable security information.

Key topics

  • Role of SIEM in modern security architectures.
  • Technical setup of Microsoft Sentinel.
  • Connection and management of data sources.
  • Analysis, correlation, and prioritization of events.
  • Automated processes for security incidents.
  • Monitoring and fine-tuning detection rules.

Prerequisite
Basic knowledge of IT security, cloud technologies, and technical processes in IT operations.

Target audience
Security-oriented IT roles with responsibility for monitoring, analyzing, and responding to security-related events.

Clear processes, automated responses, and centralized transparency form the basis of stable security operations in complex cloud and hybrid environments.

Print as PDF
Course content
  • Planning the Microsoft Sentinel workspace
  • Creating a Sentinel workspace
  • Managing cross-tenant workspaces with Azure Lighthouse
  • Understanding Microsoft Sentinel permissions and roles
  • Managing Sentinel settings
  • Configuring logs
  • Set up Microsoft Office 365 connector
  • Connect Microsoft Entra Connector
  • Connect Microsoft Entra ID Protection connector
  • Connect Azure Activity Connector
  • Connection to Windows Security Events via AMA Connector
  • Connection to Security Events via Legacy Agent Connector
  • Collection of Sysmon event logs
  • Microsoft Sentinel Analytics
  • Analysis rules
  • Create rule with wizard
  • Manage rules
  • Understanding automation options
  • Define rules for automation
  • Set up SIEM security operations in Microsoft Sentinel

Frequently Asked Questions

  • A SIEM aggregates security events from various sources, helping organizations detect attacks more quickly and respond in a targeted manner. This training course demonstrates its practical use with Microsoft Sentinel.
  • The topics covered include data sets, analysis rules, workbooks, incident management, threat detection, automation, and the evaluation of security-related events.
  • Microsoft Sentinel collects and analyzes logs from various systems, detects suspicious activity, and helps security teams investigate security incidents.
  • A key focus is on integrating Microsoft 365 services, Azure resources, and other cloud and on-premises systems for centralized security monitoring.
  • Automated playbooks speed up the handling of recurring security incidents and support a rapid and standardized response to threats.
  • This training course teaches participants how to analyze alerts, identify patterns, and efficiently investigate security incidents using Microsoft Sentinel tools.
  • It is suitable for security operations centers, threat detection, incident response, and the centralized monitoring of modern Microsoft cloud and hybrid environments.
  • This course provides hands-on knowledge on configuring and using Microsoft Sentinel for security monitoring, threat detection, and incident management.

Do you have any further questions? Please contact us.