Description
Overview:
This learning path guides you in securing Azure services and workloads using Microsoft Cloud Security Benchmark controls in Microsoft Defender for Cloud via the Azure portal.
Prerequisites:
There are no prerequisites for the Microsoft SC-5002 course, “Secure Azure Services and Workloads with Microsoft Defender for Cloud”. However, to earn the Microsoft Applied Skills credential, candidates should be familiar with the following: Azure infrastructure as a service (IaaS) and platform as a service (PaaS). Security capabilities in Azure. Regulatory compliance standards
Outline:
1 – Examine Defender for Cloud regulatory compliance standards
- Regulatory compliance standards in Defender for Cloud
- Microsoft cloud security benchmark in Defender for Cloud
- Improve your regulatory compliance in Defender for Cloud
2 – Enable Defender for Cloud on your Azure subscription
- Connect your Azure subscriptions
3 – Filter network traffic with a network security group using the Azure portal
- Azure resource group
- Azure Virtual Network
- How network security groups filter network traffic
- Application security groups
4 – Create a Log Analytics workspace
- Log Analytics workspace
5 – Collect guest operating system monitoring data from Azure and hybrid virtual machines using Azure Monitor Agent
- Deploy the Azure Monitor Agent
- Collect data with Azure Monitor Agent
6 – Explore just-in-time virtual machine access
- Understand just-in-time virtual machine access
- Enable just-in-time access on virtual machines
7 – Configure Azure Key Vault networking settings
- Azure Key Vault basic concepts
- Best practices for Azure Key Vault
- Azure Key Vault network security
- Configure Azure Key Vault firewalls and virtual networks
- Azure Key Vault soft delete overview
- Virtual network service endpoints for Azure Key Vault
8 – Connect an Azure SQL server using an Azure Private Endpoint using the Azure portal
- Azure Private Endpoint
- Azure Private Link

