Microsoft Cybersecurity Architect (SC-100)

This instructor-led Microsoft Cybersecurity Architect (SC-100) Pearson course prepares you for the Microsoft Exam SC-100 which includes designing a Zero Trust strategy and architecture; evaluating Governance Risk Compliance (GR) technical strategies and security operations strategies; designing security for infrastructure; and designing a strategy for data and applications.

This course is to provide you with all the tools you need to prepare for the SC-100 Microsoft Cybersecurity Architect exam.

Learning Outcomes:

Upon successful completion of this course, students should be able to:

  • Build an overall security strategy an architecture.
  • Design a security operations strategy.
  • Design an identity security strategy.
  • Design a regulatory compliance strategy.
  • Evaluate security posture and recommend technical strategies to manage risk.
  • Design a strategy for securing server and client endpoints.
  • Design a strategy for securing SaaS, PaaS, and IaaS services.
  • Specify security requirements for applications.
  • Design a strategy for securing data.
  • Microsoft Cybersecurity Reference Architectures and Microsoft cloud security benchmark best practices.
  • Recommend a secure methodology by using the Cloud Adoption Framework (CAF).
  • Recommend a ransomware strategy by using Microsoft Security Best Practices.

The exam voucher is included in the course package.

Duration

4 Days

Certificate​

Microsoft Certified: Cybersecurity Architect Expert

Governing Body

Microsoft

Lesson 1: Build an overall security strategy and architecture

  • Identify the integration points in an architecture by using Microsoft Cybersecurity Reference Architectures (MCRA)
  • MCRA and Cloud Adoption Framework Secure Methodology.
  • How to use the MCRA to identify integration points.
  • Translate business goals into security requirements
  • Translation process.
  • Translate security requirements into technical capabilities, including security services, security products and security processes
  • Requirement: Mitigate compromise of accounts using password spray and other credential compromise.
  • Requirement: Shorten response times to attacks across resources in the environment.
  • Requirement: Integrate network security into Infrastructure as a Code (IaC) automation.
  • Requirement: Enable eDiscovery processes for Office 365 data.
  • Design security for a resiliency strategy
  • Reducing risk by reducing critical security events.
  • Resilience requires shifting from a network-centric to an asset- and data-centric mindset.
  • Integrate a hybrid or multi-tenant environment into a security strategy
  • Develop a technical governance strategy for security
  • Summary
  • Case Study
  • Quiz

Lesson 2: Design a security operations strategy

  • Design a logging and auditing strategy to support security operations
  • Centralizing log collection.
  • Deciding which logs have security value.
  • Designing security operations use cases.
  • Determining log retention periods.
  • Develop security operations to support a hybrid or multi-cloud environment
  • Cross-platform log collection.
  • Cloud security posture management (CSPM).
  • Focus on identity.
  • Internet of Things (IoT)/Operational Technology (OT) coverage.
  • Design a strategy for SIEM and SOAR
  • Microsoft Security Operations Reference Architecture.
  • Ingest logs into your SIEM.
  • Automate, automate, automate.
  • Evaluate security workflows
  • General incident response workflow.
  • Automation, automation, automation (again).
  • Evaluate a security operations strategy for the incident management lifecycle
  • Microsoft’s approach to security incident management.
  • Detection and analysis.
  • Post-incident activity.
  • Evaluate a security operations strategy for sharing technical threat intelligence
  • Microsoft’s threat intelligence strategy.
  • Sharing technical threat intelligence in your organization.
  • Summary
  • Case Study
  • Quiz

Lesson 3: Design an identity security strategy

  • Design a strategy for access to cloud resources
  • Identity-related access controls.
  • Network-related access controls.
  • Coordinated identity and network access.
  • Interconnection and cross-service collaboration.
  • Assume-breach and explicitly verify.
  • People, process, and technology approach.
  • Recommend an identity store (tenants, B2B, B2C, and hybrid)
  • Foundational implementations.
  • External collaboration.
  • Recommend an authentication strategy
  • Enterprise accounts.
  • Specialized accounts.
  • Controlling authentication sessions.
  • Key recommendations.
  • Recommend an authorization strategy
  • Configuring access to support authorization.
  • Decentralized identities.
  • Key recommendations.
  • Design a strategy for conditional access
  • Key recommendations.
  • Design a strategy for role assignment and delegation
  • Delegating to non-administrators.
  • Delegating access to service providers.
  • Design security strategy for privileged-role access to infrastructure, including identity-based firewall rules and Azure PIM
  • Privileged Access Workstation (PAW).
  • Privileged Identity Management (PIM).
  • Microsoft Entra Permissions Management.
  • Key recommendations.
  • Design security strategy for privileged activities, including PAM, entitlement management, and cloud tenant administration
  • Privileged Access Workstation (PAM).
  • Privileged Identity Management (PIM).
  • Microsoft Entra Permission Management.
  • Summary
  • Case Study
  • Quiz

Lesson 4: Design a regulatory compliance strategy

  • Interpret compliance requirements and translate specific technical capabilities (new or existing)
  • Security compliance translation process.
  • Resolving conflicts between compliance and security.
  • Evaluate infrastructure compliance by using Microsoft Defender for Cloud
  • Interpret compliance scores and recommend actions to resolve issues or improve security
  • Design implementation of Azure Policy
  • Design for data residency requirements
  • Translate privacy requirements into requirements for security solutions
  • Security and privacy.
  • Summary
  • Case Study
  • Quiz

Lesson 5: Evaluate security posture and recommend technical strategies to manage risk

  • Evaluate security posture by using benchmarks (including Azure Security benchmarks for Microsoft Cloud security benchmark, ISO 27001, etc.)
  • Microsoft Cloud security benchmark.
  • Monitoring your MCSB compliance.
  • Industry standards.
  • Evaluate security posture by using Microsoft Defender for Cloud
  • Defender for Cloud.
  • Security posture management.
  • Considerations for multi-cloud.
  • Considerations for vulnerability assessment.
  • Evaluate security posture by using Secure Scores
  • Secure Score in Defender for Cloud.
  • Evaluate security posture of cloud workloads
  • Workload security.
  • Design security for an Azure Landing Zone
  • Design principles.
  • Enforcing guardrails.
  • Single management plane.
  • Application–centric.
  • Security considerations.
  • Interpret technical threat intelligence and recommend risk mitigations
  • Threat intelligence in Defender for Cloud.
  • Threat intelligence in Microsoft Sentinel.
  • Recommend security capabilities or controls to mitigate identified risks
  • Identifying and mitigating risks.
  • Summary
  • Case Study
  • Quiz

Lesson 6: Design a strategy for securing server and client endpoints

  • Specify security baselines for server and client endpoints
  • Group Policy Objects (GPO).
  • Security Compliance Toolkit (SCT).
  • Azure Security Benchmark (ASB).
  • Microsoft Endpoint Manager (MEM).
  • PowerShell DSC.
  • Azure Automation.
  • Azure Policy.
  • Azure Resource Manager (ARM) templates.
  • Microsoft Defender for Cloud (MDC).
  • Microsoft Defender for IoT (MDIoT).
  • Baseline configuration.
  • Key Recommendations.
  • Specify security requirements for servers, including multiple platforms and operating systems
  • Shared responsibility in the cloud.
  • Legacy insecure protocols.
  • Threat protection.
  • Local Administrator Password Management (LAPS).
  • User rights assignments.
  • Network-based controls.
  • Specify security requirements for mobile devices and clients, including endpoint protection, hardening, and configurations
  • Local Administrator Password Management.
  • Basic Mobility and Security.
  • Threat protection.
  • Conditional access.
  • Microsoft Intune.
  • User rights assignments.
  • Micro-segmentation.
  • Other security controls.
  • Specify requirements to secure Active Directory Domain Services
  • Secure the control plane.
  • Privileged Access Management.
  • Key recommendations.
  • Microsoft Defender for Identity.
  • Active Directory Federation Services (AD FS).
  • Design a strategy to manage secrets, keys, and certificates
  • Access control.
  • Configuration control.
  • Key management.
  • Key recommendations.
  • Design a strategy for secure remote access
  • Key configurations to enable secure remote access.
  • Remote access to desktop, applications, and data.
  • Remote access to on-premises web applications.
  • RDP/SSH connectivity.
  • Remotely provisioning new devices.
  • B2B collaboration.
  • Key recommendations.
  • Summary
  • Case Study
  • Quiz

Lesson 7: Design a strategy for securing SaaS, PaaS, and IaaS services

  • Specify security baselines for SaaS, PaaS, and IaaS services
  • Specify security baselines for SaaS services.
  • Specify security requirements for IoT workloads
  • Security requirements.
  • Security posture and threat detection.
  • Specify security requirements for data workloads, including SQL, Azure SQL Database, Azure Synapse, and Azure Cosmos DB
  • Security considerations for Azure Cosmos DB.
  • Specify security requirements for web workloads, including Azure App Service
  • Network communication.
  • Authentication and authorization.
  • Security posture and threat protection.
  • Specify security requirements for storage workloads, including Azure Storage
  • Data protection.
  • Identity and access management.
  • Logging and monitoring.
  • Specify security requirements for containers
  • Hardening access to Azure Container Registry.
  • Specify security requirements for container orchestration
  • Threat detection.
  • Summary
  • Case Study
  • Quiz

Lesson 8: Specify security requirements for applications

  • Specify priorities for mitigating threats to applications
  • Classifying applications.
  • Application threat modeling.
  • Microsoft Security Development Lifecycle (SDL).
  • Specify a security standard for onboarding a new application
  • Old versus new.
  • Security standards for onboarding applications.
  • Specify a security strategy for applications and APIs
  • Waterfall to Agile/DevOps.
  • Security in DevOps (DevSecOps).
  • Summary
  • Case Study
  • Quiz

Lesson 9: Design a strategy for securing data

  • Specify priorities for mitigating threats to data
  • Common threats.
  • Design a strategy to identify and protect sensitive data
  • Know your data.
  • Protect your data.
  • Prevent data loss.
  • Govern your data.
  • Specify an encryption standard for data at rest and in motion
  • Encrypt at rest.
  • Encryption in motion.
  • Summary
  • Case Study
  • Quiz

Lesson 10: Microsoft Cybersecurity Reference Architectures and Microsoft cloud security benchmark best practices

  • Recommend best practices for cybersecurity capabilities and controls
  • Recommend best practices for protecting from insider and external attacks
  • Recommend best practices for Zero Trust security
  • Recommend best practices for the Zero Trust Rapid Modernization Plan
  • Summary
  • Case Study
  • Quiz

Lesson 11: Recommend a secure methodology by using the Cloud Adoption Framework (CAF)

  • Recommend a DevSecOps process
  • DevSecOps Control.
  • Plan and develop.
  • Commit the code.
  • Build and test.
  • Go to production and operate.
  • Recommend a methodology for asset protection
  • Getting secure.
  • Staying secure.
  • Key recommendations for an asse protection program
  • Recommend strategies for managing and minimizing risk
  • Measuring risk.
  • Managing security risk.
  • Summary
  • Case Study
  • Quiz

Lesson 12: Recommend a ransomware strategy by using Microsoft Security Best Practices

  • Plan for ransomware protection and extortion-based attacks
  • Security hygiene and damage control.
  • Protect assets from ransomware attacks
  • Enter environment.
  • Traverse and spread.
  • Execute objective.
  • Recommend Microsoft ransomware best practices
  • Best practices.
  • Summary
  • Case Study
  • Quiz

Suitable for

  • Students with advanced experience and knowledge in a wide range of security engineering areas, including identity and access, platform protection security operations, securing data, and securing applications.

Pre-requisite

  • 3-5 years of experience in a wide range or security engineering areas
  • Experience with hybrid and cloud implementations

Course Price

Original price was: RM3,630.00.Current price is: RM3,300.00.

Popular Courses