Lesson 1: Build an Overall Security Strategy and Architecture
- Identify integration points using Microsoft Cybersecurity Reference Architectures (MCRA), including the MCRA and CAF Secure Methodology
- Translate business goals into security requirements and into technical capabilities
- Design security for a resiliency strategy, shifting from network-centric to asset/data-centric mindset
- Integrate a hybrid or multi-tenant environment into a security strategy
- Develop a technical governance strategy for security
Lesson 2: Design a Security Operations Strategy
- Design a logging and auditing strategy, including centralizing log collection and retention periods
- Develop security operations for hybrid/multi-cloud environments, including CSPM and IoT/OT coverage
- Design a strategy for SIEM and SOAR using the Microsoft Security Operations Reference Architecture
- Evaluate security workflows, incident response, and the incident management lifecycle
- Evaluate a strategy for sharing technical threat intelligence
Lesson 3: Design an Identity Security Strategy
- Design a strategy for access to cloud resources; recommend an identity store, authentication strategy, and authorization strategy
- Design a strategy for conditional access, role assignment, and delegation
- Design security strategy for privileged-role access to infrastructure and for privileged activities (PAM, entitlement management)
Lesson 4: Design a Regulatory Compliance Strategy
- Interpret compliance requirements and translate to technical capabilities
- Evaluate infrastructure compliance using Microsoft Defender for Cloud
- Design implementation of Azure Policy and for data residency requirements
- Translate privacy requirements into security solution requirements
Lesson 5: Evaluate Security Posture and Recommend Technical Strategies to Manage Risk
- Evaluate security posture using benchmarks, Microsoft Defender for Cloud, and Secure Scores
- Design security for an Azure Landing Zone
- Interpret technical threat intelligence and recommend risk mitigations
Lesson 6: Design a Strategy for Securing Server and Client Endpoints
- Specify security baselines and requirements for servers, mobile devices, and clients
- Specify requirements to secure Active Directory Domain Services
- Design a strategy to manage secrets, keys, and certificates, and for secure remote access
Lesson 7: Design a Strategy for Securing SaaS, PaaS, and IaaS Services
- Specify security baselines for SaaS, PaaS, and IaaS services
- Specify security requirements for IoT, data, web, storage, and container workloads
Lesson 8: Specify Security Requirements for Applications
- Specify priorities for mitigating threats to applications
- Specify a security standard for onboarding a new application
- Specify a security strategy for applications and APIs, including DevSecOps
Lesson 9: Design a Strategy for Securing Data
- Specify priorities for mitigating threats to data
- Design a strategy to identify and protect sensitive data
- Specify an encryption standard for data at rest and in motion
Lesson 10: Microsoft Cybersecurity Reference Architectures and Cloud Security Benchmark Best Practices
- Recommend best practices for cybersecurity capabilities and controls
- Recommend best practices for Zero Trust security and the Zero Trust Rapid Modernization Plan
Lesson 11: Recommend a Secure Methodology Using the Cloud Adoption Framework (CAF)
- Recommend a DevSecOps process
- Recommend a methodology for asset protection and strategies for managing risk
Lesson 12: Recommend a Ransomware Strategy Using Microsoft Security Best Practices
- Plan for ransomware protection and extortion-based attacks
- Protect assets from ransomware attacks
- Recommend Microsoft ransomware best practices