Azure Security Engineer Associate (AZ-500)
1 Manage Identity and Access
1-1 Implement and manage Azure Active Directory (Azure AD)
1-1 1 Configure Azure AD users and groups
1-1 2 Manage Azure AD roles and role-based access control (RBAC)
1-1 3 Implement and manage Azure AD identity protection
1-1 4 Configure and manage Azure AD conditional access policies
1-1 5 Implement and manage Azure AD Privileged Identity Management (PIM)
1-1 6 Configure and manage Azure AD B2B and B2C
1-1 7 Implement and manage Azure AD Connect
1-1 8 Configure and manage Azure AD Domain Services
1-2 Implement and manage hybrid identity
1-2 1 Configure and manage Azure AD Connect
1-2 2 Implement and manage password hash synchronization
1-2 3 Implement and manage pass-through authentication
1-2 4 Implement and manage federation
1-2 5 Configure and manage Azure AD Connect Health
1-3 Implement and manage multi-factor authentication (MFA)
1-3 1 Configure and manage Azure AD MFA
1-3 2 Implement and manage conditional access policies with MFA
1-3 3 Configure and manage MFA for on-premises users
1-4 Implement and manage Azure role-based access control (RBAC)
1-4 1 Configure and manage Azure RBAC roles and assignments
1-4 2 Implement and manage custom roles
1-4 3 Configure and manage resource locks
1-4 4 Implement and manage Azure Blueprints
1-5 Implement and manage Azure AD Privileged Identity Management (PIM)
1-5 1 Configure and manage PIM roles and assignments
1-5 2 Implement and manage PIM alerts and reports
1-5 3 Configure and manage PIM access reviews
2 Implement Platform Protection
2-1 Implement and manage network security
2-1 1 Configure and manage Azure Firewall
2-1 2 Implement and manage Azure DDoS protection
2-1 3 Configure and manage network security groups (NSGs)
2-1 4 Implement and manage Azure Network Watcher
2-1 5 Configure and manage Azure Bastion
2-1 6 Implement and manage Azure Private Link
2-1 7 Configure and manage Azure VPN Gateway
2-1 8 Implement and manage Azure ExpressRoute
2-2 Implement and manage storage security
2-2 1 Configure and manage Azure Storage account security
2-2 2 Implement and manage Azure Storage encryption
2-2 3 Configure and manage Azure Storage access control
2-2 4 Implement and manage Azure Storage firewalls and virtual networks
2-2 5 Configure and manage Azure Storage service encryption
2-3 Implement and manage virtual machine security
2-3 1 Configure and manage virtual machine (VM) security
2-3 2 Implement and manage VM encryption
2-3 3 Configure and manage VM access control
2-3 4 Implement and manage VM security baselines
2-3 5 Configure and manage VM extensions for security
2-4 Implement and manage container security
2-4 1 Configure and manage Azure Kubernetes Service (AKS) security
2-4 2 Implement and manage container image security
2-4 3 Configure and manage container registry security
2-4 4 Implement and manage container network security
2-5 Implement and manage application security
2-5 1 Configure and manage Azure Web Application Firewall (WAF)
2-5 2 Implement and manage Azure Application Gateway security
2-5 3 Configure and manage Azure Front Door security
2-5 4 Implement and manage Azure API Management security
3 Manage Security Operations
3-1 Implement and manage security monitoring
3-1 1 Configure and manage Azure Security Center
3-1 2 Implement and manage Azure Sentinel
3-1 3 Configure and manage Azure Monitor
3-1 4 Implement and manage Azure Log Analytics
3-1 5 Configure and manage Azure Activity Log
3-2 Implement and manage threat detection
3-2 1 Configure and manage Azure Advanced Threat Protection (ATP)
3-2 2 Implement and manage Azure Defender
3-2 3 Configure and manage Azure Security Center alerts
3-2 4 Implement and manage Azure Sentinel alerts
3-3 Implement and manage incident response
3-3 1 Configure and manage Azure Security Center incident response
3-3 2 Implement and manage Azure Sentinel incident response
3-3 3 Configure and manage Azure Automation for incident response
3-3 4 Implement and manage Azure Key Vault for incident response
3-4 Implement and manage compliance and governance
3-4 1 Configure and manage Azure Policy
3-4 2 Implement and manage Azure Blueprints
3-4 3 Configure and manage Azure Security Center compliance
3-4 4 Implement and manage Azure Information Protection (AIP)
4 Secure Data and Applications
4-1 Implement and manage encryption
4-1 1 Configure and manage Azure Key Vault
4-1 2 Implement and manage Azure Disk Encryption
4-1 3 Configure and manage Azure Storage encryption
4-1 4 Implement and manage Azure SQL Database encryption
4-1 5 Configure and manage Azure Cosmos DB encryption
4-2 Implement and manage data protection
4-2 1 Configure and manage Azure Backup
4-2 2 Implement and manage Azure Site Recovery
4-2 3 Configure and manage Azure Storage lifecycle management
4-2 4 Implement and manage Azure Information Protection (AIP)
4-3 Implement and manage application security
4-3 1 Configure and manage Azure Web Application Firewall (WAF)
4-3 2 Implement and manage Azure Application Gateway security
4-3 3 Configure and manage Azure Front Door security
4-3 4 Implement and manage Azure API Management security
4-4 Implement and manage identity and access for applications
4-4 1 Configure and manage Azure AD authentication for applications
4-4 2 Implement and manage OAuth2 and OpenID Connect
4-4 3 Configure and manage Azure AD B2B and B2C
4-4 4 Implement and manage Azure AD Conditional Access for applications
4-5 Implement and manage security for serverless computing
4-5 1 Configure and manage Azure Functions security
4-5 2 Implement and manage Azure Logic Apps security
4-5 3 Configure and manage Azure Event Grid security
4-5 4 Implement and manage Azure Service Bus security
Implement and Manage Threat Detection

Implement and Manage Threat Detection

Key Concepts

Detailed Explanation

Azure Security Center

Azure Security Center is a unified infrastructure security management system that provides advanced threat protection across your hybrid cloud workloads. It offers continuous assessment of your security posture, provides actionable recommendations, and integrates with other security tools to provide a comprehensive view of your security landscape. Azure Security Center helps in detecting, preventing, and responding to security threats.

Azure Sentinel

Azure Sentinel is a cloud-native security information and event management (SIEM) and security orchestration automated response (SOAR) solution. It provides intelligent security analytics and threat intelligence across the enterprise, helping to detect, investigate, and respond to security threats. Azure Sentinel integrates with various data sources, including Azure services and third-party solutions, to provide a holistic view of your security operations.

Microsoft Defender for Cloud

Microsoft Defender for Cloud is a security management and threat protection service that provides advanced threat detection and response capabilities. It continuously monitors your environment for potential threats and provides actionable insights to help you protect your resources. Microsoft Defender for Cloud integrates with Azure Security Center to offer enhanced security features and capabilities.

Threat Intelligence

Threat Intelligence is the collection, processing, and analysis of data related to potential or existing threats to your environment. It provides insights into the tactics, techniques, and procedures (TTPs) used by attackers, helping you to proactively identify and mitigate threats. Threat Intelligence can be integrated into Azure Security Center and Azure Sentinel to enhance their detection capabilities.

Incident Response

Incident Response is the process of identifying, analyzing, and mitigating security incidents. It involves a structured approach to responding to security breaches, including detection, containment, eradication, recovery, and post-incident activities. Effective incident response helps minimize the impact of security incidents and ensures a swift return to normal operations.

Examples and Analogies

Example: Azure Security Center

Imagine Azure Security Center as a security operations center (SOC) for your cloud environment. This SOC continuously monitors your resources, detects potential threats, and provides actionable recommendations to enhance security. Just like a SOC protects a physical facility, Azure Security Center safeguards your cloud infrastructure.

Example: Azure Sentinel

Consider Azure Sentinel as a sophisticated security operations center (SOC) for your entire enterprise. This SOC collects data from various sources, analyzes it for potential threats, and automates responses to common incidents. It acts as a centralized hub for all your security operations, providing visibility and control over your security posture.

Example: Microsoft Defender for Cloud

Think of Microsoft Defender for Cloud as a security guard that continuously patrols your environment. This guard monitors for suspicious activities, identifies potential threats, and provides actionable insights to help you protect your resources. Microsoft Defender for Cloud ensures that your environment remains secure and compliant with your security policies.

Example: Threat Intelligence

Imagine Threat Intelligence as a detective tool that collects and analyzes clues (data) about potential threats. This tool helps you piece together the story of what happened, identify suspicious activities, and uncover hidden threats. Threat Intelligence is like a detective's notebook that helps you solve security mysteries.

Example: Incident Response

Think of Incident Response as a fire department responding to a fire. The fire department follows a structured process to identify the fire, contain it, extinguish it, and recover from the damage. Effective incident response helps minimize the impact of the fire and ensures a swift return to normal operations. Similarly, incident response in cybersecurity helps minimize the impact of security incidents and ensures a swift return to normal operations.