Search icon CANCEL
Arrow left icon
Explore Products
Best Sellers
New Releases
Books
Videos
Audiobooks
Learning Hub
Conferences
Free Learning
Arrow right icon
Arrow up icon
GO TO TOP
Microsoft Cybersecurity Architect Exam Ref SC-100

You're reading from   Microsoft Cybersecurity Architect Exam Ref SC-100 Get certified with ease while learning how to develop highly effective cybersecurity strategies

Arrow left icon
Product type Paperback
Published in Jan 2023
Publisher Packt
ISBN-13 9781803242392
Length 272 pages
Edition 1st Edition
Arrow right icon
Author (1):
Arrow left icon
Dwayne Natwick Dwayne Natwick
Author Profile Icon Dwayne Natwick
Dwayne Natwick
Arrow right icon
View More author details
Toc

Table of Contents (20) Chapters Close

Preface 1. Part 1: The Evolution of Cybersecurity in the Cloud
2. Chapter 1: Cybersecurity in the Cloud FREE CHAPTER 3. Part 2: Designing a Zero-Trust Strategy and Architecture
4. Chapter 2: Building an Overall Security Strategy and Architecture 5. Chapter 3: Designing a Security Operations Strategy 6. Chapter 4: Designing an Identity Security Strategy 7. Part 3: Evaluating Governance, Risk, and Compliance (GRC) Technical Strategies and Security Operations Strategies
8. Chapter 5: Designing a Regulatory Compliance Strategy 9. Chapter 6: Evaluating the Security Posture and Recommending Technical Strategies to Manage Risk 10. Part 4: Designing Security for Infrastructure
11. Chapter 7: Designing a Strategy for Securing Server and Client Endpoints 12. Chapter 8: Designing a Strategy for Securing SaaS, PaaS, and IaaS 13. Part 5: Designing a Strategy for Data and Applications
14. Chapter 9: Specifying Security Requirements for Applications 15. Chapter 10: Designing a Strategy for Securing Data 16. Chapter 11: Case Study Responses and Final Assessment/Mock Exam 17. Index 18. Other Books You May Enjoy Appendix: Preparing for Your Microsoft Exam

Interpreting technical threat intelligence and recommending risk mitigations

Microsoft is at the forefront globally for reviewing and recognizing threats through its alliances and participation in the cyber threat intelligence (CTI) network. The information that is gathered through the CTI reports, communities, investigation feeds, and organizational security investigations are used within Microsoft’s cloud services for customers to identify threats and vulnerabilities within their environments.

SIEM solutions are the primary tools that customers can use for evaluating CTI. Within Microsoft and Azure, that solution is Microsoft Sentinel. Microsoft Sentinel utilizes CTI from a variety of security solutions within Microsoft and other third-party solutions to provide a single source to identify and interpret potential threats and attacks within your company environment.

Figure 6.24 shows this flow of information within Microsoft Sentinel:

 Figure 6.24 – Microsoft Sentinel tools for threat intelligence

...

lock icon The rest of the chapter is locked
Register for a free Packt account to unlock a world of extra content!
A free Packt account unlocks extra newsletters, articles, discounted offers, and much more. Start advancing your knowledge today.
Unlock this book and the full library FREE for 7 days
Get unlimited access to 7000+ expert-authored eBooks and videos courses covering every tech area you can think of
Renews at €18.99/month. Cancel anytime