Search icon CANCEL
Arrow left icon
Explore Products
Best Sellers
New Releases
Books
Videos
Audiobooks
Learning Hub
Conferences
Free Learning
Arrow right icon
Arrow up icon
GO TO TOP
Microsoft Cybersecurity Architect Exam Ref SC-100

You're reading from   Microsoft Cybersecurity Architect Exam Ref SC-100 Get certified with ease while learning how to develop highly effective cybersecurity strategies

Arrow left icon
Product type Paperback
Published in Jan 2023
Publisher Packt
ISBN-13 9781803242392
Length 272 pages
Edition 1st Edition
Arrow right icon
Author (1):
Arrow left icon
Dwayne Natwick Dwayne Natwick
Author Profile Icon Dwayne Natwick
Dwayne Natwick
Arrow right icon
View More author details
Toc

Table of Contents (20) Chapters Close

Preface 1. Part 1: The Evolution of Cybersecurity in the Cloud
2. Chapter 1: Cybersecurity in the Cloud FREE CHAPTER 3. Part 2: Designing a Zero-Trust Strategy and Architecture
4. Chapter 2: Building an Overall Security Strategy and Architecture 5. Chapter 3: Designing a Security Operations Strategy 6. Chapter 4: Designing an Identity Security Strategy 7. Part 3: Evaluating Governance, Risk, and Compliance (GRC) Technical Strategies and Security Operations Strategies
8. Chapter 5: Designing a Regulatory Compliance Strategy 9. Chapter 6: Evaluating the Security Posture and Recommending Technical Strategies to Manage Risk 10. Part 4: Designing Security for Infrastructure
11. Chapter 7: Designing a Strategy for Securing Server and Client Endpoints 12. Chapter 8: Designing a Strategy for Securing SaaS, PaaS, and IaaS 13. Part 5: Designing a Strategy for Data and Applications
14. Chapter 9: Specifying Security Requirements for Applications 15. Chapter 10: Designing a Strategy for Securing Data 16. Chapter 11: Case Study Responses and Final Assessment/Mock Exam 17. Index 18. Other Books You May Enjoy Appendix: Preparing for Your Microsoft Exam

Evaluating a security operations strategy for the incident management life cycle

The life cycle of managing an incident response can be viewed as a tiered approach. The more prepared security operations are for identifying and responding to threats, the lower the impact on the business from a financial, personal, and reputational perspective.

Figure 3.13 shows the tiers of the various security operations functions:

Figure 3.13 – Security operations functional tiers

Figure 3.13 – Security operations functional tiers

As shown in Figure 3.13, automation in the workflow is important to managing the efficiency of a security operations team. The more automated responses that can be put in place for well-known attacks, such as phishing-based URLs, SQL injection attacks, brute-force identity attacks, or port scans, can use solutions. An example would be a Web Application Firewall (WAF), which protects against SQL injections, or Microsoft Defender for Office 365, which protects against phishing. Another...

lock icon The rest of the chapter is locked
Register for a free Packt account to unlock a world of extra content!
A free Packt account unlocks extra newsletters, articles, discounted offers, and much more. Start advancing your knowledge today.
Unlock this book and the full library FREE for 7 days
Get unlimited access to 7000+ expert-authored eBooks and videos courses covering every tech area you can think of
Renews at €18.99/month. Cancel anytime