4Manage and monitor security posture
- 4.1Managing security posture with Defender for Cloud
Learn to identify risks with Defender CSPM, evaluate compliance against security frameworks, enable workload protection plans, connect hybrid/multicloud (AWS, GCP), configure Defender Vulnerability Management for Azure VMs, and discover unprotected assets with External Attack Surface Management (EASM).
- 4.2Event collection and automated response with Microsoft Sentinel
Learn Microsoft Sentinel, the cloud-native SIEM/SOAR: workspaces and roles, content hub, data connectors, Syslog/CEF and Windows Security events (data collection rules, WEF), custom log tables, automation rules and playbooks, data retention, and querying Purview Audit in Defender XDR.
- 4.3Microsoft Security Copilot
Learn Microsoft Security Copilot, which applies generative AI to security operations: configuring workspaces, managing permissions and roles, enabling and configuring plugins, and enabling and configuring Microsoft agents and Security Store agents.

