
educationApr 9, 202622:04pending
Course 29 - AZ-500 Microsoft Azure Security Technologies | Episode 10: Azure Security Monitoring and Threat Response
About this episode
In this lesson, you’ll learn about managing security operations and advanced threat protection in Microsoft Azure:Vulnerability Management & Governance
You can listen and download our episodes for free on more than 10 different platforms:
https://linktr.ee/cybercode_academy
- Identifying and remediating weaknesses:
- Qualys for vulnerability scanning
- Enforcing security standards through:
- Azure Security Center policies
- Grouping policies into initiatives
- Assigning them at management group level for consistency
- Implementing Just-in-Time (JIT) VM access:
- Keeping management ports (RDP / SSH) closed by default
- Opening access only when requested and for a limited time
- How it works:
- Temporarily creates NSG rules
- Automatically removes them after access expires
- Benefits:
- Reduces exposure to brute-force attacks
- Minimizes attack surface
- Using Security Center for behavioral analytics and threat intelligence
- Detecting suspicious activities such as:
- Use of hacking tools
- Unauthorized processes or anomalies
- Managing alerts:
- Categorized by severity levels
- Grouped into security incidents for full attack visibility
- Leveraging Microsoft Sentinel:
- SIEM (Security Information & Event Management):
- Collecting and analyzing logs at scale
- Correlating events across systems
- SOAR (Security Orchestration, Automation, and Response):
- Automating responses using playbooks
- Built on Azure Logic Apps
- SIEM (Security Information & Event Management):
- Key capabilities:
- Threat hunting using advanced queries
- Automated incident response workflows
- Centralized security operations
- Configuring:
- Security policies and initiatives
- JIT access for VMs
- Alert rules and incident tracking
- Onboarding resources into Sentinel:
- Connecting data sources
- Triggering and investigating alerts
- Automating remediation
- Security operations visibility + automation + control
- JIT access significantly reduces attack exposure
- Security Center provides threat detection and posture management
- Microsoft Sentinel enables full SOC capabilities in the cloud
You can listen and download our episodes for free on more than 10 different platforms:
https://linktr.ee/cybercode_academy
Hosts & guests
No transcript yet
This episode has not been transcribed. Request it and it moves to the front of the queue.
More episodes
More from CyberCode Academy

Course 42 - Mobile Malware Analysis Fundamentals | Episode 9: Mastering Basic St...
CyberCode Academy
Sep 5, 202621:16completed

Course 42 - Mobile Malware Analysis Fundamentals | Episode 8: Static Analysis of...
CyberCode Academy
Sep 4, 202621:15completed

Course 42 - Mobile Malware Analysis Fundamentals | Episode 7: Malware Tools and...
CyberCode Academy
Sep 3, 202621:03completed

Course 42 - Mobile Malware Analysis Fundamentals | Episode 6: The Evolution and...
CyberCode Academy
Sep 2, 202622:42pending