SC-200: สอบของนักวิเคราะห์ผ่านฟังก์ชันบันทึก
สิ่งที่ SC-200 ทดสอบจริง ๆ วิธีการแมปไปยัง Defender และ Sentinel workflows และวิธีการเตรียมตัวเหมือนนักวิเคราะห์ SOC ที่ทำงานจริง
SC-200 (Microsoft Security Operations Analyst) ได้รับการรับรองว่าคุณสามารถเรียกใช้ security operations workflow ภายในสแต็ก Microsoft: ตรวจจับ สืบสวน ตอบสนอง และค้นหาโดยใช้ Microsoft Sentinel, Microsoft Defender XDR และชุด Defender สำหรับ cloud, identity, endpoint และ Office 365 ไม่ใช่สอบทฤษฎีเกี่ยวกับแนวคิด security ในเชิงนามธรรม มันสร้างขึ้นโดยอ้อมวงของ Tier 1/Tier 2 analyst ที่ทำงานภายใน Defender และ Sentinel consoles
สิ่งที่สอบครอบคลุมจริง ๆ
แบบพิมพ์สอบแบ่งออกเป็นสามส่วน: บรรเทาภัยคุกคามด้วย Defender XDR บรรเทาภัยคุกคามด้วย Sentinel และการกำหนดค่าการป้องกัน/การตรวจจับในทั่วทั้ง Defender ecosystem ในทางปฏิบัติ หมายความว่าคุณต้องมีความรู้ในการใช้งาน:
- Microsoft Defender for Endpoint — device onboarding, attack surface reduction rules, automated investigation and remediation (AIR) และการอ่าน process trees ในมุมมอง incident
- Microsoft Defender for Identity — การทำความเข้าใจ lateral movement paths, Pass-the-Hash/Pass-the-Ticket alerts และวิธีการที่มันเชื่อมสัมพันธ์กับ on-prem AD signals
- Microsoft Defender for Cloud Apps — OAuth app governance, anomaly detection policies และ session control basics
- Microsoft Sentinel — data connectors, KQL-based analytics rules, workbooks, playbooks (Logic Apps) และ incident investigation graph
- Microsoft Defender for Cloud — regulatory compliance dashboards และ workload protection alerts สำหรับ VMs, storage และ containers
KQL ไม่ใช่ตัวเลือก
ถ้าคุณไม่สามารถเขียน Kusto Query Language ได้อย่างสบายใจ คุณจะประสบปัญหากับส่วนที่มีความหมายของสอบนี้ และสำคัญกว่านั้น กับงานจริง คุณควรจะเขียนคิวรีแบบนี้ได้จากความจำ ไม่ใช่แค่รู้จักเท่านั้น:
DeviceProcessEvents
| where FileName =~ "powershell.exe"
| where ProcessCommandLine has_any ("-enc", "-EncodedCommand", "IEX")
| project Timestamp, DeviceName, AccountName, ProcessCommandLine
| order by Timestamp desc
คาดหวังคำถาม scenario ที่คุณได้รับส่วนของคิวรี KQL และถูกขอให้แก้ไขข้อผิดพลาด syntax หรือคาดการณ์ผลลัพธ์ ฝึกฝน summarize, join, mv-expand และ time-window functions เช่น bin() — analytics rules ของ Sentinel ขึ้นอยู่กับสิ่งเหล่านี้อย่างมาก
การอ่าน incident เหมือนนักวิเคราะห์ ไม่ใช่ผู้ทำสอบ
คำถาม SC-200 จำนวนมากเสนอ Sentinel incident พร้อม correlated alerts หลายชุด และขอให้คุณระบุ entity, MITRE ATT&CK technique หรือขั้นตอน investigative ที่ถูกต้อง สิ่งนี้สะท้อนการแยกประเภทจริง: คุณกำลังหมุนระหว่าง alert timeline, entity page (user, host, IP) และ related incidents เพื่อสร้างเรื่องราว ใช้เวลาในพื้นที่ทำงาน Sentinel trial โดยคลิกผ่าน incidents จริงแทนที่จะเพียงแค่จดจำชื่อ alert — สอบให้รางวัล pattern recognition ที่สร้างขึ้นจากการทำซ้ำแบบ hands-on
Automation และ playbooks ปรากฏมากกว่าที่คนคาดหวัง
ผู้สมัครมักเตรียมตัวน้อยเกินไปสำหรับส่วน Logic Apps / playbook คุณควรรู้วิธีการที่ playbook ทริกเกอร์ off a Sentinel incident วิธีการส่ง incident entities (เช่น user หรือ IP) เข้าสู่ automated action เช่น disabling an account via Azure AD หรือ isolating a device via Defender for Endpoint และความแตกต่างระหว่าง automation rules และ playbooks — automation rules จัดการกับ routing/tagging/assignment logic, playbooks ดำเนินการขั้นตอน remediation จริง
เส้นทางการศึกษาในทางปฏิบัติ
- สปินอัป Azure subscription ฟรีและปรับใช้ Sentinel workspace พร้อม data connector อย่างน้อยหนึ่งตัว (Azure AD sign-in logs ใจดีให้เปิดใช้งาน)
- ทำผ่าน Microsoft Learn SC-200 learning path — มันฟรีและแมปไปยัง exam objectives โดยตรง
- สร้าง analytics rules ห้า หกตัวจากศูนย์โดยใช้ KQL ไม่ใช่ templates เพื่อให้คุณเข้าใจ query logic ข้างใต้
- ใช้ Microsoft's official practice assessment (ผ่าน Pearson VUE/MeasureUp) เมื่อคุณรู้สึกพร้อม — มันเข้าใกล้ actual question style มากกว่า third-party dumps ส่วนใหญ่
- ทบทวน MITRE ATT&CK tactic names เย็นชา คำถามมักขอให้คุณจัดประเภท observed behavior เข้าสู่ tactic (Initial Access, Persistence, Lateral Movement ฯลฯ) แทนที่จะตั้งชื่อ tactic อย่างชัดเจน
ใครที่ certification นี้ช่วยจริง ๆ
SC-200 เป็นสัญญาณที่แข็งแกร่งสำหรับ SOC analyst, security engineer หรือ incident responder roles ในองค์กรที่มุ่งมั่นกับสแต็ก security ของ Microsoft — ซึ่ง เมื่อพิจารณาจาก Defender และ Sentinel's market presence คือชิ้นส่วนใหญ่ของ enterprise environments ไม่ได้สอนคุณ general SOC theory วิธี GCIH หรือ Security+ อาจทำ แต่มันพิสูจน์ว่าคุณสามารถดำเนินการ tools ที่ SOC โฟกัส Microsoft จริง ๆ ทำงานบน
ถ้า detection engineering และ KQL จับความสนใจของคุณที่นี่ Korra Studio มี segments ที่เกี่ยวข้องในการสร้าง Sentinel analytics rules และใน MITRE ATT&CK mapping ที่คุ้มค่าที่จะตรวจสอบต่อไป
เขียนด้วยความช่วยเหลือของ AI ตรวจสอบและเผยแพร่โดย Michal Pilch (CISSP), Korra Studio
นี่คือบันทึกหนึ่งจากฐานความรู้ของ Korra Studio — แพลตฟอร์มจับคู่หัวข้อแต่ละหัวข้อกับการฝึกสอนแบบ 1-to-1
เริ่มใช้งานฟรีarrow_forward