Chapter 2

Mitigate threats using Azure Defender

One critical component of any Security Operations Center (SOC) is the quality of the alert that is received from a given data source. The quality of the alert can be measured by the relevance of the information contained in the alert, how that alert reflects into the threat vectors of a cloud workload, and how these indications can help security operation analysts to investigate and respond to that alert. Azure Defender has different plans that offer threat detections for specific workloads, based on analytics that were created specifically for the threat vector of the workload’s type.

To mitigate threats using Azure Defender you must be able to design, configure, and manage the different types ...

Get Exam Ref SC-200 Microsoft Security Operations Analyst now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.