- Level Professional
- Duration 18 hours
- Course by Microsoft
-
Offered by
About
Are you a security engineer who wants to learn how to lock down the infrastructure and network resources running in your Azure environment? Then, Implement Platform Protection is the right course for you! Throughout this course, you will explore perimeter security, network security, and host and containers security, along with various security components, tools, solutions, deployment methods, strategies, and services for protecting your Azure environment. You’ll examine connecting networks via peering, implementing hub-and-spoke topology and distributed denial of service (DDoS ) protection, securing solutions with VPNs, traffic control with network virtual appliances (NVAs), and using Azure Web Application Firewall (WAF) to prevent attacks. Within the course, you’ll discover the ins and outs of defense in depth, endpoint protection host security, network client and server technology, privileged access, serverless compute, and virtual machines (VMs). You’ll learn how to configure, deploy, enable, and manage various security solutions, including Azure App Service, Azure Application Gateway, Azure Bastion, Azure Container Instances, Azure Container Registry, Azure Defender, Azure Disk Encryption, Azure ExpressRoute, Azure Firewall and Firewall Manager, Azure Front Door, Azure Functions, Azure Kubernetes Service, Azure Private Link, Azure Security Benchmarks, and Azure Update Management. This is the third course in a series of seven courses that will prepare you to succeed in the AZ-500: Microsoft Azure Security Technologies exam.Modules
Welcome
1
Discussions
- Meet and greet
1
Videos
- Course introduction
1
Readings
- How to be successful in this course
Defense concepts
1
Assignment
- Knowledge check: Defense concepts
3
Videos
- Define defense in depth
- Recap network client and server technology
- Explore virtual network security
2
Readings
- Understand firewalls and network security
- Network monitoring
Secure your solutions using distributed denial of service protection and firewalls
1
Assignment
- Knowledge check: Secure your solutions using distributed denial of service protection and firewalls
6
Videos
- Perimeter protection as part of your defense strategy
- Enable distributed denial of service protection
- Configure a distributed denial of service protection implementation
- Explore Azure Firewall features
- Deploy an Azure Firewall implementation
- Overview of Azure Firewall Manager
4
Readings
- Exercise: Azure Firewall
- Solution: Azure Firewall
- How Azure Firewall Manager works
- Configure and deploy Azure Firewall Manager
Secure your solutions using VPNs
1
Assignment
- Knowledge check: Secure your solutions using VPNs
6
Videos
- Network isolation and security
- VPNs as part of perimeter security
- What is a network virtual appliance?
- Configure VPN-forced tunneling
- Choose between virtual network peering and VPN gateways
- Create user-defined routes and network virtual appliances
7
Readings
- Explore hub and spoke topology
- Introduction to routing Azure virtual networks
- Connect services using peering
- Exercise: Azure Virtual Network peering or network virtual appliance routes
- Solution: Azure Virtual Network peering or network virtual appliance routes
- Azure Functions networking options
- Azure Network Virtual Appliances Firewall architecture overview
Graded assessment
1
Assignment
- Module quiz: Perimeter Security
1
Videos
- Module summary
Network security groups and application security groups
1
Assignment
- Knowledge check: Network security groups and application security groups
6
Videos
- Network security as part of your defense strategy
- Deploy and configure network security groups
- Create application security groups
- Enable service endpoints
- Configure service endpoint services
- Deploy private links
5
Readings
- Exercise: Network security groups
- Solution: Network security groups
- Integrating private endpoints with other services
- Exercise: Service Endpoints and Securing Storage
- Solution: Service Endpoints and Securing Storage
Application Gateway
1
Assignment
- Knowledge check: Application Gateway
2
Videos
- Application Gateway and encryption
- Implement an Azure Application Gateway
5
Readings
- Application Gateway Components
- Configure back-end pools for encryption
- Configure an Application Gateway listener for encryption
- Exercise: Application service groups
- Solution: Application service groups
Web application firewall, Front Door, and ExpressRoute
1
Assignment
- Knowledge check: Web application firewall, Front Door, and ExpressRoute
3
Videos
- Deploy a web application firewall
- Configure and manage Azure Front Door
- Review ExpressRoute
2
Readings
- Exercise: Azure Front Door
- Solution: Azure Front Door
Graded assessment
1
Assignment
- Module quiz: Network security
1
Videos
- Module summary
Configure and manage host security
1
Assignment
- Knowledge check: Configure and manage host security
11
Videos
- Host security as part of your defense strategy
- Enable endpoint protection
- Define a privileged access device strategy
- Deploy privileged access workstations
- Create virtual machine templates
- Enable and secure remote access management
- Configure update management
- Deploy Disk Encryption
- Deploy and configure Windows Defender
- Explore Microsoft Defender for Cloud recommendations
- Secure Azure workloads with Azure Security Benchmarks
3
Readings
- Scheduled updates
- Exercise: Virtual machine updates
- Solution: Virtual machine updates
Configure and manage container security
1
Assignment
- Knowledge check: Configure and manage container security
7
Videos
- What is a container?
- Configure Azure Container Instances security
- Manage security for Azure Container Instances (ACI)
- Explore the Azure Container Registry (ACR)
- Enable Azure Container Registry authentication
- Overview of serverless compute
- Overview Azure App service
5
Readings
- Exercise: Deploy a container instance in Azure
- Solution: Deploy a container instance in Azure
- Security for serverless compute
- Security for Azure App service
- Additional resources: Security recommendations for App Service
Azure Kubernetes Service (AKS)
1
Assignment
- Knowledge check: Azure Kubernetes Service (AKS)
6
Videos
- What is Kubernetes?
- Review Azure Kubernetes Service (AKS)
- Configure Azure Kubernetes Service networking
- Deploy Azure Kubernetes Service storage
- Secure authentication to Azure Kubernetes Service with Active Directory
- Manage access to Azure Kubernetes Service using Azure role-based access controls
5
Readings
- How Kubernetes works?
- How Kubernetes deployments work?
- How Azure Kubernetes Service works
- Exercise: Configuring and securing ACR and AKS
- Solution: Configuring and securing ACR and AKS
Graded assessment
1
Assignment
- Module quiz: Host and container security
1
Videos
- Module summary
1
Readings
- Course 3 Glossary: Implement Platform Protection
Project
1
Peer Review
- Course project
1
Discussions
- Compare your work
1
Videos
- Course summary
1
Readings
- About the course project
Graded assessment
1
Assignment
- Graded assessment: Implement Platform Protection
1
Discussions
- Share helpful hints
1
Videos
- About the graded assessment
Course wrap-up
2
Videos
- Congratulations
- Next steps
Auto Summary
"Implement Platform Protection" is designed for security engineers aiming to secure their Azure environment. This IT & Computer Science course, led by Coursera, covers perimeter, network, and host security, and delves into Azure's security components and solutions. Learners will master defense in depth, endpoint protection, and securing various Azure services. With a duration of 1080 minutes, this professional-level course is part of a series to prepare for the AZ-500 exam. Subscription options include Starter and Professional tiers. Ideal for those seeking advanced Azure security skills.

Microsoft