Learning Path 3 - Lab 1 - Exercise 2 - Mitigate threats using Microsoft Defender for Cloud
Lab scenario
You are a Security Operations Analyst working at a company that implemented Microsoft Defender for Cloud. You need to respond to recommendations and security alerts generated by Microsoft Defender for Cloud.
Task 1: Explore Regulatory Compliance
In this task, you will review Regulatory compliance configuration in Microsoft Defender for Cloud.
Important: The next steps are done in a different machine than the one you were previously working. Look for the Virtual Machine name references.
-
Log in to WIN1 virtual machine as Admin with the password: Pa55w.rd.
-
In the Edge browser, open the Azure portal at (https://portal.azure.com).
-
In the Sign in dialog box, copy, and paste in the Tenant Email account provided by your lab hosting provider and then select Next.
-
In the Enter password dialog box, copy, and paste in the Tenant Password provided by your lab hosting provider and then select Sign in.
-
In the Search bar of the Azure portal, type Defender, then select Microsoft Defender for Cloud.
-
Under Cloud Security, select Regulatory compliance in the portal menu.
-
Select Managed compliance policies on the toolbar.
-
Select your subscription.
-
Under Policy settings, select Security policy in the portal menu.
-
Review the “Industry & regulatory standards” available to you by default.
-
Select Add more standards to review additional standards available.
-
Select Microsoft Defender for Cloud below the search box to return to the main blade.
Task 2: Explore Security posture and recommendations
In this task, you will review cloud security posture management. The Secure Score information can take 24 hours to recalculate. It is beneficial to do this task again in 24 hours.
-
Under Cloud Security, select Security posture in the portal menu.
-
The Secure score most likely will show N/A until the score is calculated.
-
Under General, select Recommendations in the portal menu.
-
Explore Recommendations provided (after 24 hours).
Task 3: Mitigate security alerts
In this task, you will load sample security alerts and review the alert details.
-
Under General, select Security alerts in the portal menu.
-
Select Sample alerts from the command bar. Hint: you may need to select the ellipsis (…) button from the command bar).
-
In the Create sample alerts (Preview) pane make sure your subscription is selected and that all sample alerts are selected in the Defender for Cloud plans area.
-
Select Create sample alerts.
Note: This sample alert creation process may take a few minutes to complete, wait for the “Successfully created sample alerts” notification. Once complete each of the alerts should appear in the Security alerts area.
-
For the alerts that grabbed your attention, perform the following actions:
-
Select the alert, information about the alert should appear. Select View full details.
-
Review and read the Alert details tab.
-
Select the Take action tab or select the Next: Take Action button at the end of the page.
-
Review the Take action information. Notice the sections available to take action depending on the type of alert: Inspect resource context, Mitigate the threat, Prevent future attacks, Trigger automated response and Suppress similar alerts.
-