Catalog / SEC-400
SEC-400SpecialistCloud Security
Zero-trust architecture, platform security controls, detection and response - designed for the people accountable when it goes wrong.
Overview
About this program
Cloud security fails at the architecture level long before it fails at the tooling level. This program trains security and platform leads to design identity-first zero-trust estates, operationalize posture management and policy, protect data with sound key-management design, and build detection and response capability that stands up in a real incident.
Who this is for
- Security architects and engineers covering Azure-centric estates
- Platform leads accountable for security posture and compliance
- Senior engineers moving into cloud security ownership
Outcomes
What you will be able to do
- Threat-model cloud estates and prioritize controls by attack path
- Design identity-first zero-trust architecture with conditional access and segmentation
- Operationalize posture management, policy enforcement, and secure-by-default patterns
- Build detection and response capability with a working incident playbook
Curriculum
Program modules
Delivered over 6 weeks of live tutor-led sessions, applied work, and structured review.
M01
Threat modelling cloud estates
- Cloud attack paths: identity, misconfiguration, supply chain
- Threat modelling methods that work at estate scale
- Prioritizing controls: likelihood, blast radius, cost
- Security architecture reviews: running them well
M02
Zero-trust architecture
- Identity as the perimeter: Entra ID hardening priorities
- Conditional access design and break-glass strategy
- Segmentation: networks, identities, and management planes
- Privileged access: PIM, PAWs, and tiered administration
M03
Platform security controls
- Microsoft Defender for Cloud: posture management in practice
- Azure Policy as a security enforcement layer
- Secure-by-default landing-zone patterns
- Vulnerability and misconfiguration workflow design
M04
Data protection and key management
- Encryption architecture: at rest, in transit, in use
- Azure Key Vault and managed HSM design decisions
- Data classification and protection boundaries
- Secrets lifecycle: rotation, access, and audit
M05
Detection and response
- Logging architecture: what to collect and what it costs
- Microsoft Sentinel: analytics rules and automation
- Building and testing incident-response playbooks
- Tabletop exercises: rehearsing the bad day
M06
Security leadership and reporting
- Communicating risk to executives without theatre
- Metrics that reflect real posture, not activity
- Working with auditors and compliance frameworks
- Capstone: security architecture review of a reference estate
Labs & applied work
Hands-on components
- Guided Azure security lab with intentionally vulnerable estate
- Detection engineering exercises in Microsoft Sentinel
- Incident tabletop and a capstone security architecture review
Rolling admissions
Ready to apply?
Apply any time. Admissions reviews your fit, confirms the next available cohort, and issues an invoice. Your seat is confirmed on payment.