Catalog / SEC-400

SEC-400Specialist

Cloud Security

Zero-trust architecture, platform security controls, detection and response - designed for the people accountable when it goes wrong.

Tuition
$6,750 USD
Duration
6 weeks
Commitment
5-7 hrs/week
Format
Live online cohort
Admissions
Rolling
Overview

About this program

Cloud security fails at the architecture level long before it fails at the tooling level. This program trains security and platform leads to design identity-first zero-trust estates, operationalize posture management and policy, protect data with sound key-management design, and build detection and response capability that stands up in a real incident.

Who this is for

  • Security architects and engineers covering Azure-centric estates
  • Platform leads accountable for security posture and compliance
  • Senior engineers moving into cloud security ownership
Outcomes

What you will be able to do

  • Threat-model cloud estates and prioritize controls by attack path
  • Design identity-first zero-trust architecture with conditional access and segmentation
  • Operationalize posture management, policy enforcement, and secure-by-default patterns
  • Build detection and response capability with a working incident playbook
Curriculum

Program modules

Delivered over 6 weeks of live tutor-led sessions, applied work, and structured review.

M01

Threat modelling cloud estates

  • Cloud attack paths: identity, misconfiguration, supply chain
  • Threat modelling methods that work at estate scale
  • Prioritizing controls: likelihood, blast radius, cost
  • Security architecture reviews: running them well
M02

Zero-trust architecture

  • Identity as the perimeter: Entra ID hardening priorities
  • Conditional access design and break-glass strategy
  • Segmentation: networks, identities, and management planes
  • Privileged access: PIM, PAWs, and tiered administration
M03

Platform security controls

  • Microsoft Defender for Cloud: posture management in practice
  • Azure Policy as a security enforcement layer
  • Secure-by-default landing-zone patterns
  • Vulnerability and misconfiguration workflow design
M04

Data protection and key management

  • Encryption architecture: at rest, in transit, in use
  • Azure Key Vault and managed HSM design decisions
  • Data classification and protection boundaries
  • Secrets lifecycle: rotation, access, and audit
M05

Detection and response

  • Logging architecture: what to collect and what it costs
  • Microsoft Sentinel: analytics rules and automation
  • Building and testing incident-response playbooks
  • Tabletop exercises: rehearsing the bad day
M06

Security leadership and reporting

  • Communicating risk to executives without theatre
  • Metrics that reflect real posture, not activity
  • Working with auditors and compliance frameworks
  • Capstone: security architecture review of a reference estate
Labs & applied work

Hands-on components

  • Guided Azure security lab with intentionally vulnerable estate
  • Detection engineering exercises in Microsoft Sentinel
  • Incident tabletop and a capstone security architecture review
Rolling admissions

Ready to apply?

Apply any time. Admissions reviews your fit, confirms the next available cohort, and issues an invoice. Your seat is confirmed on payment.