timothywarner-org/sc500

GitHub: timothywarner-org/sc500

微软 SC-500 云与 AI 安全工程师认证考试的全套课程实践仓库,提供逐课动手实验脚本、基础设施即代码片段和学习计划模板。

Stars: 2 | Forks: 1

# SC-500:Cloud and AI Security Engineer Associate — 课程伴侣 [![Microsoft Learn](https://img.shields.io/badge/Microsoft%20Learn-SC--500-0078D4?logo=microsoft)](https://learn.microsoft.com/credentials/certifications/exams/sc-500/) [![License: MIT](https://img.shields.io/badge/License-MIT-green.svg)](LICENSE) [![Course Status](https://img.shields.io/badge/status-in%20production-yellow)]() [![Beta Exam](https://img.shields.io/badge/Beta%20Exam-May%202026-blue)]() ## 关于本仓库 本仓库是视频课程《考试 SC-500:Cloud and AI Security Engineer Associate(视频)》的**可选但强烈推荐的伴侣资料**,该课程由 Pearson 旗下的 Microsoft Press 出版。本课程涵盖了微软 SC-500 考试(AZ-500 的继任者)的所有已发布目标。 在本仓库中,您将找到: - 每节课的专属文件夹,内含动手实践演示脚本、Azure CLI / PowerShell 命令,以及 ARM / Bicep / Terraform 代码片段 - 一份汇总的目标映射表,准确展示了哪一节课涵盖了哪个微软功能组 (FG) 的子领域 - 精选的 Microsoft Learn、Microsoft Defender for Cloud 文档、Microsoft Sentinel 内容中心解决方案以及 Microsoft Security Copilot 指南的链接 - 实践场景和学习计划模板,您可以将其复制到您首选的工具中 ## 考试概览 | | | |---|---| | **考试代码** | SC-500 | | **全称** | Microsoft Certified: Cloud and AI Security Engineer Associate | | **继任于** | AZ-500(将于 2026 年 8 月 31 日退役) | | **Beta 考试窗口** | 2026 年 5 月 | | **正式发布** | 2026 年 7 月 | | **形式** | 多项选择题、案例研究、基于场景的题目 | | **官方学习指南** | [SC-500 考察技能 (Microsoft)](https://learn.microsoft.com/credentials/certifications/exams/sc-500/) | ### 考察技能(公布的权重) | 功能组 | 权重 | 课程 | |---|---|---| | 管理 identity、访问和治理 | 20-25% | 1, 2, 3 | | 保护存储、数据库和网络 | 25-30% | 4, 5, 6, 7 | | 保护计算(包括 AI 工作负载) | 20-25% | 8, 9, 10, 11 | | 管理和监控安全态势 | 20-25% | 12, 13, 14, 15 | ## 课程大纲 | # | 课程 | 映射到 | |---|---|---| | 1 | [Identity 基础:PIM、RBAC、自定义角色和治理范围](lessons/lesson-01-identity-foundations/) | FG1.1, FG1.3 | | 2 | [Entra ID 访问:MFA、Conditional Access、应用和 Managed Identities](lessons/lesson-02-entra-id-access/) | FG1.1 | | 3 | [Key Vault、Azure Policy、合规性、备份和 IaC](lessons/lesson-03-keyvault-policy-iac/) | FG1.2, FG1.3 | | 4 | [保护存储和数据库](lessons/lesson-04-storage-databases/) | FG2.1, FG2.2 | | 5 | [网络隔离:NSG、ASG、AVNM、Virtual WAN、VPN](lessons/lesson-05-network-segmentation/) | FG2.3 | | 6 | [私有连接:Private Link、Private Endpoints、Entra Private Access](lessons/lesson-06-private-connectivity/) | FG2.3 | | 7 | [边界保护:Azure Firewall 和 Network Watcher](lessons/lesson-07-perimeter-protection/) | FG2.3 | | 8 | [保护服务器和虚拟机](lessons/lesson-08-servers-vms/) | FG3.2, FG4.1 | | 9 | [保护应用平台服务:Containers、Serverless、App Service、WAF、APIM](lessons/lesson-09-app-platform/) | FG3.3 | | 10 | [保护 AI 工作负载 I:数据过度暴露、Copilot、Entra Agent ID](lessons/lesson-10-ai-workloads-i/) | FG3.1 | | 11 | [保护 AI 工作负载 II:Foundry、AI Gateway、Defender for AI](lessons/lesson-11-ai-workloads-ii/) | FG3.1 | | 12 | [使用 Defender for Cloud 和多云管理安全态势](lessons/lesson-12-defender-cloud-multicloud/) | FG4.1 | | 13 | [Microsoft Sentinel I:Workspace、连接器、日志摄取](lessons/lesson-13-sentinel-i/) | FG4.2 | | 14 | [Microsoft Sentinel II:分析、自动化、KQL、Purview 审核](lessons/lesson-14-sentinel-ii/) | FG4.2 | | 15 | [面向 Cloud 和 AI 防御者的 Microsoft Security Copilot](lessons/lesson-15-security-copilot/) | FG4.3 | 请在 [`docs/exam-objectives.md`](docs/exam-objectives.md) 中查看完整的映射关系。 ## 如何使用本仓库 ### 如果您正在观看视频 1. 打开与您正在观看的视频相匹配的课程文件夹。 2. 使用该课程文件夹中的 `README.md` 作为您的动手实践指南。 3. 演示脚本是幂等的并且已参数化——将它们克隆到您自己的沙盒订阅中并按原样运行,或者修改每个文件顶部的参数。 ### 如果您没有观看视频而是备考 1. 从 [`docs/exam-objectives.md`](docs/exam-objectives.md) 开始,按照 1-5 的置信度对每个子领域进行自我评估。 2. 对于任何低于 4 的子领域,打开相匹配的课程文件夹,并在您自己的订阅中完成演示脚本的操作。 3. 使用 [`docs/study-plan-template.md`](docs/study-plan-template.md) 作为 30 天、60 天或 90 天的学习日历。 ### 如果您是企业 L&D 采购人员 Tim 的内容根据 MIT 许可证授权给个人学习者使用(参见 [LICENSE](LICENSE))。如需通过 Pearson、ACM Learning Center 或 O'Reilly 进行企业团队授权,请联系您的客户代表或直接通过 [timw.info](https://timw.info) 联系 Tim。 ## 前置条件 要在您自己的订阅中运行演示,您需要: - 一个 **Azure 订阅**,在订阅范围内具有 Owner 或 Contributor 权限(使用沙盒或按需付费即可;强烈建议设置预算警报) - **Azure CLI** 2.60+([安装](https://learn.microsoft.com/cli/azure/install-azure-cli)) - **Azure PowerShell** Az 11+([安装](https://learn.microsoft.com/powershell/azure/install-azps-windows)) - **Microsoft Entra ID** P1 或 P2 许可证,用于 Conditional Access 和 Privileged Identity Management 演示 - 启用 **Microsoft Defender for Cloud**(免费层即可用于安全态势管理;某些演示需要增强的安全功能) - **Microsoft Sentinel** workspace(一个 Log Analytics workspace 以及 Sentinel 解决方案) - 具备相当于 AZ-104 级别的 Azure 资源层次结构、网络和 identity 的扎实知识 ## 仓库结构 ``` sc500/ ├── README.md ← you are here ├── LICENSE ← MIT ├── CONTRIBUTING.md ← how to report issues and submit fixes ├── CHANGELOG.md ← lesson-by-lesson publication log ├── docs/ │ ├── exam-objectives.md ← full SC-500 objective domain map │ ├── study-plan-template.md ← 30/60/90 day calendar template │ └── resources.md ← curated Microsoft Learn and external links ├── lessons/ │ ├── lesson-01-identity-foundations/ │ ├── lesson-02-entra-id-access/ │ ├── ... (one folder per lesson) │ └── lesson-15-security-copilot/ ├── demos/ │ └── (demo scripts and ARM/Bicep/Terraform artifacts) └── .github/ └── ISSUE_TEMPLATE/ ← typo, broken link, content question ``` ## 作者 **Tim Warner** 是专注于 **Azure AI** 和 **云和数据中心管理** 领域的微软 MVP,Pluralsight 的首席特约作者(200 多门课程,超过 100 万学员),O'Reilly 的现场学习讲师,以及 Pearson 的高级内容开发者。他从 70-290 考试还流行的时代起就开始培训微软认证考生了。 - 网站:[timw.info](https://timw.info) - YouTube:[@TechTrainerTim](https://www.youtube.com/@TechTrainerTim) - Bluesky:[@techtrainertim.bsky.social](https://bsky.app/profile/techtrainertim.bsky.social) - LinkedIn:[in/timothywarner](https://www.linkedin.com/in/timothywarner/) ## 如何学习(三大支柱方法) Tim 告诉每一位认证考生要平衡三大支柱: 1. **理论知识** — 本课程、Microsoft Learn、已发布的学习指南 2. **动手经验** — 您自己的 Azure 沙盒、本仓库中的演示脚本 3. **模拟考试复习** — [MeasureUp](https://www.measureup.com/) 是微软官方的模拟考试提供商 本仓库为您提供支柱 2。视频课程为您提供支柱 1。MeasureUp 补齐支柱 3。 ## 许可证 MIT — 详见 [LICENSE](LICENSE)。课程视频和 Pearson 品牌材料由 Pearson 另行授权,不可转发分发。 ## 致谢 - **Microsoft Press** 和 **Pearson** 出版了本教材 - **Laura Lewin** 予以编辑指导 - Microsoft Defender、Sentinel、Foundry 和 Entra 团队开发了本考试实际测试的产品 - 数以千计的认证考生参加了 Tim 的课程并提出问题,使这些材料变得更好 *去赢得那枚徽章吧。* 🎯
标签:AI安全, Azure, Chat Copilot, SC-500, 学习资源, 微软云安全, 微软认证, 防御加固