- 課程時間
- 課程簡介
- 課程特點
- 認證要求
- 考試須知
- 課程內容
傳統服務:課程上堂時間表 (地點:旺角 總費用:$8,580) 學員使用 WhatsApp、電話或本網頁報名,待本中心確認已為學員留位後,即可使用 繳付學費,過程簡便!
|
超震撼: |
凡於 2026年 8月 7日 (五) 或之前報讀本課程, 原價 $10,725,現只需
$8,580! |
|
* 各政府部門可使用 P Card 付款
如使用 P Card 繳付考試費,考試費需另加 2.5% 行政費
*** 質素保證:
免費於任何地點試睇首 3 小時課堂錄影,從而可預先了解導師及教材的質素,才報讀課程來上堂。***
請致電與本中心職員預約。
查看各地點電話
| 旺角 |
2332-6544 |
| 觀塘 |
3563-8425 |
| 沙田 |
2151-9360 |
| 在校免費補堂: |
學員可於任何校舍補看課堂錄影,從而可銜接往後的課堂!
|
| 在校免費重讀: |
學員可於課程結束後三個月內於任何校舍不限次數地重看課堂錄影,從而可反覆重溫整個課程! |
| 課時: |
36 小時 |
| 課堂導師: |
Larry (任教課程清單) |
|
注意! 客戶必須查問報讀學校的教育局註冊編號,以確認該校為註冊學校,以免蒙受不必要的損失!
本中心是 Microsoft 認可的合作夥伴
(Microsoft Certified Partner)。
|
面對雲端應用、混合雲 (Hybrid Cloud)、多雲 (Multi-Cloud) 及生成式人工智能 (Generative AI) 的快速發展,企業的保安挑戰已不再局限於傳統網絡邊界,更延伸至身分、數據、應用程式、運算資源、開發流程及人工智能工作負載。
本中心的 Microsoft Certified Cloud and AI Security Engineer Associate 課程,幫助您掌握端到端的完整安全控制能力。從預防、偵測、調查到事故回應,全面建立雲端與人工智能安全所需的實務技能,讓企業在數碼轉型與 AI 應用過程中,有效管理風險並提升整體防禦能力。
透過本中心專業導師的講解、實際應用情境及動手示範實習,深入剖析 Microsoft Azure 與 Microsoft 365 環境的安全控制,並涵蓋人工智能工作負載 (AI Workloads) 及自主代理 (Autonomous Agents) 的保安需求。
本課程適合需要規劃、實施或管理雲端 (Azure Cloud)、混合雲 (Hybrid Cloud) 及多雲 (Multi-Cloud) 安全的保安工程師、雲端管理員、系統工程師、解決方案架構師、DevOps專業人員及技術顧問修讀,亦適合希望提升企業雲端及人工智能安全能力的資訊科技從業員。
本課程相關的 Microsoft 產品及其主要優勢:

- Microsoft Entra ID
Microsoft 的雲端身分及存取管理 (Identity and Access Management, IAM) 平台,可集中管理使用者、裝置、應用程式及工作負載身分 (Workload Identity),並透過多重要素驗證 (Multi-Factor Authentication, MFA)、條件式存取 (Conditional Access)、角色型存取控制 (Role-Based Access Control, RBAC) 及特權身分管理 (Privileged Identity Management, PIM),落實最低權限原則 (Principle of Least Privilege)。
企業可藉此統一身分治理、支援混合環境,並以身分安全作為零信任 (Zero Trust) 策略的核心,減低帳戶被盜用及未經授權存取的風險。
- Azure Key Vault
集中保護密碼字串 (Secrets)、加密式金鑰 (Keys) 及數碼證書 (Digital Certificates) 等敏感資料,協助應用程式在不保存機密資料的情況下安全地存取不同資源。其優勢包括精細存取控制 (Fine Grained Access Control)、稽核 (Internal Audit) 能力,以及與 Azure 服務和受控身分的整合。
- Microsoft Defender for Cloud
一站式雲端原生應用程式保護平台 (Cloud-Native Application Protection Platform - CNAPP),整合雲端安全態勢管理 (Cloud Security Posture Management - CSPM)、開發安全營運 (DevSecOps) 及雲端工作負載保護 (Cloud Workload Protection)。
平台可為虛擬機器 (Virtual Machines)、容器 (Containers)、儲存體 (Storage Volume)、資料庫 (Database)、無伺服器運算 (Server-less Compute) 及生成式人工智能 (Generative AI) 工作負載提供風險評估、安全建議及威脅防護。
其跨 Azure、混合雲 (Hybrid Cloud) 及多雲 (Multi-Cloud) 的統一可視性,讓企業更容易識別設定風險、持續改善安全水平,並把保安控制融入開發生命週期。
- Microsoft Sentinel
微軟雲端安全資訊及事件管理 (Security Information and Event Management, SIEM) 與安全協調、自動化及回應 (Security Orchestration, Automation and Response, SOAR) 平台。
Microsoft Sentinel 能大規模收集、分析及關聯不同來源的安全數據,支援威脅偵測、事件調查、主動威脅獵捕 (Threat Hunting) 及自動化回應。
透過人工智能、威脅情報及自動化工作流程,保安團隊可減少重複工作及警示雜訊,更快識別真正威脅並縮短事故回應時間。
- Microsoft Defender XDR
統一整合身分、終端設備、電郵、應用程式及雲端訊號,協調預防、偵測、調查與回應。其優勢是把原本分散的安全資料關聯成完整事件脈絡,並運用人工智能及自動化更有效阻截攻擊及修復受影響服務。
- Microsoft Security Copilot
以生成式人工智能 (Generative AI) 為基礎的保安解決方案,可協助保安工程師進行事件摘要、威脅調查、腳本及查詢建立,以及安全數據分析。分析人員可透過自然語言提出問題,快速整合分散的安全資訊並取得可行洞察,從而縮短調查時間、提升分析效率,並協助不同經驗水平的團隊成員更一致地執行保安流程。
課程核心內容概括:
- 管理身分、存取及治理 (Identity Management, Access Control and Governance)
設計安全驗證、條件式存取及特權存取;管理受控身分、應用程式身分、Azure Key Vault、Azure 角色型存取控制及 Azure Policy,以降低未經授權存取和過高權限的風險。
- 保護雲端儲存、資料庫及網絡 (Azure Storage, Database and Network Protection)
強化 Azure Storage 與資料庫的存取及資料保護;實施網絡安全群組 (NSG)、Azure Firewall、Private Link、私人端點及安全連線,減少攻擊面並保護敏感資料。
- 保護運算及人工智能工作負載 (Compute and AI Workload Protection)
提升虛擬機器、混合及多雲伺服器、容器、Azure Kubernetes Service、App Service、Functions、API,以及人工智能服務、模型、代理與相關數據的安全性。
- 管理及監察安全態勢 (Security Posture Monitoring and Management)
運用 Microsoft Defender for Cloud、Microsoft Sentinel、Microsoft Defender XDR 及 Microsoft Security Copilot 評估風險、監察合規、管理漏洞、偵測威脅、調查事件並建立自動化回應流程。

Microsoft Certified Cloud and AI Security Engineer Associate
考取此認證,代表您擁有在 Microsoft Azure、混合雲與 AI 環境下,設計並管理完整端到端安全控制的專業能力。
認證內容涵蓋身分管理、數據、應用程式、基礎設施、安全治理及法規遵循,並進一步把人工智能平台、數據、模型及自主代理 (Autonomous Agents) 納入保安工程實務。
對希望投身雲端安全、人工智能安全或安全營運工作的專業人士而言,此認證有助建立具市場認受性的技能證明;對企業而言,則有助培養能夠應對新一代雲端及生成式人工智能 (Generative AI) 風險的專業人才,具備相關認證與實務能力的人才可協助建立一致、可重複及可稽核的安全控制,減少設定失誤、權限濫用、資料外洩與威脅處理延誤所帶來的營運風險。
對專業人士而言,此認證可作為具備 Microsoft 雲端及人工智能安全能力的客觀證明,有助建立職業發展路徑、提升與架構師、開發人員、管理員及安全營運團隊協作的共同語言,並增加參與雲端轉型、零信任、人工智能治理及安全營運項目的能力與信心。
本課程為學員帶來的知識與實務價值:
- 建立端到端保安視野
不再只處理單一產品或個別警示,而能從身分、網絡、數據、應用程式、運算、人工智能及安全營運角度整體評估風險。
- 把知識轉化為可執行控制
能按業務與合規需求設定身分驗證、最低權限、網絡隔離、資料保護、工作負載強化及持續監察措施。
- 提升人工智能採用的安全基礎
理解人工智能服務、模型、代理及其數據在設計、部署和運行階段的風險,讓企業在推動創新的同時維持適當的治理與保護。
- 改善威脅偵測及回應效率
善用 SIEM、XDR、威脅情報、自動化及人工智能輔助分析,以更完整的事件脈絡作出快捷而一致的回應。
- 支援跨部門協作與決策
能把技術風險轉化為清晰的控制要求、優先次序及改善建議,促進保安、IT、開發、合規與管理層之間的溝通。
- 為認證及持續專業發展作準備:
以 SC-500 考試技能範圍為學習主線 (詳見 “課程內容” 頁面),建立系統化知識架構;學員配合實習及官方最新考試範圍,以全面準備的技能及知識去應付該認證考試。
完成本課程後,學員將具備更全面的雲端及人工智能安全視野,能夠在雲端、混合雲 (Hybrid Cloud) 及多雲 (Multi-Cloud) 環境中評估風險、實施安全控制、監察安全態勢並回應事故。
學員亦可把 Microsoft 安全技術應用於身分保護、網絡防禦、數據安全、工作負載強化及生成式人工智能 (Generative AI) 治理等實際場景。
結語:
本課程不但為 SC-500 認證考試奠定穩固基礎,更可協助學員把知識落實應用成為合乎企業需求的安全方案,支援法規遵循、數碼轉型及人工智能項目安全落地,為個人專業發展與企業長遠營運創造具體而實際價值。
|
| 課程名稱: |
Microsoft Certified Cloud and AI Security Engineer Associate 國際認可證書課程 (1 科 Azure 雲端保安) - 簡稱:Cloud and AI Security Training Course |
| 課程時數: |
36 小時 (共 12 堂,共 1 科) |
| 適合人士: |
有志考取 Microsoft Certified Cloud and AI Security Engineer Associate 證書人士 或
對雲端保安技術有興趣人士 |
| 授課語言: |
以廣東話為主,輔以英語 |
| 課程筆記: |
本中心導師親自編寫英文為主筆記,而部份英文字附有中文對照。 |
| 1. 模擬考試題目: |
本中心為學員提供模擬考試題目,每條考試題目均附有標準答案。 |
| 2. 時數適中: |
本中心的 Microsoft Certified Cloud and AI Security Engineer Associate 國際認可證書課程 (1 科 Azure 雲端保安) 時數適中,有 36 小時。
令學員能真正了解及掌握課程內容,而又能於 3 個月內考獲以下 1 張國際認可證書:
- Microsoft Certified Cloud and AI Security Engineer Associate
|
| 3. 導師親自編寫筆記: |
由本中心已擁有五項 MCITP , 十多項 MCTS,MCSA 及 MCSE 資格,並有教授 Microsoft 相關課程
20年以上經驗的資深導師 Larry Chan 親自編寫筆記,絕對適合考試及實際管理之用,令你無須「死鋤」如字典般厚及不適合香港讀書格調的書本。 |
| 4. 一人一機上課: |
本課程以一人一機模式上課。 |
| 5. 免費重讀: |
傳統課堂學員可於課程結束後三個月內免費重看課堂錄影。 |
Microsoft 已公佈考生只要通過以下 1 個 Cloud and AI 相關科目的考試,便可獲發 Microsoft Certified Cloud and AI Security Engineer Associate 國際認可證書:
| 考試編號 |
科目名稱 |
| SC-500 |
Implementing End-to-End Security Controls for Cloud and AI Workloads |
本中心為Microsoft指定的考試試場。報考時請致電本中心,登記欲報考之科目考試編號、考試日期及時間
(最快可即日報考)。臨考試前要出示身份證及繳付每科HK$943之考試費。
考試題目由澳洲考試中心傳送到你要應考的電腦,考試時以電腦作答。所有考試題目均為英文,而大多數的考試題目為單項及多項選擇題,其餘則為實戰題。
考試合格後會收到來自Microsoft的作實電郵,並進入該電郵內的連結,登入 Microsoft Credentials Dashboard 下載您的證書。
考試不合格便可重新報考,不限次數。欲知道作答時間、題目總數、合格分數等詳細考試資料,可瀏覽本中心網頁 "各科考試分數資料"。 |
課程名稱:Microsoft Certified Cloud and AI Security Engineer Associate 國際認可證書課程 (1 科 Azure 雲端保安) - 簡稱:Cloud and AI Security Training Course |
Secure access to resources by using Microsoft Entra ID
- Implement and configure Privileged Identity Management (PIM)
- Implement conditional access policies
- Implement and configure authentication methods, including multifactor authentication (MFA) and passwordless
- Implement and configure identity for applications, including enterprise applications and app registrations
- Manage OAuth permission grants and consent settings
- Implement and configure managed identities for Azure resources
Secure secrets and keys by using Azure Key Vault
- Deploy Key Vault
- Configure Key Vault settings
- Configure access to Key Vault
- Configure firewall settings on Key Vault
- Manage keys, secrets, and certificates
- Scan for secrets by using Defender Cloud Security Posture Management (Defender CSPM)
- Implement Defender for Key Vault
Implement governance to enforce security and regulatory compliance
- Implement and configure security controls by using Azure Policy, including built-in and custom policy definitions
- Evaluate regulatory compliance by using Microsoft Defender for Cloud
- Implement and configure security controls in Defender for Cloud, including security standards and recommendations
- Implement resource locks
- Manage Azure built-in role assignments
- Manage custom roles, including Azure roles and Microsoft Entra roles
- Evaluate and remediate overprivileged access assignments by using Azure role-based access control (RBAC)
- Configure security controls for backup protection by using Azure Backup security features
- Implement and configure security controls by using infrastructure as code
Implement security for storage accounts
- Implement and configure security for storage accounts
- Configure Azure Storage firewall rules
- Implement Defender for Storage threat protection configurations
- Manage access to storage, including access policies
Implement security for databases
- Implement platform-level security configurations in Azure SQL
- Configure database auditing for Azure SQL Database and Azure SQL Managed Instance
- Configure Defender for Databases protection across Azure database services
Implement security for Azure network services
- Implement and manage network security groups (NSGs) and application security groups (ASGs)
- Implement and configure network access policies by using Azure Virtual Network Manager
- Configure security for an Azure Virtual WAN
- Implement and configure security for virtual private network (VPN) connections
- Implement and configure Microsoft Entra Private Access
- Configure Azure private endpoints to secure access to Azure platform as a service (PaaS) resources
- Configure Azure Private Link services to secure access to network resources
- Implement and configure Azure Firewall
- Evaluate effective security rules by using Azure Network Watcher diagnostics
Implement security for AI
- Identify overexposure of data in SharePoint
- Identify risks related to Microsoft Copilot and AI apps by using Microsoft Purview Data Security Posture Management (DSPM)
- Enable and configure real-time protection for Microsoft Copilot Studio agents
- Implement conditional access for Microsoft Entra Agent ID
- Analyze blast radius for security risks related to Entra Agent ID by using Defender XDR
- Manage Entra Agent ID access
- Configure and deploy AI Gateway in Azure API Management for Microsoft Foundry
- Enable Defender for AI Service in Cloud Workload Protection in Defender for Cloud
- Configure guardrails for agent security in Foundry
- Monitor AI security by using the Data and AI security dashboard in Defender for Cloud
- Manage agents in Microsoft 365 admin center
Implement security for servers and virtual machines (VMs)
- Implement and configure disk encryption
- Plan and implement Azure Bastion
- Enable and enforce use of just-in-time (JIT) VM access
- Extend security controls to hybrid and multi-cloud servers by using Azure Arc
- Onboard servers to Defender for Servers in Defender for Cloud, including hybrid and multi-cloud scenarios
- Configure Defender for Servers settings, including vulnerability scanning, and endpoint detection and response (EDR)
- Implement and manage agentless scanning for VMs in Defender for Servers
- Configure security features on a VM, including secure boot, virtual Trusted Platform Module (vTPM), integrity monitoring, and security type
- Enforce security configuration of Azure-managed servers by using Azure Machine Configuration
Implement security for application platform services
- Detect misconfigurations and runtime risks in container workloads by using Defender for Containers
- Implement and configure security controls for Azure Kubernetes Service (AKS)
- Implement and configure security controls for Azure Container Registry
- Implement and configure security controls for Azure Container Instances and Azure Container Apps
- Implement and configure security controls for Azure Functions, including authentication and network access
- Implement and configure security controls for Azure Logic Apps
- Implement and configure security controls for Azure App Service
- Implement and configure Azure Web Application Firewall
- Implement security policies for back-end API protection by using API Management
Manage security posture by using Defender for Cloud
- Identify security risks by using Defender CSPM
- Evaluate compliance against security frameworks by using Defender for Cloud
- Enable and configure Defender for Cloud workload protection plans
- Connect hybrid cloud and multi-cloud environments to Defender for Cloud, including Amazon Web Services (AWS) and Google Cloud Platform (GCP)
- Configure Microsoft Defender Vulnerability Management settings for Azure VMs
- Discover unprotected assets and vulnerabilities by using Microsoft Defender External Attack Surface Management (EASM)
Implement activity and event collection in Microsoft Sentinel
- Create and connect workspaces in Microsoft Sentinel
- Assign roles in Microsoft Sentinel
- Implement and use content hub solutions
- Configure and use Microsoft data connectors for Azure resources
- Implement and configure syslog and Common Event Format (CEF) event collections
- Implement and configure collection of Windows Security events by using data collection rules, including Windows Event Forwarding (WEF)
- Create custom log tables in the workspace to store ingested data
- Implement automation rules and playbooks in Microsoft Sentinel
- Implement data retention in Microsoft Sentinel data stores
- Query Microsoft Purview Audit in Defender XDR
Implement Microsoft Security Copilot
- Configure workspaces for Security Copilot
- Manage permissions and roles in Security Copilot
- Enable and configure plugins
- Enable and configure Microsoft agents and Security Store agents
The course content above may change at any time without notice in order to better reflect the contents of examination.
|
|