Save 20% off your training this summer, book before 5pm July 5th - See details here

Duration:
Only 5 days
Study Mode:
Classroom / Online / Classroom or Online
Next Date:
30/07/2024 (Tuesday)

Overview

The accelerated Performing CyberOps Using Cisco Security Technologies (CBRCOR) v1.0 course, guides you through cybersecurity operations fundamentals, methods, and automation. The knowledge you gain in this training will prepare you for the role of Information Security Analyst on a Security Operations Center (SOC) team. You will learn foundational concepts and their application in real-world scenarios, and how to leverage playbooks in formulating an Incident Response (IR).

This course teaches you how to use automation for security using cloud platforms and a SecDevOps methodology. You will learn the techniques for detecting cyberattacks, analyzing threats, and making appropriate recommendations to improve cybersecurity. This training will help you: Gain an advanced understanding of the tasks involved for senior-level roles in a security operations center Configure common tools and platforms used by security operation teams via practical application Prepare you to respond like a hacker in real-life attack scenarios and submit recommendations to senior management

In just 5 days, you’ll also learn how to:

  • Describe the types of service coverage within a SOC and operational responsibilities associated with each.
  • Compare security operations considerations of cloud platforms.
  • Describe the general methodologies of SOC platforms development, management, and automation.
  • Explain asset segmentation, segregation, network segmentation, micro-segmentation, and approaches to each, as part of asset controls and protections.
  • Describe Zero Trust and associated approaches, as part of asset controls and protections.
  • Perform incident investigations using Security Information and Event Management (SIEM) and/or security orchestration and automation (SOAR) in the SOC.
  • Use different types of core security technology platforms for security monitoring, investigation, and response.
  • Describe the DevOps and SecDevOps processes.
  • Explain the common data formats, for example, JavaScript Object Notation (JSON), HTML, XML, Comma-Separated Values (CSV).
  • Describe API authentication mechanisms.
  • Analyze the approach and strategies of threat detection, during monitoring, investigation, and response.
  • Determine known Indicators of Compromise (IOCs) and Indicators of Attack (IOAs).
  • Interpret the sequence of events during an attack based on analysis of traffic patterns.
  • Describe the different security tools and their limitations for network analysis (for example, packet capture tools, traffic analysis tools, network log analysis tools).
  • Analyze anomalous user and entity behavior (UEBA).
  • Perform proactive threat hunting following best practices.

At the end of this course, you’ll sit the Cisco exam, and achieve your Performing CyberOps Using Cisco Security Technologies (CBRCOR) v1.0 certification. Through Firebrand’s Lecture | Lab | Review methodology, you’ll get certified at twice the speed of the traditional training and get access to courseware, learn from certified instructors, and train in a distraction-free environment.

 

Audience

This course is ideal for:

  • Cybersecurity engineer
  • Cybersecurity investigator
  • Incident manager
  • Incident responder
  • Network engineer
  • SOC analysts currently functioning at entry level with a minimum of 1 year of experience 

Curriculum

Lab Outline:

  • Module 1: Explore Cisco SecureX Orchestration
  • Module 2: Explore Splunk Phantom Playbooks
  • Module 3: Examine Cisco Firepower Packet Captures and PCAP Analysis
  • Module 4: Validate an Attack and Determine the Incident Response
  • Module 5: Submit a Malicious File to Cisco Threat Grid for Analysis
  • Module 6: Endpoint-Based Attack Scenario Referencing MITRE ATTACK
  • Module 7: Evaluate Assets in a Typical Enterprise Environment
  • Module 8: Explore Cisco Firepower NGFW Access Control Policy and Snort Rules
  • Module 9: Investigate IOCs from Cisco Talos Blog Using Cisco SecureX
  • Module 10: Explore the ThreatConnect Threat Intelligence Platform
  • Module 11: Track the TTPs of a Successful Attack Using a TIP
  • Module 12: Query Cisco Umbrella Using Postman API Client
  • Module 13: Fix a Python API Script
  • Module 14: Create Bash Basic Scripts
  • Module 15: Reverse Engineer Malware
  • Module 16: Perform Threat Hunting
  • Module 17: Conduct an Incident Response

Exam Track

At the end of this accelerated course, you’ll sit the following exam at the Firebrand Training centre, covered Certification Guarantee:

Performing CyberOps Using Cisco Security Technologies (CBRCOR) v1.0 Exam 350-201

  • Duration: 120-minutes
  • Format: The multiple-choice format tests knowledge of core cybersecurity operations including cybersecurity fundamentals, techniques, policies, processes, and automation.
  • Domains:
    • Monitoring for cyberattacks
    • Analyzing high volume of data using automation tools and platforms—both open source and commercial
    • Accurately identifying the nature of attack and formulate a mitigation plan
    • Scenario-based questions; for example, using a screenshot of output from a tool, you may be asked to interpret portions of output and establish conclusions

Prerequisites

Before attending this accelerated course, you should have:

  • Familiarity with UNIX/Linux shells (bash, csh) and shell commands.
  • Familiarity with the Splunk search and navigation functions
  • Basic understanding of scripting using one or more of Python, JavaScript, PHP or similar.

 

  • Recommended Cisco offering that may help you prepare for this training:
    • Understanding Cisco Cybersecurity Operations Fundamentals (CBROPS)
    • Implementing and Administering Cisco Solutions (CCNA)

  • Recommended third-party resources:
    • Splunk Fundamentals 1 Blue Team Handbook: Incident Response Edition by Don Murdoch
    • Threat Modeling- Designing for Security y Adam Shostack
    • Red Team Field Manual by Ben Clark
    • Blue Team Field Manual by Alan J White
    • Purple Team Field Manual by Tim Bryant
    • Applied Network Security and Monitoring by Chris Sanders and Jason Smith

What's Included

Your accelerated course includes:

  • Accommodation *
  • Meals, unlimited snacks, beverages, tea and coffee *
  • On-site exams **
  • Exam vouchers **
  • Practice tests **
  • Certification Guarantee ***
  • Courseware
  • Up-to 12 hours of instructor-led training each day
  • 24-hour lab access
  • Digital courseware **

* For residential training only. Accommodation is included from the night before the course starts. This doesn't apply for online courses.
** Some exceptions apply. Please refer to the Exam Track or speak with our experts.
*** Pass first time or train again free as many times as it takes, unlimited for 1 year. Just pay for accommodation, exams, and incidental costs.

Benefits

Seven reasons why you should sit your course with Firebrand Training

  1. Two options of training. Choose between residential classroom-based, or online courses
  2. You'll be certified fast. With us, you’ll be trained in record time
  3. Our course is all-inclusive. A one-off fee covers all course materials, exams**, accommodation* and meals*. No hidden extras.
  4. Pass the first time or train again for free. This is our guarantee. We’re confident you’ll pass your course the first time. But if not, come back within a year and only pay for accommodation, exams and incidental costs
  5. You’ll learn more. A day with a traditional training provider generally runs from 9 am – 5 pm, with a nice long break for lunch. With Firebrand Training you’ll get at least 12 hours/day of quality learning time, with your instructor
  6. You’ll learn faster. Chances are, you’ll have a different learning style to those around you. We combine visual, auditory and tactile styles to deliver the material in a way that ensures you will learn faster and more easily
  7. You’ll be studying with the best. We’ve been named in the Training Industry’s “Top 20 IT Training Companies of the Year” every year since 2010. As well as winning many more awards, we’ve trained and certified over 135,000 professionals
  • For residential training only. Doesn't apply for online courses
    ** Some exceptions apply. Please refer to the Exam Track or speak with our experts

Think you are ready for the course? Take a FREE practice test to assess your knowledge!  Free Practice Test

Course Dates


Start
Finish
Status
Study Mode
Prices
30/07/2024 (Tue)
03/08/2024 (Sat)
Open
Classroom
29/10/2024 (Tue)
02/11/2024 (Sat)
Open
Classroom
27/01/2025 (Mon)
31/01/2025 (Fri)
Open
Classroom
29/04/2025 (Tue)
03/05/2025 (Sat)
Open
Classroom