Only 8 days
Classroom
04/12/2024 (Wednesday)
Overview
Achieve the IBM Certified SOC Analyst certification through this 8-day accelerated combined course. This programme includes the following courses:
- CompTIA Cybersecurity Analyst CySA+
- IBM's Security QRadar SIEM Administrator
Through CompTIA's CySA+, you'll learn best practices to secure and protect your business’ applications and systems by:
- Configuring and using threat detection tools
- Learning how to perform data analysis to identify vulnerabilities, threats and risks
- Focusing on network behaviour – both internal and external threats
Through the IBM Security QRadar SIEM Administrator course, you’ll build knowledge on how to support IBM’s Security QRadar SIEM V7.3.3 by:
- Implementing and managing a IBM Security QRadar SIEM V7.3.3 solution
- Becoming familiar with the product’s functionality and security policies
- Deploying, migrating and troubleshooting the IBM Security QRadar SIEM V7.3.3 software
At the end of your course you’ll sit exams CS0-002 and C1000-026, and get your IBM Certified SOC Analyst certification.
Authorised CompTIA Partner
At Firebrand, we are proud to be an award-winning, Platinum-level CompTIA Authorised Partner. Our courses feature the latest official curriculum and the best instructors, with exams included in the price of each course.
Our time-tested Lecture | Lab | Review method helps you become competent, confident, and certified at twice the speed. Why wait?
If you're just interested in the CompTIA Cybersecurity Analyst (CySA+), you can take it on its own in just 4 days. See the full course spec.
Who is this course for?
If you’re an Analyst interested in building your technical knowledge and skills in CompTIA and IBM software, this course is ideal for you!
Curriculum
CompTIA CySa+ (Cybersecurity Analyst)
Section 1: Threat Management
- Module 1: Given a scenario, apply environmental reconnaissance techniques using appropriate tools and processes
- Module 2: Given a scenario, analyse the results of a network reconnaissance
- Module 3: Given a network-based threat, implement or recommend the appropriate response and countermeasure
- Module 4: Explain the purpose of practices used to secure a corporate environment
Section 2: Vulnerability Management
- Module 1: Given a scenario, implement an information security vulnerability management process
- Module 2: Given a scenario, analyse the output resulting from a vulnerability scan
- Module 3: Compare and contrast common vulnerabilities found in the following targets
Section 3: Cyber Incident Response
- Module 1: Given a scenario, distinguish threat data or behaviour to determine the impact of an incident
- Module 2: Given a scenario, prepare a toolkit and use appropriate forensic tools during an investigation
- Module 3: Explain the importance of communication during the incident response process
- Module 4: Given a scenario, analyse common symptoms to select the best course of action to support incident response
- Module 5: Summarise the incident recovery and post-incident response process
Section 4: Security Architecture and Tool Sets
- Module 1: Explain the relationship between frameworks, common policies, controls, and procedures
- Module 2: Given a scenario, use data to recommend remediation of security issues related to identity and access management
- Module 3: Given a scenario, review security architecture and make recommendations to implement compensating controls
- Module 4: Given a scenario, use application security best practices while participating in the Software Development Life Cycle (SDLC)
- Module 5: Compare and contrast the general purpose and reasons for using various cybersecurity tools and technologies
IBM Security QRadar SIEM V7.3.3 Fundamental Administration
Section 1: Implementing
- Module 1: Plan and design QRadar deployment
- Module 2: Implement and install QRadar
- Module 3: Add Managed Hosts
Section 2: Migrating and upgrading
- Module 1: Plan QRadar upgrade and migration
- Module 2: Review documentation and release notes
- Module 3: Perform QRadar updates, patches and upgrades
- Module 4: Perform migration (e.g., backup and restore, import and export content)
Section 3: Configuring and administering tasks
- Module 1: Configure event flow sources and custom properties
- Module 2: Maintain configuration and data backups
- Module 3: Create and administer users, user roles, and security profiles
- Module 4: Manage the license per allocation
- Module 5: Create, review and modify rules, building blocks and reference sets
- Module 6: Configure and manage retention policies (i.e., data and assets)
- Module 7: Create and manage saved searches, index, global views, dashboards and reports
- Module 8: Deploy and manage applications and content packages
- Module 9: Configure global system notifications
- Module 10: Configure and apply network hierarchy
- Module 11: Configure and manage domain and tenants
- Module 12: Use the asset database
- Module 13: Schedule and run a VA scan
Section 4: Monitoring
- Module 1: Monitor QRadar Notifications and error messages
- Module 2: Review and interpret system monitoring dashboards
- Module 3: Verify QRadar processes and services
- Module 4: Monitor QRadar performance
- Module 5: Use apps and tools for monitoring (e.g., QDI, assistant app, incident overview, DrQ)
- Module 6: Check system maintenance and health of appliances
- Module 7: Monitor offences and detect anomalies
Section 5: Troubleshooting
- Module 1: Demonstrate knowledge of key commands to interpret QRadar services and processes
- Module 2: Explain error messages and notifications
- Module 3: Interpret the basic logs (e.g., qradar.error, qradar.log)
- Module 4: Use embedded troubleshooting tools and scripts
Exam Track
As part of your accelerated course, you’ll sit the following exams at the Firebrand Training centre, covered by your Certification Guarantee:
CompTIA CySa+ (Cybersecurity Analyst)
- Exam code: CS0-002
- Format: Multiple-choice & performance-based
- Duration: 165 minutes
- Passing score: 750 (on a scale of 100-900)
IBM Security QRadar SIEM V7.3.3 Fundamental Administration
- Exam code: C1000-026
- Duration: 90 minutes
- Passing score: 40/60 (66.7%)
- Domains:
- Implementing (8%)
- Migrating and upgrading (12%)
- Configuring and administering tasks (42%)
- Monitoring (25%0
- Troubleshooting (13%)
Prerequisites
Before attending this accelerated course, CompTIA CySa+ and IBM Security QRadar SIEM V7.3.3 Fundamental Administration have individual prerequisites you'll need in order to get certified:
CompTIA CySa+ (Cybersecurity Analyst)
- Network+, Security+ or equivalent knowledge
- Minimum of 3-4 years of information security or related experience
IBM QRadar SIEM V7.3.3 Fundamental Administration
You'll need basic knowledge of:
- RedHat
- Networking
- Basic Query Language
- Regular Expressions
- System architecture design
- Security platform
What's Included
Your accelerated course includes:
- Accommodation *
- Meals, unlimited snacks, beverages, tea and coffee *
- On-site exams **
- Exam vouchers **
- Practice tests **
- Certification Guarantee ***
- Courseware
- Up-to 12 hours of instructor-led training each day
- 24-hour lab access
- Digital courseware **
* For residential training only. Accommodation is included from the night before the course starts. This doesn't apply for online courses.
** Some exceptions apply. Please refer to the Exam Track or speak with our experts.
*** Pass first time or train again free as many times as it takes, unlimited for 1 year. Just pay for accommodation, exams, and incidental costs.
Benefits
Seven reasons why you should sit your course with Firebrand Training
- Two options of training. Choose between residential classroom-based, or online courses
- You'll be certified fast. With us, you’ll be trained in record time
- Our course is all-inclusive. A one-off fee covers all course materials, exams**, accommodation* and meals*. No hidden extras.
- Pass the first time or train again for free. This is our guarantee. We’re confident you’ll pass your course the first time. But if not, come back within a year and only pay for accommodation, exams and incidental costs
- You’ll learn more. A day with a traditional training provider generally runs from 9 am – 5 pm, with a nice long break for lunch. With Firebrand Training you’ll get at least 12 hours/day of quality learning time, with your instructor
- You’ll learn faster. Chances are, you’ll have a different learning style to those around you. We combine visual, auditory and tactile styles to deliver the material in a way that ensures you will learn faster and more easily
- You’ll be studying with the best. We’ve been named in the Training Industry’s “Top 20 IT Training Companies of the Year” every year since 2010. As well as winning many more awards, we’ve trained and certified over 135,000 professionals
*For residential training only. Doesn't apply for online courses
**Some exceptions apply. Please refer to the Exam Track or speak with our experts
Think you are ready for the course? Take a FREE practice test to assess your knowledge! Free Practice Test