Cisco - Performing CyberOps Using Cisco Security Technologies (CBRCOR) v1.0

Duration

Duration:

Just 5 Days

Method

Method:

Classroom / Online / Hybrid

Next date

Next date:

30/9/2024 (Monday)

Overview

The accelerated Performing CyberOps Using Cisco Security Technologies (CBRCOR) v1.0 course, guides you through cybersecurity operations fundamentals, methods, and automation. The knowledge you gain in this training will prepare you for the role of Information Security Analyst on a Security Operations Center (SOC) team. You will learn foundational concepts and their application in real-world scenarios, and how to leverage playbooks in formulating an Incident Response (IR).

This course teaches you how to use automation for security using cloud platforms and a SecDevOps methodology. You will learn the techniques for detecting cyberattacks, analyzing threats, and making appropriate recommendations to improve cybersecurity. This training will help you: Gain an advanced understanding of the tasks involved for senior-level roles in a security operations center Configure common tools and platforms used by security operation teams via practical application Prepare you to respond like a hacker in real-life attack scenarios and submit recommendations to senior management

In just 5 days, you’ll also learn how to:

  • Describe the types of service coverage within a SOC and operational responsibilities associated with each.
  • Compare security operations considerations of cloud platforms.
  • Describe the general methodologies of SOC platforms development, management, and automation.
  • Explain asset segmentation, segregation, network segmentation, micro-segmentation, and approaches to each, as part of asset controls and protections.
  • Describe Zero Trust and associated approaches, as part of asset controls and protections.
  • Perform incident investigations using Security Information and Event Management (SIEM) and/or security orchestration and automation (SOAR) in the SOC.
  • Use different types of core security technology platforms for security monitoring, investigation, and response.
  • Describe the DevOps and SecDevOps processes.
  • Explain the common data formats, for example, JavaScript Object Notation (JSON), HTML, XML, Comma-Separated Values (CSV).
  • Describe API authentication mechanisms.
  • Analyze the approach and strategies of threat detection, during monitoring, investigation, and response.
  • Determine known Indicators of Compromise (IOCs) and Indicators of Attack (IOAs).
  • Interpret the sequence of events during an attack based on analysis of traffic patterns.
  • Describe the different security tools and their limitations for network analysis (for example, packet capture tools, traffic analysis tools, network log analysis tools).
  • Analyze anomalous user and entity behavior (UEBA).
  • Perform proactive threat hunting following best practices.

At the end of this course, you’ll sit the Cisco exam, and achieve your Performing CyberOps Using Cisco Security Technologies (CBRCOR) v1.0 certification. Through Firebrand’s Lecture | Lab | Review methodology, you’ll get certified at twice the speed of the traditional training and get access to courseware, learn from certified instructors, and train in a distraction-free environment.

 

Audience

This course is ideal for:

  • Cybersecurity engineer
  • Cybersecurity investigator
  • Incident manager
  • Incident responder
  • Network engineer
  • SOC analysts currently functioning at entry level with a minimum of 1 year of experience 

Four reasons why you should sit your course with Firebrand Training

  1. You'll be trained and certified faster. Learn more on this 5-day accelerated course. You'll get at least 12 hours a day of quality learning time in a distraction-free environment
  2. Your course is all-inclusive. One simple price covers all course materials, exams, accommodation and meals – so you can focus on learning
  3. Pass first time or train again for free. Your expert instructor will deliver our unique accelerated learning methods, allowing you to learn faster and be in the best possible position to pass first time. In the unlikely event that you don't, it's covered by your Certification Guarantee
  4. Study with an award-winning training provider. We've won the Learning and Performance Institute's "Training Company of the Year" three times. Firebrand is your fastest way to learn, with 134.561 students saving more than one million hours since 2001

Curriculum

Lab Outline:

  • Module 1: Explore Cisco SecureX Orchestration
  • Module 2: Explore Splunk Phantom Playbooks
  • Module 3: Examine Cisco Firepower Packet Captures and PCAP Analysis
  • Module 4: Validate an Attack and Determine the Incident Response
  • Module 5: Submit a Malicious File to Cisco Threat Grid for Analysis
  • Module 6: Endpoint-Based Attack Scenario Referencing MITRE ATTACK
  • Module 7: Evaluate Assets in a Typical Enterprise Environment
  • Module 8: Explore Cisco Firepower NGFW Access Control Policy and Snort Rules
  • Module 9: Investigate IOCs from Cisco Talos Blog Using Cisco SecureX
  • Module 10: Explore the ThreatConnect Threat Intelligence Platform
  • Module 11: Track the TTPs of a Successful Attack Using a TIP
  • Module 12: Query Cisco Umbrella Using Postman API Client
  • Module 13: Fix a Python API Script
  • Module 14: Create Bash Basic Scripts
  • Module 15: Reverse Engineer Malware
  • Module 16: Perform Threat Hunting
  • Module 17: Conduct an Incident Response

Exam Track

At the end of this accelerated course, you’ll sit the following exam at the Firebrand Training centre, covered Certification Guarantee:

Performing CyberOps Using Cisco Security Technologies (CBRCOR) v1.0 Exam 350-201

  • Duration: 120-minutes
  • Format: The multiple-choice format tests knowledge of core cybersecurity operations including cybersecurity fundamentals, techniques, policies, processes, and automation.
  • Domains:
    • Monitoring for cyberattacks
    • Analyzing high volume of data using automation tools and platforms—both open source and commercial
    • Accurately identifying the nature of attack and formulate a mitigation plan
    • Scenario-based questions; for example, using a screenshot of output from a tool, you may be asked to interpret portions of output and establish conclusions

What's Included

Your accelerated course includes:

  • Accommodation *
  • Meals, unlimited snacks, beverages, tea and coffee *
  • On-site exams **
  • Exam vouchers **
  • Practice tests **
  • Certification Guarantee ***
  • Courseware
  • Up-to 12 hours of instructor-led training each day
  • 24-hour lab access
  • Digital courseware **
  • * For residential training only. Accommodation is included from the night before the course starts. This doesn't apply for online courses.
  • ** Some exceptions apply. Please refer to the Exam Track or speak with our experts
  • *** Pass first time or train again free as many times as it takes, unlimited for 1 year. Just pay for accommodation, exams, and incidental costs.

Prerequisites

Before attending this accelerated course, you should have:

  • Familiarity with UNIX/Linux shells (bash, csh) and shell commands.
  • Familiarity with the Splunk search and navigation functions
  • Basic understanding of scripting using one or more of Python, JavaScript, PHP or similar.

 

  • Recommended Cisco offering that may help you prepare for this training:
    • Understanding Cisco Cybersecurity Operations Fundamentals (CBROPS)
    • Implementing and Administering Cisco Solutions (CCNA)

  • Recommended third-party resources:
    • Splunk Fundamentals 1 Blue Team Handbook: Incident Response Edition by Don Murdoch
    • Threat Modeling- Designing for Security y Adam Shostack
    • Red Team Field Manual by Ben Clark
    • Blue Team Field Manual by Alan J White
    • Purple Team Field Manual by Tim Bryant
    • Applied Network Security and Monitoring by Chris Sanders and Jason Smith

Are you ready to get certified in record time?

We interview all applicants for the course on their technical background, degrees and certifications held, and general suitability. If you get through this screening process, it means you stand a great chance of passing.

Firebrand Training is an immersive training environment. You must be committed to the course. The above prerequisites are guidelines, but many students with less experience have other background or traits that have enabled their success in accelerated training through Firebrand Training.

If you have any doubts as to whether you meet the pre-requisites please call 21 96 61 82 and speak to one of our enrolment consultants, who can help you with a training plan.

Reviews

We've currently trained 134.561 students in 12 years. We asked them all to review our Accelerated Learning. Currently,
96,14% have said Firebrand exceeded their expectations:

"The staff, training facilities and accommodation are all of a high standard, and thus I will be looking to return in the future to undertake further courses."
J.H.. (8/4/2024 (Monday) to 13/4/2024 (Saturday))

"Our instructor was extremely knowledgeable in this subject and was helpful when delegates were confused in certain areas."
Anonymous. (8/4/2024 (Monday) to 13/4/2024 (Saturday))

"A great instructor with a wealth of knowledge. This is the perfect course for anyone who struggles to find the time for self study and wants to get the training done in a short space of time."
E.W.. (8/4/2024 (Monday) to 13/4/2024 (Saturday))

"A superb instructor at explaining complex topics while keeping every member of the class engaged. I found the classroom sessions and the 1-1 Q&A after evening meal especially helpful, and it was a really uplifting experience learning so much content in such a short space of time, because of how easy our instructor made it seem!"
A.S.. (8/4/2024 (Monday) to 13/4/2024 (Saturday))

"Great facilities, easy to get to, knowledgeable instructors and a testing centre to. All you need for a good learning experience and to get certified in a week."
A.S.. (18/3/2024 (Monday) to 23/3/2024 (Saturday))

Course Dates

Start

Finish

Status

Location

Book now

27/5/2024 (Monday)

31/5/2024 (Friday)

Finished - Leave feedback

-

 

30/9/2024 (Monday)

4/10/2024 (Friday)

Wait list

Nationwide

 

11/11/2024 (Monday)

15/11/2024 (Friday)

Limited availability

Nationwide

 

 

3/2/2025 (Monday)

7/2/2025 (Friday)

Open

Nationwide

 

17/3/2025 (Monday)

21/3/2025 (Friday)

Open

Nationwide

 

Latest Reviews from our students