Cisco - Performing CyberOps Using Cisco Security Technologies (CBRCOR) v1.0

Varighet

Varighet:

Bare 5 dager

Metode

Metode:

klasserommet / på nett / Hybrid

Neste dato

Neste dato:

30/9/2024 (Mandag)

Overview

The accelerated Performing CyberOps Using Cisco Security Technologies (CBRCOR) v1.0 course, guides you through cybersecurity operations fundamentals, methods, and automation. The knowledge you gain in this training will prepare you for the role of Information Security Analyst on a Security Operations Center (SOC) team. You will learn foundational concepts and their application in real-world scenarios, and how to leverage playbooks in formulating an Incident Response (IR).

This course teaches you how to use automation for security using cloud platforms and a SecDevOps methodology. You will learn the techniques for detecting cyberattacks, analyzing threats, and making appropriate recommendations to improve cybersecurity. This training will help you: Gain an advanced understanding of the tasks involved for senior-level roles in a security operations center Configure common tools and platforms used by security operation teams via practical application Prepare you to respond like a hacker in real-life attack scenarios and submit recommendations to senior management

In just 5 days, you’ll also learn how to:

  • Describe the types of service coverage within a SOC and operational responsibilities associated with each.
  • Compare security operations considerations of cloud platforms.
  • Describe the general methodologies of SOC platforms development, management, and automation.
  • Explain asset segmentation, segregation, network segmentation, micro-segmentation, and approaches to each, as part of asset controls and protections.
  • Describe Zero Trust and associated approaches, as part of asset controls and protections.
  • Perform incident investigations using Security Information and Event Management (SIEM) and/or security orchestration and automation (SOAR) in the SOC.
  • Use different types of core security technology platforms for security monitoring, investigation, and response.
  • Describe the DevOps and SecDevOps processes.
  • Explain the common data formats, for example, JavaScript Object Notation (JSON), HTML, XML, Comma-Separated Values (CSV).
  • Describe API authentication mechanisms.
  • Analyze the approach and strategies of threat detection, during monitoring, investigation, and response.
  • Determine known Indicators of Compromise (IOCs) and Indicators of Attack (IOAs).
  • Interpret the sequence of events during an attack based on analysis of traffic patterns.
  • Describe the different security tools and their limitations for network analysis (for example, packet capture tools, traffic analysis tools, network log analysis tools).
  • Analyze anomalous user and entity behavior (UEBA).
  • Perform proactive threat hunting following best practices.

At the end of this course, you’ll sit the Cisco exam, and achieve your Performing CyberOps Using Cisco Security Technologies (CBRCOR) v1.0 certification. Through Firebrand’s Lecture | Lab | Review methodology, you’ll get certified at twice the speed of the traditional training and get access to courseware, learn from certified instructors, and train in a distraction-free environment.

 

Audience

This course is ideal for:

  • Cybersecurity engineer
  • Cybersecurity investigator
  • Incident manager
  • Incident responder
  • Network engineer
  • SOC analysts currently functioning at entry level with a minimum of 1 year of experience 

Her er 8 grunner til hvorfor du skal gjennomføre ditt hos Firebrand Training:

  1. Du blir utdannet og sertifisert på bare 5 dager. Hos oss får du din utdanning og sertifisering på rekordtid, en sertifisering du også gjennomfører der og da som en integrert del av den intensive, akselererte utdanningen.
  2. Alt er inkludert. Et engangsbeløp dekker alt kursmaterial, eksamen, kost og losji og tilbyr den mest kostnadseffektive måten å gjennomføre ditt kurs og sertifisering på. Og dette uten noen uannonserte ytterligere kostnader.
  3. Du klarer sertifiseringen første gangen eller kan gå kurset om igjen kostnadsfritt. Det er vår garanti. Vi er sikre på at du vil klare din sertifisering første gangen. Men skulle du mot formodning ikke gjøre det kan du innen et år komme tilbake og kun betale for eventuelle overnattinger og din eksamen. Alt annet er gratis.
  4. Du lærer deg mer.Tradisjonelle utdanningsdager varer fra kl. 09.00 til 16.00 med lange lunsj- og kaffepauser. Hos Firebrand Training får du minst 12 timers effektiv og fokusert kvalitetsutdanning hver dag sammen med din instruktør, uten private eller arbeidsrelaterte, forstyrrende momenter.
  5. Du lærer deg raskere. Vi kombinerer de tre innlæringsmetodene (Presentasjon |Øving| Diskusjon) slik at vi gjennomfører kurset på en måte som sikrer at du lærer deg raskere og lettere.
  6. Du er i sikre hender.Vi har utdannet og sertifisert 134.561 personer, vi er partner med alle de store navn i bransjen og vi har vunnet atskillige utmerkelser, bla. a. "Årets Learning Partner 2010, 2011, 2012, 2013 og 2015” fra Microsoft Danmark og med en vekst på 1430 % siden 2009 er vi årets Gazelle prisvinner på Sjælland, Danmark.
  7. Du lærer deg ikke bare teorien. Vi har videreutviklet kursen og tilbyr flere praktiske øvelser og sikrer på den måten, at du kan bruke dine ferdigheter for å løse daglige praktiske problemstillinger.
  8. Du lærer av de beste. Våre instruktører på er de beste i bransjen og tilbyr en helt unik blanding av kunnskap, praktisk erfaring og pasjon for å lære bort.

Curriculum

Lab Outline:

  • Module 1: Explore Cisco SecureX Orchestration
  • Module 2: Explore Splunk Phantom Playbooks
  • Module 3: Examine Cisco Firepower Packet Captures and PCAP Analysis
  • Module 4: Validate an Attack and Determine the Incident Response
  • Module 5: Submit a Malicious File to Cisco Threat Grid for Analysis
  • Module 6: Endpoint-Based Attack Scenario Referencing MITRE ATTACK
  • Module 7: Evaluate Assets in a Typical Enterprise Environment
  • Module 8: Explore Cisco Firepower NGFW Access Control Policy and Snort Rules
  • Module 9: Investigate IOCs from Cisco Talos Blog Using Cisco SecureX
  • Module 10: Explore the ThreatConnect Threat Intelligence Platform
  • Module 11: Track the TTPs of a Successful Attack Using a TIP
  • Module 12: Query Cisco Umbrella Using Postman API Client
  • Module 13: Fix a Python API Script
  • Module 14: Create Bash Basic Scripts
  • Module 15: Reverse Engineer Malware
  • Module 16: Perform Threat Hunting
  • Module 17: Conduct an Incident Response

Exam Track

At the end of this accelerated course, you’ll sit the following exam at the Firebrand Training centre, covered Certification Guarantee:

Performing CyberOps Using Cisco Security Technologies (CBRCOR) v1.0 Exam 350-201

  • Duration: 120-minutes
  • Format: The multiple-choice format tests knowledge of core cybersecurity operations including cybersecurity fundamentals, techniques, policies, processes, and automation.
  • Domains:
    • Monitoring for cyberattacks
    • Analyzing high volume of data using automation tools and platforms—both open source and commercial
    • Accurately identifying the nature of attack and formulate a mitigation plan
    • Scenario-based questions; for example, using a screenshot of output from a tool, you may be asked to interpret portions of output and establish conclusions

What's Included

Prerequisites

Before attending this accelerated course, you should have:

  • Familiarity with UNIX/Linux shells (bash, csh) and shell commands.
  • Familiarity with the Splunk search and navigation functions
  • Basic understanding of scripting using one or more of Python, JavaScript, PHP or similar.

 

  • Recommended Cisco offering that may help you prepare for this training:
    • Understanding Cisco Cybersecurity Operations Fundamentals (CBROPS)
    • Implementing and Administering Cisco Solutions (CCNA)

  • Recommended third-party resources:
    • Splunk Fundamentals 1 Blue Team Handbook: Incident Response Edition by Don Murdoch
    • Threat Modeling- Designing for Security y Adam Shostack
    • Red Team Field Manual by Ben Clark
    • Blue Team Field Manual by Alan J White
    • Purple Team Field Manual by Tim Bryant
    • Applied Network Security and Monitoring by Chris Sanders and Jason Smith

Anmeldelser

Vi har lært opp 134.561 personer på 12 år. Vi ba dem om å anmelde vår akselererte opplæring. Akkurat nå har 95,77% angitt at Firebrand overgikk forventningene:

"The staff, training facilities and accommodation are all of a high standard, and thus I will be looking to return in the future to undertake further courses."
J.H.. (8/4/2024 (Mandag) til 13/4/2024 (Lørdag))

"Our instructor was extremely knowledgeable in this subject and was helpful when delegates were confused in certain areas."
Anonymous. (8/4/2024 (Mandag) til 13/4/2024 (Lørdag))

"A great instructor with a wealth of knowledge. This is the perfect course for anyone who struggles to find the time for self study and wants to get the training done in a short space of time."
E.W.. (8/4/2024 (Mandag) til 13/4/2024 (Lørdag))

"A superb instructor at explaining complex topics while keeping every member of the class engaged. I found the classroom sessions and the 1-1 Q&A after evening meal especially helpful, and it was a really uplifting experience learning so much content in such a short space of time, because of how easy our instructor made it seem!"
A.S.. (8/4/2024 (Mandag) til 13/4/2024 (Lørdag))

"Great facilities, easy to get to, knowledgeable instructors and a testing centre to. All you need for a good learning experience and to get certified in a week."
A.S.. (18/3/2024 (Mandag) til 23/3/2024 (Lørdag))

Kursdatoer

Start

Slutt

Kapasitet

Plass

Registrer deg

27/5/2024 (Mandag)

31/5/2024 (Fredag)

Ferdig - Gi tilbakemelding

-

 

30/9/2024 (Mandag)

4/10/2024 (Fredag)

Venteliste

Landsdekkende

 

11/11/2024 (Mandag)

15/11/2024 (Fredag)

Begrenset kapasitet

Landsdekkende

 

 

3/2/2025 (Mandag)

7/2/2025 (Fredag)

Ledige plasser

Landsdekkende

 

17/3/2025 (Mandag)

21/3/2025 (Fredag)

Ledige plasser

Landsdekkende

 

Siste anmeldelser fra studenten vår