Logo

Cisco Performing CyberOps Using Cisco Security Technologies (CBRCOR v1.0)

Code: cbrcor

What you'll learn

The accelerated Performing CyberOps Using Cisco Security Technologies (CBRCOR) v1.0 course, guides you through cybersecurity operations fundamentals, methods, and automation. The knowledge you gain in this training will prepare you for the role of Information Security Analyst on a Security Operations Center (SOC) team. You will learn foundational concepts and their application in real-world scenarios, and how to leverage playbooks in formulating an Incident Response (IR).

This course teaches you how to use automation for security using cloud platforms and a SecDevOps methodology. You will learn the techniques for detecting cyberattacks, analyzing threats, and making appropriate recommendations to improve cybersecurity. This training will help you: Gain an advanced understanding of the tasks involved for senior-level roles in a security operations center Configure common tools and platforms used by security operation teams via practical application Prepare you to respond like a hacker in real-life attack scenarios and submit recommendations to senior management

In just 5 days, you’ll also learn how to:

  • Describe the types of service coverage within a SOC and operational responsibilities associated with each.
  • Compare security operations considerations of cloud platforms.
  • Describe the general methodologies of SOC platforms development, management, and automation.
  • Explain asset segmentation, segregation, network segmentation, micro-segmentation, and approaches to each, as part of asset controls and protections.
  • Describe Zero Trust and associated approaches, as part of asset controls and protections.
  • Perform incident investigations using Security Information and Event Management (SIEM) and/or security orchestration and automation (SOAR) in the SOC.
  • Use different types of core security technology platforms for security monitoring, investigation, and response.
  • Describe the DevOps and SecDevOps processes.
  • Explain the common data formats, for example, JavaScript Object Notation (JSON), HTML, XML, Comma-Separated Values (CSV).
  • Describe API authentication mechanisms.
  • Analyze the approach and strategies of threat detection, during monitoring, investigation, and response.
  • Determine known Indicators of Compromise (IOCs) and Indicators of Attack (IOAs).
  • Interpret the sequence of events during an attack based on analysis of traffic patterns.
  • Describe the different security tools and their limitations for network analysis (for example, packet capture tools, traffic analysis tools, network log analysis tools).
  • Analyze anomalous user and entity behavior (UEBA).
  • Perform proactive threat hunting following best practices.

At the end of this course, you’ll sit the Cisco exam, and achieve your Performing CyberOps Using Cisco Security Technologies (CBRCOR) v1.0 certification. Through Firebrand’s Lecture | Lab | Review methodology, you’ll get certified at twice the speed of the traditional training and get access to courseware, learn from certified instructors, and train in a distraction-free environment.

Audience

This course is ideal for:

  • Cybersecurity engineer
  • Cybersecurity investigator
  • Incident manager
  • Incident responder
  • Network engineer
  • SOC analysts currently functioning at entry level with a minimum of 1 year of experience

Curriculum

17 modules

Lab Outline:

  • Module 1: Explore Cisco SecureX Orchestration
  • Module 2: Explore Splunk Phantom Playbooks
  • Module 3: Examine Cisco Firepower Packet Captures and PCAP Analysis
  • Module 4: Validate an Attack and Determine the Incident Response
  • Module 5: Submit a Malicious File to Cisco Threat Grid for Analysis
  • Module 6: Endpoint-Based Attack Scenario Referencing MITRE ATTACK
  • Module 7: Evaluate Assets in a Typical Enterprise Environment
  • Module 8: Explore Cisco Firepower NGFW Access Control Policy and Snort Rules
  • Module 9: Investigate IOCs from Cisco Talos Blog Using Cisco SecureX
  • Module 10: Explore the ThreatConnect Threat Intelligence Platform
  • Module 11: Track the TTPs of a Successful Attack Using a TIP
  • Module 12: Query Cisco Umbrella Using Postman API Client
  • Module 13: Fix a Python API Script
  • Module 14: Create Bash Basic Scripts
  • Module 15: Reverse Engineer Malware
  • Module 16: Perform Threat Hunting
  • Module 17: Conduct an Incident Response

Prerequisites

Before attending this accelerated course, you should have:

  • Familiarity with UNIX/Linux shells (bash, csh) and shell commands.
  • Familiarity with the Splunk search and navigation functions
  • Basic understanding of scripting using one or more of Python, JavaScript, PHP or similar.

  • Recommended Cisco offering that may help you prepare for this training:
    • Understanding Cisco Cybersecurity Operations Fundamentals (CBROPS)
    • Implementing and Administering Cisco Solutions (CCNA)

  • Recommended third-party resources:
    • Splunk Fundamentals 1 Blue Team Handbook: Incident Response Edition by Don Murdoch
    • Threat Modeling- Designing for Security y Adam Shostack
    • Red Team Field Manual by Ben Clark
    • Blue Team Field Manual by Alan J White
    • Purple Team Field Manual by Tim Bryant
    • Applied Network Security and Monitoring by Chris Sanders and Jason Smith

Exam info

At the end of this accelerated course, you’ll sit the following exam at the Firebrand Training centre, covered Certification Guarantee:

Performing CyberOps Using Cisco Security Technologies (CBRCOR) v1.0 Exam 350-201

  • Duration: 120-minutes
  • Format: The multiple-choice format tests knowledge of core cybersecurity operations including cybersecurity fundamentals, techniques, policies, processes, and automation.
  • Domains:
    • Monitoring for cyberattacks
    • Analyzing high volume of data using automation tools and platforms—both open source and commercial
    • Accurately identifying the nature of attack and formulate a mitigation plan
    • Scenario-based questions; for example, using a screenshot of output from a tool, you may be asked to interpret portions of output and establish conclusions

Course Dates

Sorry, there are currently no dates available for this course. Please submit an enquiry and one of our team will contact you about potential future dates or alternative options.

FAQs

4 question

Yes, we do provide courses suitable for beginners. However, Firebrand's accelerated courses aren't easy and it's essential that you are interested and actively pursuing a career in IT.

Traditional training providers usually run their courses from 9am to 5pm. At Firebrand Training we maximise the number of learning hours to minimise the number of training days, so you’ll be back to your job as quickly as possible. You don’t waste time travelling to several courses and finding an exam centre after that.

Firebrand's accelerated courses are constantly reviewed. We ask our delegates for feedback after every course. We are official partners with leading vendors and therefore, we're provided with certification changes and updates, which we can then implement in our course delivery at a very early stage. This feedback is then analysed in view of changes or discrepancies. We will then address the topics mentioned and have a panel of subject matter experts provide us with valuable suggestions for improvement and solutions.

If you need to learn new skills and you want to be able to put them into practice quickly, then Firebrand is the right training company for you.

Our unique accelerated training method means that we are your fastest way to learn. By delivering training for up to 12 hours per day, seven days per week, with exam centres on-site, we ensure that you are trained and certified quicker than anywhere else, having spent less time out of the office away from the day job.

Can't find the answer you're looking for?

Our expert learning advisors are ready to help. Whether you need course recommendations, have technical queries, or want to discuss your learning goals, we're just a message away.

Related courses

All Cisco Courses

Train your team

Since 2001 we've trained 134,561 employees from thousands of large and small organisations, saving them more than one million hours in training time.

Learn More