200-201 CBROPS Cisco Cybersecurity Operations Fundamental QA

所在平台: Udemy

课程主页: https://www.udemy.com/course/cbrops-cisco-cybersecurity-operations-fundamental/

课程评论:没有评论

第一个写评论        关注课程

课程简介

课程名称:200-201 CBROPS Cisco 网络安全操作基础 QA 课程概述: 您是否准备好为Cisco认证的CyberOps助理认证考试做好准备?Cisco认证的CyberOps助理课程侧重于您在安全运营中心(SOCs)中的真实工作所需的最新操作技能和知识。SOC分析师是对抗网络安全威胁的第一道防线,负责预防和检测威胁以保护您的组织。Understanding Cisco Cybersecurity Operations Fundamentals (CBROPS)考试(200-201)是一个持续120分钟的评估,与Cisco认证CyberOps助理认证相关。CBROPS考试测试考生与安全概念、安全监控、基于主机的分析、网络入侵分析以及安全政策和程序相关的知识和技能。课程旨在帮助考生为此考试做好准备。 考试主题包括: 1.0 安全概念 - 理解CIA三元组 - 比较安全部署和概念 - 安全术语的解释 - 防御深度策略的原则 - 数据可见性面临的挑战 - 5元组方法的解释 - 规则检测与行为/统计检测的比较 2.0 安全监控 - 攻击面与漏洞的比较 - 网络与Web应用程序攻击的描述 - 社会工程和端点攻击的识别 - 证书对安全性的影响 3.0 基于主机的分析 - 操作系统组件的识别 - 证据类型的识别 - 日志的解释与事件的识别 4.0 网络入侵分析 - 事件与源技术的映射 - 深度包检测与数据包过滤的比较 - 使用Wireshark提取TCP流中的文件 5.0 安全政策与程序 - 事故响应计划的元素 - NIST.SP800-61中的事件处理过程应用 - 网络与服务器定位要素的识别 该课程为准备CBROPS考试的考生提供了全面的知识基础与实用技能,帮助他们在安全运营领域中立足。

课程评论(0条)

课程详情

Are you ready to prepare for the Cisco Certified CyberOps Associate certification exam ?The Cisco Certified CyberOps Associate program focuses on the latest operational skills and knowledge you need for real-world jobs in security operations centers (SOCs). SOC analysts serve as the front line of defense against cybersecurity threats - preventing and detecting threats to defend your organization. The Understanding Cisco Cybersecurity Operations Fundamentals (CBROPS) exam (200-201) is a 120-minute assessment that is associated with the Cisco Certified CyberOps Associate certification. The CBROPS exam tests a candidate's knowledge and skills related to security concepts, security monitoring, host-based analysis, network intrusion analysis, and security policies and procedures. The course, Understanding Cisco Cybersecurity Operations Fundamentals, helps candidates to prepare for this exam.Cisco 200-201 CBROPS Exam Topics:1.0 Security ConceptsDescribe the CIA triadCompare security deploymentsDescribe security termsCompare security conceptsDescribe the principles of the defense-in-depth strategyCompare access control modelsDescribe terms as defined in CVSSIdentify the challenges of data visibility (network, host, and cloud) in detectionIdentify potential data loss from provided traffic profilesInterpret the 5-tuple approach to isolate a compromised host in a grouped set of logsCompare rule-based detection vs. behavioral and statistical detection2.0 Security MonitoringCompare attack surface and vulnerabilityIdentify the types of data provided by these technologiesDescribe the impact of these technologies on data visibilityDescribe the uses of these data types in security monitoringDescribe network attacks, such as protocol-based, denial of service, distributed denial of service, and man-in-the-middleDescribe web application attacks, such as SQL injection, command injections, and crosssite scriptingDescribe social engineering attacksDescribe endpoint-based attacks, such as buffer overflows, command and control (C2), malware, and ransomwareDescribe evasion and obfuscation techniques, such as tunneling, encryption, and proxiesDescribe the impact of certificates on security (includes PKI, public/private crossing the network, asymmetric/symmetric)3.0 Host-Based AnalysisDescribe the functionality of these endpoint technologies in regard to security monitoringIdentify components of an operating system (such as Windows and Linux)Describe the role of attribution in an investigationIdentify type of evidence used based on provided logsCompare tampered and untampered disk imageInterpret operating system, application, or command line logs to identify an eventInterpret the output report of a malware analysis tool (such as a detonation chamber or sandbox)4.0 Network Intrusion AnalysisMap the provided events to source technologiesCompare impact and no impact for these itemsCompare deep packet inspection with packet filtering and stateful firewall operationCompare inline traffic interrogation and taps or traffic monitoringCompare the characteristics of data obtained from taps or traffic monitoring and transactional data (NetFlow) in the analysis of network trafficExtract files from a TCP stream when given a PCAP file and WiresharkInterpret the fields in protocol headers as related to intrusion analysisInterpret common artifact elements from an event to identify an alertInterpret basic regular expressions5.0 Security Policies and ProceduresDescribe management conceptsDescribe the elements in an incident response plan as stated in NIST.SP800-61Apply the incident handling process (such as NIST.SP800-61) to an eventMap elements to these steps of analysis based on the NIST.SP800-61Map the organization stakeholders against the NIST IR categories (CMMC, NIST.SP800- 61)Describe concepts as documented in NIST.SP800-86Identify these elements used for network profilingIdentify these elements used for server profilingIdentify protected data in a networkClassify intrusion events into categories as defined by security models, such as Cyber Kill Chain Model and Diamond Model of IntrusionDescribe the relationship of SOC metrics to scope analysis (time to detect, time to contain, time to respond, time to control)

课程标签

0人关注该课程

主题相关的课程