Cisco Certified CyberOps Professional (350-201 CBRCOR) *NEW*

所在平台: Udemy

课程主页: https://www.udemy.com/course/cisco-certified-cyberops-professional-exam-prep-course/

课程评论:没有评论

第一个写评论        关注课程

课程简介

课程名称:思科认证网络安全运营专业(350-201 CBRCOR)*新* 课程概述:本课程《使用思科安全技术进行网络安全运营(v1.1)》是与思科网络安全运营专业认证相关的120分钟考试。该课程验证考生在关键网络安全运营领域的专业知识,包括基础知识、技术、流程和自动化。课程旨在帮助考生有效准备考试,并增强对这些关键领域的理解。 课程内容包括: 1. **基础知识** - 解析实施手册中的组件。 - 根据实施手册场景确定所需工具。 - 应用实施手册应对常见场景(如未授权提升、拒绝服务、DDoS、网站篡改)。 - 推断行业合规标准(如PCI、FISMA、FedRAMP等)。 - 描述网络风险保险的目的。 - 分析风险分析的基本要素(资产、脆弱性、威胁)。 - 应用事件响应工作流程及其改进指标。 - 描述云环境类型及其安全运营对比。 2. **技术** - 推荐满足特定需求的数据分析技术。 - 描述机器映像加固、资产安全态势评估的过程。 - 评估安全控制、诊断漏洞并建议改进。 - 应用网络分段及控制硬化。 - 理解数据丢失及其检测机制,推荐设备和软件的调优。 3. **流程** - 分析威胁模型中的组件,并确定常见案件的调查步骤。 - 应用恶意软件分析流程,包括样本提取和静态分析。 - 调查潜在的端点入侵和数据丢失,识别已知的攻击指标。 4. **自动化** - 比较编排和自动化的概念和平台。 - 理解API的使用限制,解释常见的HTTP响应代码。 - 利用Bash命令管理文件,描述CI/CD管道组件并应用DevOps原则于安全运营。 本课程旨在帮助考生建立系统的网络安全知识框架,掌握必要的工具和技术,从而在实际工作中有效应对网络安全挑战。

课程评论(0条)

课程详情

The Performing CyberOps Using Cisco Security Technologies v1.1 (CBRCOR 350-201) is a 120-minute exam linked to the Cisco CyberOps Professional Certification. It validates a candidate's expertise in key cybersecurity operations, including fundamentals, techniques, processes, and automation. This course is designed to help candidates effectively prepare for the exam and enhance their understanding of these critical areas.1.0 FundamentalsInterpret the components within a playbook.Determine the tools needed based on a playbook scenario.Apply the playbook for common scenarios (e.g., unauthorized elevation, DoS, DDoS, website defacement).Infer industry compliance standards (e.g., PCI, FISMA, FedRAMP, SOC, SOX, GDPR, Data Privacy, ISO 27101).Describe the purpose of cyber risk insurance.Analyze elements of risk analysis (asset, vulnerability, threat).Apply the incident response workflow.Describe improvement areas using incident response metrics.Describe types of cloud environments.Compare security operations for cloud platforms (e.g., IaaS, PaaS).2. TechniquesRecommend data analytic techniques to meet specific needs or answer specific questionsRecommend data analytics techniques for specific needs.Describe the use of hardening machine images for deployment.Describe the process of evaluating an asset's security posture.Evaluate security controls, diagnose gaps, and recommend improvements.Determine resources for industry standards for system hardening.Provide patching recommendations for given scenarios.Recommend services to disable based on scenarios.Apply network segmentation.Utilize network controls for hardening.Determine SecDevOps implications and recommendations.Explain the use of a Threat Intelligence Platform (TIP) for automation.Apply threat intelligence using relevant tools.Understand concepts of data loss, leakage, and data at rest/in motion/use.Describe mechanisms to detect/enforce data loss prevention (endpoint, network, application, cloud).Recommend tuning of devices and software across rules, filters, and policies.Describe security data management concepts.Use tools for security data analytics.Recommend workflow for escalation and automation from issues.Apply dashboard data for technical and leadership communication.Analyze anomalous user and entity behavior (UEBA).Determine the next actions based on user behavior alerts.Describe network analysis tools and limitations (packet capture, traffic, log analysis).Evaluate artifacts in packet capture files.Troubleshoot detection rules.Identify tactics, techniques, and procedures (TTPs) from an attack.3. ProcessesAnalyze components in a threat modelAnalyze components in a threat model.Determine investigation steps for common types of cases.Apply steps in the malware analysis process:Extract and identify samples (e.g., packet capture).Perform reverse engineering and dynamic malware analysis.Identify the need for static malware analysis.Perform static analysis and share results.Interpret the sequence of attack events based on traffic patterns.Investigate potential endpoint intrusions across various platforms (desktop, laptop, IoT, mobile).Identify known Indicators of Compromise (IOCs) and Indicators of Attack (IOAs).Investigate IOCs in sandbox environments and generate complex indicators.Investigate potential data loss across multiple vectors (e.g., cloud, endpoint, server).Recommend general mitigation steps for vulnerability issues.Recommend next steps for vulnerability triage and risk analysis using industry scoring systems (e.g., CVSS).4. AutomationCompare orchestration and automation concepts, platforms, and mechanisms.Interpret basic scripts (e.g., Python).Modify scripts to automate security operations tasks.Recognize common data formats (e.g., JSON, HTML, CSV, XML).Identify opportunities for automation, orchestration, and machine learning.Understand constraints when consuming APIs (rate limits, timeouts, payload).Explain common HTTP response codes associated with REST APIs.Evaluate parts of an HTTP response (code, headers, body).Interpret API authentication mechanisms (basic, token, API keys).Utilize Bash commands (file management, directory navigation, environmental variables).Describe components of a CI/CD pipeline.Apply DevOps principles in security operations.Describe the principles of Infrastructure as Code.

课程标签

0人关注该课程

主题相关的课程