|
所在平台: Udemy |
课程主页: https://www.udemy.com/course/cisco-threat-hunting-and-defending-exam-questions-prep/
课程评论:没有评论
课程名称:思科威胁狩猎与防御 (300-220) CBRTHD *2025* 课程概述:本课程由NextGen LabWorks提供,旨在帮助学员为思科CyberOps专业认证考试300-220 CBRTHD做好准备。课程内容重点关注利用思科技术进行先进的威胁狩猎、检测和防御策略,以保护现代网络环境。 学习内容: 1. **威胁狩猎基础** (20%) - 理解威胁狩猎成熟度模型及MITRE ATT&CK等威胁建模框架。 - 学习自动化在Security Operations Center (SOC)中的作用,并分析安全日志。 - 识别高级持续性威胁(APT)并利用威胁情报。 2. **威胁建模技术** (10%) - 针对不同攻击场景选择合适的威胁建模方法论。 - 应用MITRE ATT&CK策略,并根据网络杀伤链优先考虑攻击。 - 区分结构化和非结构化的威胁狩猎方法。 3. **威胁参与者归属技术** (20%) - 分析安全日志中的攻击战术、技术和流程(TTP)。 - 识别妨碍威胁检测的痕迹和妨碍指标(IoC)。 - 区分恶意行为者、伦理黑客和渗透测试人员。 4. **威胁狩猎技术** (20%) - 使用脚本语言进行威胁检测和取证分析。 - 进行云原生狩猎并分析终端数据以发现未检测的威胁。 - 识别指挥与控制(C2)通信并进行代码级分析。 5. **威胁狩猎流程** (20%) - 理解内存驻留攻击并进行逆向工程以检测威胁。 - 识别现有检测机制中的不足并提出改进建议。 - 制定运行手册、安全策略和缓解威胁的方案。 6. **威胁狩猎结果** (10%) - 通过整合多种安全产品提高数据可视性。 - 诊断威胁检测中的分析缺口并提出缓解策略。 - 使用演示工具传达发现并推动安全改进。 适合对象: - 从事威胁检测、狩猎和事件响应的安全专业人员。 - 负责网络安全操作的网络管理员和IT专家。 - 处理高级威胁情报的威胁分析师和SOC分析师。 - 监督威胁管理策略的网络安全管理人员。 - 准备参加思科CyberOps专业认证300-220的人士。 通过NextGen LabWorks的专业培训,掌握识别、分析和缓解网络威胁的基本技能,增强信心,应对300-220 CBRTHD考试,并加强保护现代网络基础设施的能力。
Threat Hunting and Defending with Cisco Technologies (300-220) - by NextGen LabWorksPrepare for the Cisco CyberOps Professional 300-220 CBRTHD certification exam with NextGen LabWorks' structured practice course. This course focuses on advanced threat hunting, detection, and defense strategies, using Cisco technologies to secure modern network environments.What You'll Learn:1. Threat Hunting Fundamentals (20%)Understand the Threat Hunting Maturity Model and threat modeling frameworks like MITRE ATT & CK.Learn the role of automation in SOC operations and analyze security logs.Identify advanced persistent threats (APTs) and leverage threat intelligence.2. Threat Modeling Techniques (10%)Select appropriate threat modeling methodologies for different attack scenarios.Apply MITRE ATT & CK tactics and prioritize attacks using the Cyber Kill Chain.Differentiate between structured and unstructured threat hunting approaches.3. Threat Actor Attribution Techniques (20%)Analyze attack tactics, techniques, and procedures (TTPs) from security logs.Identify artifacts and indicators of compromise (IoCs) to detect hidden threats.Distinguish between malicious actors, ethical hackers, and penetration testers.4. Threat Hunting Techniques (20%)Use scripting languages for threat detection and forensic analysis.Conduct cloud-native hunts and analyze endpoint artifacts for undetected threats.Identify command-and-control (C2) communications and perform code-level analysis.5. Threat Hunting Processes (20%)Understand memory-resident attacks and perform reverse engineering for threat detection.Identify gaps in existing detection mechanisms and recommend improvements.Develop runbooks, security policies, and remediation strategies for threat mitigation.6. Threat Hunting Outcomes (10%)Improve data visibility by integrating multiple security products.Diagnose analytical gaps in threat detection and suggest mitigation strategies.Use presentation tools to communicate findings and drive security improvements.Who This Course Is For:Security professionals working in threat detection, hunting, and incident response.Network administrators and IT specialists responsible for cybersecurity operations.Threat analysts and SOC analysts handling advanced threat intelligence.Cybersecurity managers overseeing threat management strategies.Individuals preparing for the Cisco CyberOps Professional 300-220 certification.Equip yourself with the essential skills to identify, analyze, and mitigate cyber threats with NextGen LabWorks' expert-led training. Build confidence for the 300-220 CBRTHD exam and strengthen your ability to defend modern network infrastructures.