Security Operations Architect

This course will help:
  • Gain knowledge and skills in designing, deploying, and managing a Fortinet solution for a Security Operations Center (SOC) using FortiSIEM and FortiSOAR
  • Learn how to analyze and respond to security incidents in accordance with industry-standard incident handling practices
  • Develop skills in creating SOC playbooks to automate incident monitoring and response processes
  • Learn how to apply Threat Hunting techniques to identify potential threats within the infrastructure
  • Learn how to integrate FortiAI into SOC workflows to improve the efficiency of threat analysis and response
  • Prepare for the Fortinet NSE 7 certification exam

Course syllabus:

  • SOC Concepts and Security Frameworks
  • Fortinet SOC with FortiSIEM and FortiSOAR
  • Incident Handling and FortiSIEM
  • Incident Handling and FortiSOAR
  • SOC Playbook Development
  • Threat Hunting

You will learn:

  • Describe the main functions and roles within a SOC
  • Identify the challenges that can be solved by the Fortinet SOC
  • Describe the MITRE ATT&CK Enterprise Matrix and the Cyber Kill Chain
  • Describe how to identify and reduce the attack surface
  • Describe common attack vectors
  • Describe the benefits of using FortiSIEM and FortiSOAR
  • Describe different Fortinet SOC deployment architectures
  • Describe the FortiSOAR Content Hub and connectors
  • Describe FortiAI features
  • Describe FortiAI in FortiSIEM and FortiSOAR
  • Describe reactive and proactive threat hunting processes
  • Generate threat hunting hypotheses
  • Identify and configure data sources
  • Configure data ingestion
  • Configure FortiSIEM rules
  • Execute attack vectors
  • Describe the NIST SP 800-61 incident handling process
  • Describe the incident handling workflow with FortiSIEM and FortiSOAR
  • Analyze, handle, and tune incidents on FortiSIEM
  • Ingest FortiSIEM incidents into FortiSOAR for incident handling
  • Escalate FortiSOAR alerts into incidents
  • Describe automation requirements
  • Describe FortiSOAR playbook steps
  • Run playbooks to enrich indicators
  • Configure a playbook to retrieve a hash rating from FortiSandbox
  • Perform containment on FortiGate, Windows Active Directory, and FortiClient EMS using FortiSOAR connectors
  • Eradicate artifacts from a compromised host
  • Release a compromised host from quarantine after recovery
  • Manage playbook history logs

Pre-requisites:

This course assumes knowledge of the topics covered in the FortiSIEM Analyst course, or equivalent work experience.

Sign up for a course Security Operations Architect