Security Operations Architect
Главная страница » Курсы » Courses in English » Fortinet Courses » Fortinet NSE 7 » Security Operations Architect
- Duration: 2 days (12 hours)
- Date: on request
Security Operations Architect
This course will help:
- Gain knowledge and skills in designing, deploying, and managing a Fortinet solution for a Security Operations Center (SOC) using FortiSIEM and FortiSOAR
- Learn how to analyze and respond to security incidents in accordance with industry-standard incident handling practices
- Develop skills in creating SOC playbooks to automate incident monitoring and response processes
- Learn how to apply Threat Hunting techniques to identify potential threats within the infrastructure
- Learn how to integrate FortiAI into SOC workflows to improve the efficiency of threat analysis and response
- Prepare for the Fortinet NSE 7 certification exam
Course syllabus:
- SOC Concepts and Security Frameworks
- Fortinet SOC with FortiSIEM and FortiSOAR
- Incident Handling and FortiSIEM
- Incident Handling and FortiSOAR
- SOC Playbook Development
- Threat Hunting
You will learn:
- Describe the main functions and roles within a SOC
- Identify the challenges that can be solved by the Fortinet SOC
- Describe the MITRE ATT&CK Enterprise Matrix and the Cyber Kill Chain
- Describe how to identify and reduce the attack surface
- Describe common attack vectors
- Describe the benefits of using FortiSIEM and FortiSOAR
- Describe different Fortinet SOC deployment architectures
- Describe the FortiSOAR Content Hub and connectors
- Describe FortiAI features
- Describe FortiAI in FortiSIEM and FortiSOAR
- Describe reactive and proactive threat hunting processes
- Generate threat hunting hypotheses
- Identify and configure data sources
- Configure data ingestion
- Configure FortiSIEM rules
- Execute attack vectors
- Describe the NIST SP 800-61 incident handling process
- Describe the incident handling workflow with FortiSIEM and FortiSOAR
- Analyze, handle, and tune incidents on FortiSIEM
- Ingest FortiSIEM incidents into FortiSOAR for incident handling
- Escalate FortiSOAR alerts into incidents
- Describe automation requirements
- Describe FortiSOAR playbook steps
- Run playbooks to enrich indicators
- Configure a playbook to retrieve a hash rating from FortiSandbox
- Perform containment on FortiGate, Windows Active Directory, and FortiClient EMS using FortiSOAR connectors
- Eradicate artifacts from a compromised host
- Release a compromised host from quarantine after recovery
- Manage playbook history logs
Pre-requisites:
This course assumes knowledge of the topics covered in the FortiSIEM Analyst course, or equivalent work experience.
Sign up for a course Security Operations Architect
The application has been successfully submitted!
Mistake!