About Course
Course Objectives:
Understand the role and functions of a Security Operations Center (SOC).
-
Monitor and analyze network traffic and host-based data to detect threats.
-
Apply basic cryptography and endpoint security technologies.
-
Identify and investigate malicious activity, common attack vectors, and suspicious behavior patterns.
-
Conduct security incident investigations using SOC processes and playbooks.
-
Understand incident response, workflow automation, and SOC metrics.
-
Gain practical experience with Cisco Packet Tracer and real equipment.
-
Prepare for the Cisco Certified CyberOps Associate (CBROPS) certification exam (200-201).
Course Outlines:
-
Defining the Security Operations Center (SOC)
-
Network Infrastructure and Network Security Monitoring Tools
-
Data Type Categories and Basic Cryptography Concepts
-
Common TCP/IP Attacks and Endpoint Security Technologies
-
Incident Analysis in a Threat-Centric SOC
-
Resources for Hunting Cyber Threats
-
Event Correlation and Normalization
-
Identifying Attack Vectors, Malicious Activity, and Suspicious Patterns
-
Conducting Security Incident Investigations
-
Using Playbooks for Security Monitoring
-
SOC Metrics, Workflow, and Automation
-
Incident Response and Use of VERIS
-
Windows and Linux Operating System Basics
