Skip to main Content

ArcSight ESM Advanced Analyst (V)ILT with Certified Expert Exam

  • Code training ESM320-76-CE
  • Duur 5 dagen
  • Versie link.aspx

Andere trainingsmethoden

Klassikale training Prijs

eur3,750.00

(excl. BTW)

Vraag een groepstraining aan Schrijf je in

Methode

Deze training is in de volgende formats beschikbaar:

  • Klassikale training

    Klassikaal leren

Vraag deze training aan in een andere lesvorm.

Trainingsbeschrijving

Naar boven

This course provides you with the knowledge required to use advanced ArcSight ESM content to find and correlate event information,perform actions such as notifying stakeholders,graphically analyze event data,and report on security incidents. You will familiarize and/or reinforce your understanding of the advanced correlation capabilities within ArcSight ESM that provide a significant edge in detecting active attacks.

 

This course covers ArcSight security problem solving methodology using advanced ESM content to find,track,and re-mediate security incidents. During the training,you will use variables and correlation activities,customize report templates for dynamic content,and customize Dashboards to monitor incidents.

 

The last day of class offers a hands-on exam. Passing the exam awards you with Certified Expert badge

Doelgroep

Naar boven

This course is intended for analysts responsible for:

  • Defining their organization’s security objectives
  • Building or using advanced content to correlate,view and respond to those security

Trainingsdoelstellingen

Naar boven

Upon successful completion of this course,you should be able to:

  • Navigate ArcSight ESM console and command center to correlate,investigate,analyze
  • and remediate both exposed and obscure threats
  • Construct ArcSight variables to provide advanced analysis of the event stream
  • Develop ArcSight lists and rules to allow advanced correlation activities
  • Optimize event-based data monitors to provide real-time viewing of event traffic and
  • anomalies
  • Design new report templates and create functional reports
  • Find events through the search

Inhoud training

Naar boven

Module 1: ESM Overview

Module 2: ArcSight Command Center

Module 3: ArcSight Console

Module 4: Active Channels

Module 5: Filters

Module 6: Variable Customization

Module 7: Data Monitors and Dashboards

Module 8: ESM Lists

Module 9: ESM Rules

Module 10: Query Viewers Authoring

Module 11: ESM Reports

Module 12: Unified Event Search Tools

Voorkennis

Naar boven

To be successful in this course,you should have the following prerequisites or knowledge:

  • Common security devices such as IDS and firewalls
  • Common network device functions,such as routers,switches,and hubs
  • TCP/IP functions such as CIDR blocks,subnets,addressing,and communications
  • Basic Windows operating system tasks and functions
  • Possible attack activities,such as scans,man in the middle,sniffing,DoS,and possible abnormal activities,such as worms,Trojans,and viruses

 

  • SIEM terminology,such as threat,vulnerability,risk,asset,exposure,and safeguards
  • Completed the ArcSight ESM Administrator and Analyst course or 6 months experience administering ArcSight ESM
Cookie Control toggle icon