IBM Security QRadar SIEM FoundationsDigi Academy
Chiedi il prezzo
Domande più frequenti
You must have:
- Basic TCP/IP networking skills
- System administration knowledge
- Basic information security skills
Cosa impari in questo corso?
Target del corso
This basic course is suitable for security analysts, security technical architects, offense managers, network administrators, and system administrators.
Contenuti del corso
QRadar SIEM provides deep visibility into network, user, and application activity. It provides collection, normalization, correlation, and secure storage of events, flows, assets, and vulnerabilities. Suspected attacks and policy breaches are highlighted as offenses. In this course, you learn to navigate the user interface and how to investigate offenses. You search and analyze the information from which QRadar SIEM concluded a suspicious activity. Hands-on exercises reinforce the skills learned.
Contenuti dettagliati del corso
- Unit 1: Introduction to IBM Security QRadar SIEM
- Unit 2: How QRadar SIEM collects security data
- Unit 3: Using the QRadar SIEM Dashboard
- Unit 4: Investigating an offense that is triggered by events
- Unit 5: Investigating the events of an offense
- Unit 6: Using asset profiles to investigate offenses
- Unit 7: Investigating an offense that is triggered by flows
- Unit 8: Using rules and building blocks
- Unit 9: Creating QRadar SIEM reports
- Unit 10: Performing advanced filtering