Detail kurzu
EDU260 - Cortex XDR Training Prevention, Analysis and Response (EDU260) |Virtual course|In English|
EDU Trainings s.r.o.
Popis kurzu
The Palo Alto Networks Cortex XDR: Prevention, Analysis, and Response (EDU-260) course for advanced endpoint protection and remediation is an instructor-led training that will help you to:
- Differentiate the architecture and components of the Cortex XDR family
- Activate XDR, deploy the agents, and work with the management console
- Work with the management console, describe a typical management page and work with the tables and filters
- Create agent installation packages, endpoint groups, policies, and profiles
- Create and manage exploit and malware profiles, and perform response actions
- Differentiate BIOC and IOC rules, and create and manage them
- Describe the Cortex XDR causality analysis and analytics concepts
- Triage and investigate alerts and incidents, and create alert starring and exclusion policies
- Work with the Causality and Timeline Views and investigate threats in the Query Center
- Enable the Host Insights add-on and work with the insights and the Asset View
- Use Vulnerability Assessment, and work with the Asset Management and the IP View
The Cortex XDR course teaches students how the agent protects against exploits and malware-driven attacks. In hands-on lab exercises, students will explore and configure the management platform and install XDR agent as well as relevant components; create security policies and profiles to protect endpoints against multi-stage, fileless attacks built using malware and exploits; respond to attacks using response actions; understand behavioural threat analysis, log stitching, agent-provided enhanced endpoint data, and causality analysis; investigate and triage attacks using the incident management page and analyze alerts using the Causality and Timeline analysis views; use API to insert alerts; create BIOC rules, and search a lead in raw data sets in Cortex Data Lake using the Query Builder
Obsah kurzu
- Cortex XDR Family Overview
- Working with the Cortex Apps
- Getting Started with Endpoint Protection
- Malware Protection
- Exploit Protection
- Exceptions and Response Actions
- Behavioral Threat Analysis
- Cortex XDR Rules
- Incident Management
- Alert Analysis Views
- Search and Investigate
- Basic Troubleshooting
Cieľová skupina
Cybersecurity Analysts and Engineers
Security Operations Specialists
Hodnotenie
Organizátor
Podobné kurzy
podľa názvu a lokality