Performing CyberOps Using Cisco Security Technologies (CBRCOR)

CCNP CyberOps Cisco Security Technologies CBRCOR

Earn your Cisco Certified CyberOps Professional certification.

Learn core cyber security operations including cyber security fundamentals, techniques, processes, and automation.

Use automation for security using cloud platforms and a SecDevOps methodology.

Learn the techniques for detecting cyberattacks, analyzing threats, and making appropriate recommendations to improve cybersecurity.

Course Overivew

  • The Performing CyberOps Using Cisco Security Technologies (CBRCOR) v1.0 course covers cybersecurity operations fundamentals, methods, and automation.
  • The knowledge you gain in this course will prepare you for the role of Information Security Analyst on a Security Operations Center (SOC) team.
  • You will learn foundational concepts and their application in real-world scenarios, and how to leverage playbooks in formulating an Incident Response (IR).
  • The course shows you how to use automation for security using cloud platforms and a SecDevOps methodology.
  • You will learn the techniques for detecting cyberattacks, analyzing threats, and making appropriate recommendations to improve cybersecurity.
  • Expand your knowledge in the following areas:
  • Monitoring for cyberattacks
  • Analyzing high volume of data using automation tools and platforms—both open source and commercial
  • Accurately identifying the nature of attack and formulate a mitigation plan
  • Scenario-based questions; for example, using a screenshot of output from a tool, you may be asked to interpret portions of output and establish conclusions
Read More
Read Less
Course Benefits:

Module 1: Fundamentals

 

  • Interpret the components within a playbook
  • Determine the tools needed based on a playbook scenario
  • Apply the playbook for a common scenario (for example, unauthorized elevation of privilege, DoS and DDoS, website defacement)
  • Infer the industry for various compliance standards (for example, PCI, FISMA, FedRAMP, SOC, SOX, PCI, GDPR, Data Privacy, and ISO 27101)
  • Describe the concepts and limitations of cyber risk insurance
  • Analyze elements of a risk analysis (combination asset, vulnerability, and threat)
  • Apply the incident response workflow
  • Describe characteristics and areas of improvement using common incident response metrics
  • Describe types of cloud environments (for example, IaaS platform)
  • Compare security operations considerations of cloud platforms (for example, IaaS, PaaS)

 

Module 2: Techniques

  • Recommend data analytic techniques to meet specific needs or answer specific questions
  • Describe the use of hardening machine images for deployment
  • Describe the process of evaluating the security posture of an asset
  • Evaluate the security controls of an environment, diagnose gaps, and recommend improvement
  • Determine resources for industry standards and recommendations for hardening of systems
  • Determine patching recommendations, given a scenario
  • Recommend services to disable, given a scenario
  • Apply segmentation to a network
  • Utilize network controls for network hardening
  • Determine SecDevOps recommendations (implications)
  • Describe use and concepts related to using a Threat Intelligence Platform (TIP) to automate intelligence
  • Apply threat intelligence using tools
  • Apply the concepts of data loss, data leakage, data in motion, data in use, and data at rest based on common standards
  • Describe the different mechanisms to detect and enforce data loss prevention techniques
  • Recommend tuning or adapting devices and software across rules, filters, and policies
  • Describe the concepts of security data management
  • Describe use and concepts of tools for security data analytics
  • Recommend workflow from the described issue through escalation and the automation needed for resolution
  • Apply dashboard data to communicate with technical, leadership, or executive stakeholders
  • Analyze anomalous user and entity behavior (UEBA)
  • Determine the next action based on user behavior alerts
  • Describe tools and their limitations for network analysis (for example, packet capture tools, traffic analysis tools, network log analysis tools)
  • Evaluate artifacts and streams in a packet capture file
  • Troubleshoot existing detection rules
  • Determine the tactics, techniques, and procedures (TTPs) from an attack

 

Module 3: Processes

  • Prioritize components in a threat model
  • Determine the steps to investigate the common types of cases
  • Apply the concepts and sequence of steps in the malware analysis process:
  • Interpret the sequence of events during an attack based on analysis of traffic patterns
  • Determine the steps to investigate potential endpoint intrusion across a variety of platform types (for example, desktop, laptop, IoT, mobile devices)
  • Determine known Indicators of Compromise (IOCs) and Indicators of Attack (IOAs), given a scenario
  • Determine IOCs in a sandbox environment (includes generating complex indicators)
  • Determine the steps to investigate potential data loss from a variety of vectors of modality (for example, cloud, endpoint, server, databases, application), given a scenario
  • Recommend the general mitigation steps to address vulnerability issues
  • Recommend the next steps for vulnerability triage and risk analysis using industry scoring systems (for example, CVSS) and other techniques

 

Module 4: Automation

  • Compare concepts, platforms, and mechanisms of orchestration and automation
  • Interpret basic scripts (for example, Python)
  • Modify a provided script to automate a security operations task
  • Recognize common data formats (for example, JSON, HTML, CSV, XML)
  • Determine opportunities for automation and orchestration
  • Determine the constraints when consuming APIs (for example, rate limited, timeouts, and payload)
  • Explain the common HTTP response codes associated with REST APIs
  • Evaluate the parts of an HTTP response (response code, headers, body)
  • Interpret API authentication mechanisms: basic, custom token, and API keys
  • Utilize Bash commands (file management, directory navigation, and environmental variables)
  • Describe components of a CI/CD pipeline
  • Apply the principles of DevOps practices
  • Describe the principles of Infrastructure as Code
  • Describe the types of service coverage within a SOC and operational responsibilities associated with each
  • Compare security operations considerations of cloud platforms
  • Describe the general methodologies of SOC platforms development, management, and automation
  • Explain asset segmentation, segregation, network segmentation, micro-segmentation, and approaches to each, as part of asset controls and protections
  • Describe Zero Trust and associated approaches, as part of asset controls and protections
  • Perform incident investigations using Security Information and Event Management (SIEM) and/or security orchestration and automation (SOAR) in the SOC
  • Use different types of core security technology platforms for security monitoring, investigation, and response
  • Describe the DevOps and SecDevOps processes
  • Explain the common data formats, for example, JavaScript Object Notation (JSON), HTML, XML, Comma-Separated Values (CSV)
  • Describe API authentication mechanisms
  • Analyze the approach and strategies of threat detection, during monitoring, investigation, and response
  • Determine known Indicators of Compromise (IOCs) and Indicators of Attack (IOAs)
  • Interpret the sequence of events during an attack based on analysis of traffic patterns
  • Describe the different security tools and their limitations for network analysis (for example, packet capture tools, traffic analysis tools, network log analysis tools)
  • Analyze anomalous user and entity behavior (UEBA)
  • Perform proactive threat hunting following best practices
  • Cybersecurity engineers and investigators
  • Incident managers
  • Incident responders
  • Network engineers
  • SOC analysts currently functioning at entry level with 2+ years of experience
Download
Course
Brochure

Prerequisites

This course is available at :

Classroom Training

Cairo
Giza
Onsite

Online Training

Virtual Interactive Instructor LED
Self-Paced Training

WHY CHOOSE CLS

Experience

We have been in the market since 1995, and we kept accumulating experience in the training business, and providing training for more than 100,000 trainees ever since, in Egypt, and the MENA region.

Premium Facilities

CLS facilities are well-equipped with strong hardware and software technologies that aid both students and trainers lead very effective smooth training programs.

Customer Support

We provide our clients with the best solutions, customized to their specific needs and goals. Our team is highly qualified to answer whatever questions you have.

Global Accredited

CLS is an authorized and accredited partner by technology leaders. This means that our training programs are of the highest quality source materials.

Up To Date

We keep tabs on every change in the market and the technology field, so our training programs will always be updated up to the World-class latest standards, and adapted to the global shape-shifting job market.

Certified Instructors

We select the best instructors, who are certified from trustworthy international vendors. They share their professional experience with the Trainees, so they can have a clear hands-on experience.

Over 200,000 Gradutes From CLS

Play Video
Amr Mostafa
An employee of the Security Department at the Ministry of Electricity

I`m attending now CEH Training with Eng Mohamed Hamdy ,CISSP Training with Eng Mohamed Gohar, I really learned a lot from him , everything here in CLS  is very satisfying including facilities .

Play Video
Lamiaa Medhat
CIO

We took a series of courses as the digital Transformation Unit of the ministry . we just finished CRISC Certification Training with DR Adel Abdel Meneim . Thank you CLS for all your efforts, we really appreciate it

Play Video
Ahmed Salah
Senior Cyber Security Engineer

Me and my colleagues are working in a government Organization, We took a no. of cyber security trainings with CLS starting with CEH and CISSP. we liked every thing the instructors, the stuff and whole environment

Play Video
Ferras Hassan
Head of the Programming Department at Bashayer Energy Company

I`m attending ASP.NET Core with MVC Training with Eng Mohamed Hesham , I really learned a lot from him , everything here in CLS  is very satisfying including facilities .Thanks you all team.

Play Video
Mohamed Ahmed Ali
Systems management specialist

Qualifying the cadres of digital transformation units in government agencies moving to the administrative capital .Thanks CLS

Play Video
Zeinab Salah
Software Developer at Bashayer Energy Company

I`m attending ASP.NET Core with MVC Training with Eng Mohamed Hesham , I really learned a lot from him , everything here in CLS  is very satisfying including facilities .Thanks you all team.

Play Video
Ibrahim Khalaf
IT Infrastructure and Security Manger

I`m attending now CRISC Training with DR Adel Abdel Meneim , I really learned a lot from him , everything here in CLS  is very satisfying including facilities , locations and the team.

Play Video
Samar Shams ElDin
Programmer at Bashayer Energy Company

I`m attending ASP.NET Core with MVC Training with Eng Mohamed Hesham , I really learned a lot from him , everything here in CLS  is very satisfying including facilities .Thanks you all team.

Student Application For

CCNP CyberOps Cisco Security Technologies CBRCOR
Full Name *
Email *
Phone *
Full Phone
Training Location *
Additional Request

Business Application For

CCNP CyberOps Cisco Security Technologies CBRCOR
Full Name *
Company Name *
Job Title *
Number of Employees
Email *
Phone *
Full Phone
Training Location *
Additional Request