Cisco Stealthwatch for Security Operations Training (SSO)
|Commitment||2 days, 7-8 hours a day.|
|How To Pass||Pass all graded assignments to complete the course.|
|User Ratings||Average User Rating 4.8 See what learners said|
|Delivery Options||Instructor-Led Onsite, Online, and Classroom Live|
Cisco Stealthwatch for Security Operations Training (SSO) Course – Hands-on
Cisco Stealthwatch for Security Operations Training (SSO) is a 2-day, instructor-led, lab-based, hands-on course that focuses on using Cisco Stealthwatch Enterprise from the perspective of a security analyst. The overarching goal of the course is to use the Stealthwatch System to investigate potential security issues and make initial determinations on whether to proceed with a more thorough investigation or to move on to the next potential threat.
Cisco Stealthwatch for Security Operations Training (SSO) Course – Customize it
- We can adapt this training course to your group’s background and work requirements at little to no added cost.
- If you are familiar with some aspects of this training course, we can omit or shorten their discussion.
- We can adjust the emphasis placed on the various topics or build the training around the mix of technologies of interest to you (including technologies other than those included in this outline).
- If your background is nontechnical, we can exclude the more technical topics, include the topics that may be of special interest to you (e.g., as a manager or policy-maker), and present the training course in manner understandable to lay audiences.
Cisco Stealthwatch for Security Operations Training (SSO) Course – Audience/Target Group
- This course is intended for individuals who are responsible for using Stealthwatch to monitor security policy, provide feedback on the configuration and initiate incident response investigations.
Cisco Stealthwatch for Security Operations Training (SSO) Course – Class Prerequisites
The knowledge and skills that a learner must have before attending this training course are:
- Flow Basics
- Cisco Stealthwatch Overview and Components
- Cisco Stealthwatch SMC Client Interface Overview
- Cisco Stealthwatch Web App Overview
Cisco Stealthwatch for Security Operations Training (SSO) Course – Objectives:
Upon completing this training course, learners will be able to meet these objectives:
- Explain what Cisco Stealtwatch is and how it works.
- Explain how hosts and host groups are defined in Cisco Stealthwtch.
- Define basic concepts of policy management.
- Identify the three phases of the Cisco Stealthwatch tuning process.
- Complete workflows to identify indicators of compromise in your network.
Cisco Stealthwatch for Security Operations Training (SSO) – Course Content
Module 1: Stealthwatch
- Cisco Stealthwatch Security Overview
- Introduction to Security
Module 2: Stealthwatch in the Proactive Mode
- Using Stealthwatch in the Proactive Mode
- Pattern Recognition
- Investigation and Detection Using Stealthwatch
Module 3: Stealthwatch in the Operational Mode
- Using Stealthwatch in the Operational Mode
- Alarms and Alarm Response
- Host Identification
Module 4: Summary
- Culminating Scenario: Using Stealthwatch for Insider Threats
- Putting Together an Incident Response Process
- Example Workflow for Incident Response
- Security Best Practices in Stealthwatch
- Using Top Reports and Flow Tables for Detection
- Creating and Using Dashboards for Detection
- Creating Custom Security Events
- Responding to Alarms
- Proactive Investigation Practice
- Using Maps for Incident Response
- Identify Hosts Using Host Snapshot and Host Report