Scheda corso MARS

Implementing Cisco SecurityMonitoring : Analysis and Response System

Questo è un corso ufficiale Cisco ed è quindi tenuto da istruttori certificati Cisco CCSI (Certified Cisco Systems Instructor) che garantiscono la qualità della docenza in conformità ai requisiti tecnici e didattici definiti da Cisco. Il partecipante riceverà materiali didattici ufficiali Cisco e l’accesso ai laboratori remoti approvati da Cisco necessari al completamento delle esercitazioni previste dal percorso didattico ufficiale.
 
Cisco Security Mitigation and Response System (CS MARS) è una famiglia di applicazioni scalabili e di high performance per la gestione e la mitigazione delle minacce che mette in grado i clienti di utilizzare più efficacemente di strumenti di rete e di sicurezza combinando network intelligence, context correlation, vector analysis, anomaly detection, hotspot identification e automatismi di mitigazione.
 
    • Engineers who support sales of Cisco security product solutions
    • Cisco channel partners and customers who sell, implement, and maintain secure networks
 

Obiettivi

    • Describe the Cisco Security MARS solution, features, and functions in relation to the issues of security incidents and security information in an enterprise network
    • Explain the task flows that you should follow when you deploy Cisco Security MARS as an STM system in your network
    • Cover the basic physical installation process of Cisco Security MARS software and hardware appliances and navigate the web-based administrator console
    • Add Cisco security and network devices into the Cisco Security MARS appliance
    • Add security and network devices from other vendors into the Cisco Security MARS appliance
    • Discuss NetFlow and the DTM features of the Cisco Security MARS appliance
    • Provide an overview of log parser templates
    • Use the management features in the Cisco Security MARS appliance to assign event, addressing, service, and user informationConfigure hardware maintenance tasks such as viewing the audit trail, data archiving, hot swapping hard drives, and upgrading software on Cisco Security MARS appliance
    • Describe the Cisco Security MARS user interface and Summary page to get an overview of the network
    • Describe the case management features that can capture, combine, and preserve user-selected Cisco Security MARS data within a specialized report called a case
    • Configure security devices to generate interesting events that constitute an attack scenario and have Cisco Security MARS collect the interesting events for incident investigation
    • Discuss attack mitigation and false-positive confirmation in the context of the Cisco Security MARS appliance
    • Configure the Cisco Security MARS appliance to perform incident investigation and attack mitigation
    • Explain how to create, view and save a long-duration query and reports on the Cisco Security MARS appliance
    • Configure the Cisco Security MARS appliance to send an alert
    • Describe and configure a rule (or rules) that detect interesting patterns of network activity and other anomalous network behaviorProvide an overview of Cisco Security MARS Global Controller
 

Prerequisiti

Contenuti

Cisco, the Cisco Logo, Cisco Systems, CCNA, CCSP are trademarks or registered trademarks of Cisco Systems, Inc. and/or its affiliates in the United States and certain other countries.
Education Time is sponsored by a Cisco Learning Solutions Partner.

© 2009 Education Time S.p.A. | P.Iva 05352330962 | Note Legali | Privacy | Realizzato da Education Time