TRENDS delivers Symantec courses in partnership with Red Education.

Symantec Security Analytics 7.2.x Administrator + Professional

Schedule

Start End Duration Location Details

Course Details

Symantec Security Analytics 7.2.x Administrator + Professional

Duration: 4 Days

Course Code: SSAAP

SYMANTEC SECURITY ANALYTICS 7.2.x ADMINISTRATOR

Prerequisites: 

 Participants should be familiar with network administration in distributed, enterprise-class LAN/WAN topologies, including basic Unix/Linux administration and have some experience with using proxies, firewalls, routers, and switches to implement network-security policies. Basic to advanced knowledge of best practices for incident response and continuous monitoring is a plus.

Course Description:

The Symantec Security Analytics Administrator course is intended for IT professionals who want to master the fundamentals of the Symantec Security Analytics solution. 

Course Objectives: 

•    Install, preconfigure, and license new instances of Security Analytics 
•    Identify and evaluate reference scenarios and deployment options based on organizational needs, network configurations, and storage capacity 
•    Select network locations for data capture and describe the potential implications 
•    Explain the options for, limitations of, and differences among the use of taps, mirror/SPAN ports, and virtual infrastructure for capturing packet data 
•    Identify the options and requirements for load distribution and the capabilities, benefits, and limitations of load?distributed configurations 
•    Identify hardware specifications and requirements for physical appliances and storage modules, including the correct identification of the cabling requirements for connecting storage modules to 2G and 10G appliances 
•    Navigate the GUI, identify the main functional areas of the GUI, and understand how tokens in the path bar, time?frame values, and other factors determine the information displayed 
•    Create custom dashboards and widgets 
•    Use the path bar to filter out noise and narrow your focus on relevant data 

Intended Audience:

 IT network or security professionals who wish to master the fundamentals of Symantec + Blue Coat products, with a focus on network security, and who may have not taken any previous Symantec and Blue Coat training courses.     

Course Outlines:

 •    Security Analytics Product Introduction 
•    Solution Design 
•    Installation and Setup 
•    Security Analytics Web-based User Interface 
•    Reports – What Do They Tell Me? 
•    Using the Filter Bar 
•    Using Advanced Filters 
•    Indicators 
•    Management, Monitoring, and Maintenance 

SYMANTEC SECURITY ANALYTICS 7.2.x PROFESSIONAL

Prerequisites: 

Participants should have a sound understanding of the OSI reference model and common networking protocols, and how those protocols make connections, keep state, and transfer data, along with basic experience with network packet and flow analysis, including the use of PCAP files, tcpdump, and Wireshark. Basic to advanced knowledge of best practices for incident response and continuous monitoring will provide a significant advantage.

Course Description:

The Symantec Security Analytics Professional course is designed for participants who want to learn how to use the Symantec Security Analytics platform to perform virtually any type of network-based monitoring and forensic analysis, including incident-response investigation, real-time situational awareness, and continuous monitoring for indicators of compromise (IOCs) and advanced persistent threats (APTs).

Course Objectives: 

•    Map high-level operational functions to internal system modules and identify how data flows through the system 
•    Use reports and extractions to find and analyze relevant data to solve problems 

•    Use comparisons and advanced display filters to narrow search results 
•    Import/export PCAPs for forensic analysis and archival functions 
•    Use actions, alerts, and real-time extractor 
•    Use the Security Analytics platform for incident-response 
•    Apply kill-chain analysis to discover and describe indicators of compromise 
•    Navigate and query the virtual file system 

Intended Audience:

IT or network security professionals who want to master the use of Blue Coat Security Analytics and who have completed the Symantec Security Analytics Administrator course.

Course Outlines:

•    How Security Analysis Works 
•    File and Artifact Extraction 
•    Anomaly Detection and Modeling 
•    Data Enrichment 
•    Threat Intelligence Services 
•    Kill Chain Analysis 
•    Indicators of Compromise (IOCs) 
•    Malware Integration 
•    The Virtual Filesystem (VFS)