IBM Security QRadar SIEM 7.1 Foundations (BQ100)
Request a Quote for this class
About this Course
QRadar SIEM provides deep visibility into network, user, and application activity. It provides collection, normalization, correlation, and secure storage of events, flows, assets, topologies, and vulnerabilities. Suspected attacks and policy breaches are highlighted as offenses. In this course, you learn how to navigate QRadar SIEM to detect anomalies and unusual behavior. Using the skills taught in this course, you can identify and investigate threats and attacks. Hands-on exercises reinforce the skills learned.
Audience Profile
This basic course is for:
- Security Analysts
- Network Administrators
- System Administrators
At Course Completion
Students will be able to:
- Navigating the QRadar SIEM user interface
- Analyzing network activity
- Analyzing log activity
- Discovering servers
- Determining and assessing vulnerabilities
- Investigating offenses
- Creating rules
- Tuning offenses
- Reporting
Prerequisites
You should have the following skills:
- TCP/IP networking
- Familiarity with logfiles and events
- IT security fundamentals
Course Outline
-
Unit 1: Introduction
-
Unit 2: Network Security
-
Unit 3: Dashboard
-
Unit 4: Log Activity
-
Unit 5: Network Activity
-
Unit 6: Advanced Filtering
-
Unit 7: Asset and Vulnerability Assessment
-
Unit 8: Offenses
-
Unit 9: Offense Investigation
-
Unit 10: Rules
-
Unit 11: Tuning
-
Unit 12: Reporting
-
Unit 13: Customer Support