|
via Udemy |
Go to Course: https://www.udemy.com/course/ibm-qradar-certified-administratoranalyst/
This intermediate level certification is intended for security analysts who wish to validate their comprehensive knowledge of IBM Security QRadar SIEM V7.4.3+.These security analysts will understand basic networking, basic IT security, SIEM and QRadar concepts. They will also understand how to log in to, navigate within, and explain capabilities of the product using the graphical user interface. Additionally, they will also be able to identify causes of offenses, and access, interpret, and report security information in a QRadar deployment.Recommended SkillsPrerequisite KnowledgeKnowledge and foundational skills one must possess before acquiring skills measured on the certification test. These foundational skills are NOT measured on the test.Knowledge of SIEM conceptsKnowledge of TCP/IP NetworkingKnowledge of IT Security conceptsGeneral IT skills (browser navigation etc...)Knowledge of Internet security attack types, including but not limited to the MITRE ATT & CK FrameworkAdditional features that need additional licenses including but not limited to QRadar Network Insights, QRadar Incident ForensicsKey Areas of CompetencyOffense and log analysisUnderstanding reference dataRule and building block understandingSearching and reporting, regular and adhoc reportsUnderstanding basic QRadar tuning and network hierarchyBasic concepts of multi-domain QRadar instancesDetails:Triage initial offenseAnalyze fully matched and partially matched rulesAnalyze an offense and associated IP addressesRecognize MITRE threat groups and actorsPerform offense managementDescribe the use of the magnitude of an offenseIdentify events not correctly parsed and their source (Stored events)Outline simple offense naming mechanismsCreate customized searchesInterpret rules that test for regular expressionsCreate and manage reference sets and populate them with dataInstall QRadar Content Packs using the QRadar Assistant AppAnalyze rules that use Event and Flow dataAnalyze Building Blocks: Host definition, category definition, Port definitionReview and recommend updates to the network hierarchyReview and recommend updates to building blocks and rulesDescribe the different types of rules, including behavioral, anomaly and threshold rulesInvestigate Event and Flow parametersPerform AQL querySearch & filter logs by specific log source typeConfigure a search to utilize time seriesAnalyze potential IoCsBreak down triggered rules to identify the reason for the offenseRecommend changes to tune QRadar SIEM after offense analysis identifies issuesDistinguish potential threats from probable false positivesAdd a reference set based filter in log analysisInvestigate the payload for additional details on the offenseRecommend adding new custom properties based on payload dataPerform "right-click Investigations" on offense dataUse the default QRadar dashboard to create, view, and maintain a dashboard based on common searchesUse Pulse to create, view, and maintain a dashboard based on common searchesPerform an advanced searchExplain the different uses for each search typeFilter search resultsBuild threat reportsPerform a quick searchView the most commonly triggered rulesReport events correlated in the offenseExport Search results in CSV or XMLCreate reports and advanced reports out of offensesShare reports with usersSearch using indexed and non-indexed propertiesCreate and generate scheduled and manual reports