Section 1: Understanding Risk Management and SOC Operations
- Governance, Risk, and Compliance
- Security Regulatory Requirements
- Security Policy
- Protected Information
- Risk Analysis and Insurance
- SOC Services, Operations, and Automation
- SOC Service Models
Section 2: Understanding Analytical Processes and Playbooks
- Security Analytics
- SOC Playbook
- SOC Automation and Workflow
- Incident Response Concepts, Metrics, and Workflow
- Documenting Security Incidents in Cases
- Security Orchestration, Automation, and Response
- Cisco XDR
- Splunk Enterprise and Phantom Overview
Section 3: Understanding Cloud Service Model Security Responsibilities
- Evolution of Cloud Computing
- Cloud Service Models
- Security Responsibilities in the laaS Service Model
- Security Responsibilities in the PaaS Service Model
- Security Responsibilities in the SaaS Service Model
- Cloud Deployment Models
- Key Security Controls in SaaS
- Cloud Access Security Broker
- Cisco Cloudlock
- Cloud Security Regulations and References
Section 4: Understanding Enterprise Environment Assets
- Asset Management
- Remediating Vulnerabilities and the SOC
- Assessing Vulnerabilities
- Patch Management
- Data Storage and Protecting Data Privacy
- Multi-Factor Authentication
- Zero Trust Model
Section 5: Understanding APIs
- API Overview
- CSV, HTML, and XML Data Encoding
- JSON Data Encoding
- YAML Data Serialization Standard
- HTTP-Based APIs
- RESTful APIs vs. Non-RESTful APIs
- Cisco pxGrid
- HTTP-Based Authentication
- Postman
- NETCONF
- Data Modeling with YANG
- RESTCONF
- Google RPC
- STIX and TAXII Specifications
- Role of APIs in Cisco Security Solutions
- Python Fundamentals
- Python Virtual Elements
Section 6: Understanding SOC Development and Deployment Models
- Agile Methodology
- DevOps Practices and Principles
- Components of a CI/CD Pipeline
- Essential Windows and Linux CLI for Development and Operations
- Infrastructure as Code
- SOC Platform Development, Engineering, Operation, and Maintenance
Section 7: Investigating Packet Captures, Logs, and Traffic Analysis
- Identity Access Management Logs
- Artifacts and Traffic Streams in a Packet Capture
- Nextgen Firewall and IPS Logs
- Dissecting Suspicious Requests
- Network Traffic Analysis Using NetFlow Analytics
- Detecting and Enforcing DLP On-the-Wire
- Cisco AMP Architecture
- Cisco Web Security Appliance
- Network DNS Logs
- Cisco Email Security Appliance
- Email Security Logs (Not Detection-Based)
- Cisco Umbrella
Section 8: Investigating Endpoint and Appliance Logs
- Cisco ISE Monitoring, Reporting, and Alerting
- Cisco Advanced Malware Protection
- Cisco Threat Grid
- Endpoint Logs from Non-Detection Sources
- Server DNS Logs
- Internet of Things
- Web Security Logs
- Endpoint Data Loss Prevention
Section 9: Implementing Threat Tuning
- Security Tuning Governance Policy
- Tuning Security Controls Rules, Filters, and Policies
- Determining If a Rule Is Defective
- Anatomy of a Snort Rule
- Troubleshooting Detection Rules
- Recommending Scenarios for Tuning
Section 10: Threat Research and Threat Intelligence Practices
- Cyber Threat Intelligence Overview
- Cyber Threat Intelligence Lifecycle
- Cyber Threat Intelligence Data Sources
- Indicators of Compromise and Indicators of Attack
- Security Intelligence Reports
- Cyber Attribution
- Cyber Threat Intelligence Tools
- Security Intelligence in a TIP Platform
- Using Indicator Analysis to Reveal Hidden Infections
Section 11: Performing Security Analytics and Reports in a SOC
- Security Data and Log Analytic Techniques
- Security Data Management Users
- Security Data with Log Management and Retention
- Security Data and Log Aggregations
- Security Information and Event Management
- Security Data and Log Analytics Automation
- Dashboards and Reports
Section 12: Malware Forensics Basics
- Malware Detection Tools
- Static Malware Analysis from Detection Tools
- Dynamic Malware Analysis from Sandbox Logs
- File Fingerprinting for Attribution
- Evading Detection
- File Forensics
Section 13: Threat Hunting Basics
- Proactive Threat Hunting Concepts
- Using MITRE ATTACK@ Framework for Threat Hunting
- Using CAPEC to Hunt for Weaknesses in Applications
- Evaluating Security Posture and Gaps in Controls Using MITRE ATTACK®
- Threat Hunting Case Study
Section 14: Performing Incident Investigation and Response
- Threat Modeling
- Attack Campaigns, Tactics, Techniques, and Procedures
- Steps to Investigate Potential Data Loss