After doing these courses, I feel confident creating professional visualizations and dashboards
Descrierea cursului
This is the fourth of five courses in the Google Cloud Cybersecurity Certificate. In this course, you’ll focus on developing capabilities in logging, security, and alert monitoring, along with techniques for mitigating attacks. You'll gain valuable knowledge in customizing threat feeds, managing incidents, handling crisis communications, conducting root cause analysis, and mastering incident response and post-event communications. Using Google Cloud tools, you'll learn to identify indicators of compromise and prepare for business continuity and disaster recovery. Alongside these technical skills, you'll continue updating your resume and practicing interview techniques.
Cerințe prealabile
Nu există cerințe prealabile pentru acest curs
Curriculum
Structura cursului
1
Detection foundations
In this module, you’ll delve into crucial topics for detecting security activities, focusing on log retention policies, intrusion detection and prevention systems, and the intricacies of monitoring and alerts. You'll learn about incident management and attack mitigation strategies. Additionally, the section will guide you through logging fundamentals and monitoring best practices, equipping you with the knowledge to effectively manage and respond to security incidents.
- Introduction to course 450 XP
- Course 4 overview50 XP
- Seline: Make an impact in cloud security50 XP
- Helpful resources and tips50 XP
- Lab technical tips50 XP
- Explore your course 4 scenario: Cymbal Bank50 XP
- Welcome to module 150 XP
- SecOps and its components50 XP
- Essential SecOps skills50 XP
- Vulnerability management techniques50 XP
- Vulnerability scanning, penetration testing, and tabletop exercises50 XP
- AI in SecOps: Red teams50 XP
- Test your knowledge: Security operations foundations — Question 150 XP
- Test your knowledge: Security operations foundations — Question 250 XP
- Test your knowledge: Security operations foundations — Question 350 XP
- Test your knowledge: Security operations foundations — Question 450 XP
- Incident detection basics50 XP
- Phases of incident response and management50 XP
- Incident response plans50 XP
- More about incident response phases50 XP
- Intrusion detection systems50 XP
- Signature and anomaly-based detection50 XP
- Test your knowledge: Incident management foundations — Question 150 XP
- Test your knowledge: Incident management foundations — Question 250 XP
- Test your knowledge: Incident management foundations — Question 350 XP
- Test your knowledge: Incident management foundations — Question 450 XP
- Logs for analysis and monitoring50 XP
- Log types: A breakdown50 XP
- Log management: The skills needed for success50 XP
- Test your knowledge: Logging and log retention fundamentals — Question 150 XP
- Test your knowledge: Logging and log retention fundamentals — Question 250 XP
- Test your knowledge: Logging and log retention fundamentals — Question 350 XP
- Test your knowledge: Logging and log retention fundamentals — Question 450 XP
- Alerts and notifications50 XP
- Alert search techniques50 XP
- Alert and log optimization50 XP
- Guide to event threat detection50 XP
- Determine the difference between normal activity and an incident100 XP
- Test your knowledge: Alerts, notifications, and log optimization — Question 150 XP
- Test your knowledge: Alerts, notifications, and log optimization — Question 250 XP
- Test your knowledge: Alerts, notifications, and log optimization — Question 350 XP
- Test your knowledge: Alerts, notifications, and log optimization — Question 450 XP
- Wrap-up50 XP
- Glossary terms from module 150 XP
- Module 1 challenge — Question 150 XP
- Module 1 challenge — Question 250 XP
- Module 1 challenge — Question 350 XP
- Module 1 challenge — Question 450 XP
- Module 1 challenge — Question 550 XP
- Module 1 challenge — Question 650 XP
- Module 1 challenge — Question 750 XP
- Module 1 challenge — Question 850 XP
- Module 1 challenge — Question 950 XP
- Module 1 challenge — Question 1050 XP
2
Detection in practice
In this module, you’ll delve into the intrusion kill chain, false positive analysis, and threat hunting techniques through the lens of incident management and attack mitigation. You’ll also learn how to create detection rules, use query tools to analyze logs and identify indicators of compromise (IoC).
3
Incident response management and attack mitigation
In this module, you'll explore the entire incident response process. Additionally, you’ll gain essential skills in documenting information for various stakeholders, defining and conducting post-mortem analyses, and developing and executing automated playbooks. By the end of this course, you'll have a comprehensive understanding of the importance of automation in SecOps and be equipped with the necessary tools and knowledge to thrive in your chosen cloud security role.
4
Incident recovery
In this module, you'll acquire a thorough understanding of disaster recovery planning and business continuity in the Google Cloud environment, ensuring data integrity and maintaining operations during a disaster, focusing on swift response strategies. This module will also guide you through the role of automation in detecting and responding to cyberattacks, the use of the business continuity and disaster recovery (BCDR) tool, and the criticality of recovery as a last resort.
R
Detect, Respond, and Recover from Cloud Cybersecurity Attacks
Curs
finalizat

