Skip Navigation
image Running Womanimage Peopleimage Monitors

train | consult | mentor

View all courses

SECUR202: Integrated Threat Defense Investigation and Mitigation (SECUR202)

The Integrated Threat Defense Investigation and Mitigation (SECUR202) version 1.0 Cisco®
Training on Demand course is a self-paced, lab-based, hands-on course offered by Learning@Cisco.

In this course, you learn to identify, isolate, and mitigate network threats using the Cisco Integrated Threat Defense solution platforms. This course is the second in a pair of courses covering the Cisco Integrated Threat Defense solution. This course teaches you the concepts of network threat investigation and reinforces learning through a series of lab scenarios designed to identify relationships between the Cisco products and the stages of the attack lifecycle.


Course Objectives

After completing this course the student should be able to:

● Describe the stages of the network attack lifecycle and identify ITD solution platform placement based on a given stage
● Detail how to locate and mitigate email malware attacks
● Describe email phishing attacks and the steps taken to locate and mitigate them on the network
● Identify and mitigate data exfiltration threats on the network
● Identify malware threats on the network and mitigate those threats after investigation

Course Content

● Module 1: Network Threat Investigation Introduction
● Module 2: Investigation and Mitigation of Email Malware Threats
● Module 3: Investigation and Mitigation of Email Phishing Threats
● Module 4: Investigation and Mitigation of Data Exfiltration Threats
● Module 5: Investigation and Mitigation of Malware Threats

Lab Outline:

● Lab 1: Connecting to the Lab Environment
● Lab 2: Threat Scenario 1: Email Malware Attachments
● Lab 3: Threat Scenario 2: Email-Based Phishing
● Lab 4: Threat Scenario 3: Targeted Network Server Threats and Data Exfiltration
● Lab 5: Threat Scenario 4: Endpoint Malware Investigation and Mitigation

Target Audience

This course is designed for technical professionals who need to know how to use a deployed Integrated Threat Defense (ITD) network solution to identify, isolate, and mitigate network threats.

Course Duration

On Demand 1 day

Suggested Pre-requisites

The knowledge and skills that a student must have before attending this course are as follows:

The knowledge and skills necessary before attending this course are:

● Technical understanding of TCP/IP networking and network architecture
● Technical understanding of security concepts and protocols
● Familiarity with Cisco Identity Services Engine, Cisco Stealthwatch® , Cisco Firepower® , and Cisco Advanced Malware Protection (AMP) for Endpoints is an advantage

Need a quote or have a question about this class?

ask us here

Subscribe to Course Updates