• Online, Self-Paced
Course Description

IBM QRadar is a leader in SIEM solution according to the Gartner Magic Quadrant. In this course, Incident Detection and Investigation with QRadar, you will explore the QRadar main features from a SOC Analyst perspective. First, you will explore what SIEM is and how QRadar provides more functions than a regular SIEM. Next, you will walk through all relevant functionalities provided by the tool and some extra functions, such as risk manager and vulnerability manager. Finally, with the SIEM basics covered, you will dive into incident investigation using QRadar, where you will learn about events, flows, and offences. When you have completed this course, you'll have a foundational knowledge of QRadar incident and detection and skills related to the certification IBM C2150-612 (IBM Security QRadar SIEM V7.2.6 Associate Analyst). Moreover, you will have a full understanding of how to investigate the most common cyber threats using IBM QRadar.

Learning Objectives

  • Data Collection
  • Events
  • Flows
  • Offenses
  • Rules
  • Assets
  • Reports
  • Dashboards

Framework Connections

The materials within this course focus on the NICE Framework Task, Knowledge, and Skill statements identified within the indicated NICE Framework component(s):

Specialty Areas

  • Cyber Defense Analysis
  • Cyber Defense Infrastructure Support
  • Incident Response

Specialty Areas have been removed from the NICE Framework. With the recent release of the new NICE Framework data, updates to courses are underway. Until this course can be updated, this historical information is provided to give better context as to how it can help you with your cybersecurity goals.