IBM QRadar is a leader in SIEM solution according to the Gartner Magic Quadrant. In this course, Incident Detection and Investigation with QRadar, you will explore the QRadar main features from a SOC Analyst perspective. First, you will explore what SIEM is and how QRadar provides more functions than a regular SIEM. Next, you will walk through all relevant functionalities provided by the tool and some extra functions, such as risk manager and vulnerability manager. Finally, with the SIEM basics covered, you will dive into incident investigation using QRadar, where you will learn about events, flows, and offences. When you have completed this course, you'll have a foundational knowledge of QRadar incident and detection and skills related to the certification IBM C2150-612 (IBM Security QRadar SIEM V7.2.6 Associate Analyst). Moreover, you will have a full understanding of how to investigate the most common cyber threats using IBM QRadar.
Learning Objectives
- Data Collection
- Events
- Flows
- Offenses
- Rules
- Assets
- Reports
- Dashboards
Framework Connections
The materials within this course focus on the NICE Framework Task, Knowledge, and Skill statements identified within the indicated NICE Framework component(s):
Specialty Areas
- Cyber Defense Analysis
- Cyber Defense Infrastructure Support
- Incident Response
Feedback
If you would like to provide feedback on this course, please e-mail the NICCS team at NICCS@mail.cisa.dhs.gov. Please keep in mind that NICCS does not own this course or accept payment for course entry. If you have questions related to the details of this course, such as cost, prerequisites, how to register, etc., please contact the course training provider directly. You can find course training provider contact information by following the link that says “Visit course page for more information...” on this page.