Palo Alto Networks : Cortex XDR 2: Prevention, Analysis, and Response (EDU-260) - LATAM

This course is three days of instructor-led training that will help you to:Differentiate the architecture and components of the Cortex XDR familyDescribe Cortex, Cortex Data Lake, the Customer Support Portal, and the hubActivate Cortex XDR, deploy the agents, and work with the management consoleWork with the Cortex XDR management console, describe a typical management page, and work with the tables and filtersCreate Cortex XDR agent installation packages, endpoint groups, policies, and profilesCreate and manage exploit and malware profiles, and perform response actionsDescribe detection challenges with behavioral threatsDifferentiate the Cortex XDR rules BIOC and IOC, and create and manage themDescribe the Cortex XDR causality analysis and analytics conceptsTriage and investigate alerts and incidents, and create alert starring and exclusion policiesWork with the Causality and Timeline Views and investigate threats in the Query Center
Participants must be familiar with enterprise security concepts.
24 Hours
Cybersecurity analysts and engineers, and security operations specialists
Successful completion of this instructor-led course with hands-on lab activities should enhance the student�s understanding of how to activate a Cortex XDR instance, create agent installation packages to install the Cortex XDR agents, create security policies and profiles to protect endpoints against multi-stage, fileless attacks built using malware and exploits, respond to attacks using response actions, understand behavioral threat analysis, log stitching, agent-provided enhanced endpoint data, and causality analysis, investigate and triage attacks using the incident management page of Cortex XDR and analyze alerts using the Causality and Timeline analysis views, use API to insert alerts, create BIOC rules, and search a lead in raw data sets in Cortex Data Lake using Cortex XDR Query Builder.

Related Scheduled Courses