FortiSIEM Analyst (FORT-SIEM)

 

Course Overview

In this course, you will learn how to use FortiSIEM to search, enrich, and analyze events from customers in a managed security service provider (MSSP) organization. You will learn how to perform real-time and historical searches, and build advanced queries. You will also learn how to perform analysis and remediation of security incidents using traditional and machine learning (ML)assisted methods.

This exam is part of the FCSS Security Operations certification track.

Who should attend

Security professionals responsible for the detection, analysis, and remediation of security incidents using FortiSIEM should attend this course.

Certifications

This course is part of the following Certifications:

Prerequisites

You must have an understanding of the topics covered in the following courses, or have equivalent experience:

Course Objectives

After completing this course, you should be able to:

  • Describe how FortiSIEM solves common cybersecurity challenges
  • Describe the main components and the unique database architecture on FortiSIEM
  • Perform real-time and historical searches
  • Define structured search operators and search conditions
  • Reference the CMDB data in structured searches
  • Configure display fields and columns
  • Build queries from search results and events
  • Build nested queries and lookup tables
  • Build rule subpatterns and conditions
  • Manage and tune incidents
  • Resolve an incident
  • Create time-based and pattern-based clear conditions
  • Configure automation policies
  • Create rules using baselines
  • Analyze anomalies against baselines
  • Describe the threat hunting workflow
  • Analyze threat hunting dashboards
  • Describe FortiSIEM ML modes and algorithms
  • Describe how to train an ML model perform an analysis using a ML model
  • Describe the benefits of deploying FortiSIEM UEBA
  • Configure tags, rules, and incidents using UEBA data
  • Describe how ZTNA tags affect the FortiSIEM incident and remediation process
  • Configure a ZTNA tag using FortiSIEM to remediate incidents
  • Generate and export a report
  • Create a custom dashboard

Outline: FortiSIEM Analyst (FORT-SIEM)

  • 1. Introduction to FortiSIEM
  • 2. Analytics
  • 3. Nested Queries and Lookup Tables
  • 4. Rules and Subpatterns
  • 5. Incidents
  • 6. Clear Conditions and Remediation
  • 7. Threat Hunting
  • 8. Performance Metrics and Baselines
  • 9. Machine Learning
  • 10. User and Entity Behavior Analytics
  • 11. FortiSIEM ZTNA
  • 12. Reports and Dashboards

Prices & Delivery methods

Online Training

Duration
3 days

Price
  • US $ 2,900
Classroom Training

Duration
3 days

Price
  • United States: US $ 2,900

Click on town name or "Online Training" to book Schedule

Instructor-led Online Training:   This is an Instructor-Led Online (ILO) course. These sessions are conducted via WebEx in a VoIP environment and require an Internet Connection and headset with microphone connected to your computer or laptop. If you have any questions about our online courses, feel free to contact us via phone or Email anytime.
*   This class is delivered by a vendor or third party partner.

United States

Online Training 09:00 Central Daylight Time (CDT) 2 days * Enroll
Online Training 09:00 Eastern Daylight Time (EDT) 2 days * Enroll