Powered by Consigas
The Palo Alto Networks Cortex XDR: Prevention, Analysis, and Response (EDU-260/262) course for advanced endpoint protection and remediation is an instructor-led training that will help you to:
- Differentiate the architecture and components of the Cortex XDR family
- Activate XDR, deploy the agents, and work with the management console
- Work with the management console, describe a typical management page and work with the tables and filters
- Create agent installation packages, endpoint groups, policies, and profiles
- Create and manage exploit and malware profiles, and perform response actions
- Differentiate BIOC and IOC rules, and create and manage them
- Describe the Cortex XDR causality analysis and analytics concepts
- Triage and investigate alerts and incidents, and create alert starring and exclusion policies
- Work with the Causality and Timeline Views and investigate threats in the Query Center
- Enable the Host Insights add-on and work with the insights and the Asset View
- Use Vulnerability Assessment, and work with the Asset Management and the IP View
Objectives
Successful completion of this instructor-led course with hands-on lab activities
should enhance the student’s understanding of how to activate a Cortex XDR
instance; create agent installation packages to install the Cortex XDR agents; create
security policies and profiles to protect endpoints against multi-stage, fileless attacks
built using malware and exploits; respond to attacks using response actions;
understand behavioral threat analysis, log stitching, agent-provided enhanced
endpoint data, and causality analysis; investigate and triage attacks using the
incident management page of Cortex XDR and analyze alerts using the Causality and
Timeline analysis views; use API to insert alerts; create BIOC rules; and search a lead
in raw data sets in Cortex Data Lake using Cortex XDR Query Builder.
Target Audience
Cybersecurity analysts and engineers, and security operations specialists
Prerequisites
Participants must be familiar with enterprise security concepts.
Palo Alto Networks Education
The technical curriculum developed and authorized by Palo Alto Networks and
delivered by Palo Alto Networks Authorized Training Partners helps provide the
knowledge and expertise that prepare you to protect our digital way of life. Our
trusted certifications validate your knowledge of the Palo Alto Networks product
portfolio and your ability to help prevent successful cyberattacks and safely enable
applications
Course Modules
1. Cortex XDR Family Overview
2. Working with Cortex Apps
3. Getting Started with Endpoint Protection
4. Malware Protection
5. Exploit Protection
6. Exceptions and Response Actions
7. Basic Troubleshooting
8. Behavioral Threat Analysis
9. Cortex XDR Rules
10. Incident Management
11. Alert Analysis Views
12. Search and Investigate
13. Investigation Views
14. Host Insights
Timing
8am-12pm (Irish Time)