FortiSIEM Analyst (FORT-SIEM)

 

Course Overview

In this course, you will learn how to use FortiSIEM to search, enrich, and analyze events from customers in a managed security service provider (MSSP) organization. You will learn how to perform real-time and historical searches, and build advanced queries. You will also learn how to perform analysis and remediation of security incidents.

This exam is part of the FCSS Security Operations certification track.

This training is provided by our partner Fortinet.

Important notes for the booking of trainings directly provided by Fortinet

If you are unable to attend the training date you have booked (e.g. illness, etc.) or if Fortinet cancels the course, a credit note is not possible under any circumstances. In both cases of cancellation, the validity of your credit remains for 12 months after the order.

For more information, please refer to the Fortinet Terms and Conditions.

Who should attend

Security professionals responsible for the detection, analysis, and remediation of security incidents using FortiSIEM should attend this course.

Certifications

This course is part of the following Certifications:

Prerequisites

You must have an understanding of the topics covered in the following courses, or have equivalent experience.

  • FCF - FortiGate Fundamentals
  • FortiSIEM Administrator

Course Objectives

After completing this course, you should be able to:

  • Describe how FortiSIEM solves common cybersecurity challenges
  • Describe the main components and the unique database architecture on FortiSIEM
  • Perform real-time and historical searches
  • Define structured search operators and search conditions
  • Reference the CMDB data in structured searches
  • Add display fields and columns
  • Build queries from search results and events
  • Build nested queries and lookup tables
  • Build rule subpatterns and conditions
  • Identify critical interfaces and processes
  • Create rules using baselines
  • Analyze a profile report
  • Analyze anomalies against baselines
  • Analyze the different incident dashboard views
  • Refine and tune incidents
  • Clear an incident
  • Export an incident report
  • Create time-based and pattern-based clear conditions
  • Configure automation policies
  • Configure remediation scripts and actions
  • Differentiate between manual and automatic remediation
  • Configure notifications

Prices & Delivery methods

Online Training

Duration
2 days

Price
  • on request
Classroom Training

Duration
2 days

Price
  • on request
 

Schedule

Instructor-led Online Training:   Course conducted online in a virtual classroom.

English

European Time Zones

Online Training Course language: English
Online Training Course language: English

6 hours difference to Central European Time (CET)

Online Training Time zone: Central Daylight Time (CDT) Course language: English
Online Training Time zone: Eastern Daylight Time (EDT) Course language: English