Default Site Title
ccna-banner-image

Fortinet Certified Professional in Security Operations (FCP in security operations)

In this course, you will gain knowledge on the initial configuration of FortiSIEM, its architecture, and the process of discovering devices on the network. You will also learn how to gather performanc

Fortinet Certified Professional in Security Operations (FCP in Security Operations)

In this course, you will gain knowledge on the initial configuration of FortiSIEM, its architecture, and the process of discovering devices on the network. You will also learn how to gather performance data and combine it with syslog information to enhance the overall monitoring of your environment's health. 

Course

Outline Elective Course:

SKU: NSE-EX-FTE2

1.FortiGate Administrator

2.FortiAnalyzer Analyst

3.FortiSIEM

4.FortiSOAR Administrator

5.FortiEDR

FortiSIEM

In this course, you will gain knowledge on the initial conguration of FortiSIEM, its architecture, and the process of discovering devices on the network. You will also learn how to gather performance data and combine it with syslog information to enhance the overall monitoring of your environment's health. Additionally, the course will cover the use of the conguration database to simplify compliance audits and how to integrate FortiSIEM into your network awareness infrastructure.

Objectives

  • Identify business drivers for using SIEM tools
  • Understand SIEM and PAM (Privileged Access Management) concepts
  • Describe key features of FortiSIEM
  • Learn how collectors, workers, and supervisors collaborate in SIEM architecture
  • Congure and manage noti cations in FortiSIEM
  • Create new users and de ne custom roles in FortiSIEM
  • Enable and congure devices for discovery in FortiSIEM
  • Understand when to deploy and use agents in FortiSIEM
  • Perform real-time and historical structured searches
  • Group and aggregate search results for analysis
  • Analyze performance metrics within FortiSIEM
  • Create custom incident rules for speci c monitoring needs
  • Edit existing reports or create new custom reports
  • Congure and personalize dashboards for enhanced visibility
  • Export Conguration Management Database (CMDB) information
  • Identify key components of Windows agents
  • Understand the purpose and function of Windows agents in FortiSIEM
  • Learn how the Windows agent manager operates in di erent deployment models
  • Identify reports related to Windows agents in FortiSIEM
  • Understand the functionality of FortiSIEM's Linux le monitoring agent
  • Understand agent registration processes in FortiSIEM
  • Monitor agent communication post-deployment
  • Troubleshoot and resolve FortiSIEM issues e ectively
  • Target Audience

Target Audience

  • This course is designed for individuals responsible for the day-to-day management of FortiSIEM.
  • Ideal for those managing and overseeing FortiSIEM operations on a daily basis.

Prerequisites

  • FCP - FortiGate Security
  • FCP - FortiGate Infrastructure

Course Syllabus

1.Introduction

2.SIEM and PAM Concepts

3.Discovery and FortiSIEM Agents

4.FortiSIEM Analytics

5.CMDB Lookups and Filters

6.Group By and Data Aggregation

7.Rules and MITRE ATT&CK

8.Incidents and Noti cation Policies

9.Reports and Dashboards

10.Maintaining and Tuning

11.Troubleshooting


Related Courses

experts-banner-background

EMIGO Expert Training Team

new-batch-mage

New Batches Commence On

Testimonials

enquiry-section1-bg
enquiry-form-model1

Learn like a Leader
Not a follower

Scan or Click on the QR Code to submit your enquiry

Enquiry
enquiry-section1-qrcode
footer-enquiry footer-enquiry