• Online, Self-Paced
Course Description

IBM QRadar is a leader in SIEM solution according to the Gartner Magic Quadrant. In this course, Incident Detection and Investigation with QRadar, you will explore the QRadar main features from a SOC Analyst perspective. First, you will explore what SIEM is and how QRadar provides more functions than a regular SIEM. Next, you will walk through all relevant functionalities provided by the tool and some extra functions, such as risk manager and vulnerability manager. Finally, with the SIEM basics covered, you will dive into incident investigation using QRadar, where you will learn about events, flows, and offences. When you have completed this course, you'll have a foundational knowledge of QRadar incident and detection and skills related to the certification IBM C2150-612 (IBM Security QRadar SIEM V7.2.6 Associate Analyst). Moreover, you will have a full understanding of how to investigate the most common cyber threats using IBM QRadar.

Learning Objectives

  • Data Collection
  • Events
  • Flows
  • Offenses
  • Rules
  • Assets
  • Reports
  • Dashboards

Framework Connections

Feedback

If you would like to provide feedback for this course, please e-mail the NICCS SO at NICCS@hq.dhs.gov.