1
1

00:00:00,120  -->  00:00:02,640
<v ->In this section of the course, we're going to cover SIEMs</v>
2

2

00:00:02,640  -->  00:00:04,200
which are the security information
3

3

00:00:04,200  -->  00:00:06,060
and event management systems.
4

4

00:00:06,060  -->  00:00:07,500
Now we're going to continue to focus
5

5

00:00:07,500  -->  00:00:10,440
on domain one, security operations, with a focus
6

6

00:00:10,440  -->  00:00:14,250
on objectives 1.1 and 1.3 during this section.
7

7

00:00:14,250  -->  00:00:15,840
Objective 1.1 states
8

8

00:00:15,840  -->  00:00:17,520
that you must be able to explain the importance
9

9

00:00:17,520  -->  00:00:19,800
of system and network architecture concepts
10

10

00:00:19,800  -->  00:00:21,480
in security operations.
11

11

00:00:21,480  -->  00:00:24,330
And objective 1.3 states that given a scenario,
12

12

00:00:24,330  -->  00:00:25,560
you must analyze data
13

13

00:00:25,560  -->  00:00:28,140
as part of your security monitoring activities.
14

14

00:00:28,140  -->  00:00:30,060
Now in particular, we're going to be focused
15

15

00:00:30,060  -->  00:00:32,340
on security monitoring activities that are associated
16

16

00:00:32,340  -->  00:00:33,990
with SIEMs which makes sense
17

17

00:00:33,990  -->  00:00:36,540
because this is the SIEM section of the course.
18

18

00:00:36,540  -->  00:00:38,460
Now, as we begin to move through the section,
19

19

00:00:38,460  -->  00:00:40,920
we're going to start out by describing a security information
20

20

00:00:40,920  -->  00:00:43,770
and event management system or SIEM and how it's used
21

21

00:00:43,770  -->  00:00:45,660
within your network to increase your monitoring
22

22

00:00:45,660  -->  00:00:47,430
and detection capabilities.
23

23

00:00:47,430  -->  00:00:49,860
Then we're going to explore the various use cases
24

24

00:00:49,860  -->  00:00:52,320
for security data collection techniques that are available
25

25

00:00:52,320  -->  00:00:54,840
for us to use as cybersecurity analysts.
26

26

00:00:54,840  -->  00:00:56,760
Next, we're going to focus on the importance
27

27

00:00:56,760  -->  00:00:59,580
of security data normalization inside of your network
28

28

00:00:59,580  -->  00:01:02,220
before we move into our event logs and syslogs
29

29

00:01:02,220  -->  00:01:05,010
as we begin to analyze various security incidents.
30

30

00:01:05,010  -->  00:01:05,910
After that,
31

31

00:01:05,910  -->  00:01:08,280
I'm going to be performing another hands-on demonstration
32

32

00:01:08,280  -->  00:01:09,930
and this time I'm going to be showing you
33

33

00:01:09,930  -->  00:01:12,090
how to configure a SIEM agent to collect data
34

34

00:01:12,090  -->  00:01:13,260
from across your network
35

35

00:01:13,260  -->  00:01:15,600
and bring it back into a central repository.
36

36

00:01:15,600  -->  00:01:17,640
Remember, a SIEM is an essential part
37

37

00:01:17,640  -->  00:01:20,490
of detecting malicious activity inside of your networks
38

38

00:01:20,490  -->  00:01:22,530
so you won't want to miss this section of the course.
39

39

00:01:22,530  -->  00:01:24,660
It is really, really important.
40

40

00:01:24,660  -->  00:01:26,670
Now finally, we're going to take a short quiz
41

41

00:01:26,670  -->  00:01:28,680
to see what you learned during this section of the course
42

42

00:01:28,680  -->  00:01:30,720
and review each of those quiz questions fully
43

43

00:01:30,720  -->  00:01:33,210
to ensure you can explain why the right answers were right.
44

44

00:01:33,210  -->  00:01:36,060
So let's start exploring the world of security information
45

45

00:01:36,060  -->  00:01:39,010
and event management systems in this section of the course.
