1
1

00:00:00,330  -->  00:00:01,680
<v ->In this section of the course,</v>
2

2

00:00:01,680  -->  00:00:03,900
we're going to cover appliance monitoring.
3

3

00:00:03,900  -->  00:00:06,450
Now our focus in this section is going to continue to be
4

4

00:00:06,450  -->  00:00:08,790
on domain one, security operations,
5

5

00:00:08,790  -->  00:00:13,050
but this time we'll be focusing on objectives 1.1 and 1.3.
6

6

00:00:13,050  -->  00:00:15,300
Objective 1.1 states that you must be able
7

7

00:00:15,300  -->  00:00:16,860
to explain the importance of system
8

8

00:00:16,860  -->  00:00:20,400
and network architecture concepts in security operations.
9

9

00:00:20,400  -->  00:00:22,650
For this objective, we are really going to be focused
10

10

00:00:22,650  -->  00:00:24,870
on log ingestion and your ability to read
11

11

00:00:24,870  -->  00:00:27,270
and analyze a log to identify a given threat
12

12

00:00:27,270  -->  00:00:29,100
against the system or network.
13

13

00:00:29,100  -->  00:00:31,920
Objective, 1.3 states that, given a scenario,
14

14

00:00:31,920  -->  00:00:33,330
you must use appropriate tools
15

15

00:00:33,330  -->  00:00:35,940
or techniques to determine malicious activity.
16

16

00:00:35,940  -->  00:00:37,980
Again, here we are really going to be focused
17

17

00:00:37,980  -->  00:00:39,090
on the log analysis
18

18

00:00:39,090  -->  00:00:41,640
and correlation portions of this objective.
19

19

00:00:41,640  -->  00:00:43,950
Now, as we move through this section, we're going to start
20

20

00:00:43,950  -->  00:00:47,010
with reviewing firewall logs and their configurations.
21

21

00:00:47,010  -->  00:00:49,950
Then we're going to move into proxy logs and a specialized type
22

22

00:00:49,950  -->  00:00:53,160
of firewall called a web application firewall.
23

23

00:00:53,160  -->  00:00:54,990
Next, we're going to explore the configuration
24

24

00:00:54,990  -->  00:00:57,630
of IDS and IPS devices and how to conduct
25

25

00:00:57,630  -->  00:00:59,820
log reviews on those devices.
26

26

00:00:59,820  -->  00:01:02,460
After that, we're going to take a look at port security
27

27

00:01:02,460  -->  00:01:04,950
and the configuration of network access control
28

28

00:01:04,950  -->  00:01:07,290
known as NAC or NAC.
29

29

00:01:07,290  -->  00:01:09,960
Then we're going to move into a hands-on demonstration
30

30

00:01:09,960  -->  00:01:11,520
that shows you how to analyze output
31

31

00:01:11,520  -->  00:01:14,010
from some security appliance logs just like you would
32

32

00:01:14,010  -->  00:01:16,680
in the real world as a cybersecurity analyst.
33

33

00:01:16,680  -->  00:01:18,630
Finally, we're going to take a short quiz to see
34

34

00:01:18,630  -->  00:01:20,430
what you learned during this section of the course
35

35

00:01:20,430  -->  00:01:22,410
and review each of those quiz questions fully
36

36

00:01:22,410  -->  00:01:24,600
to ensure you know why the right answers were right.
37

37

00:01:24,600  -->  00:01:27,120
So let's start exploring the world of appliance monitoring
38

38

00:01:27,120  -->  00:01:29,523
and log analysis in this section of the course.
