Cisco Certified CyberOps Associate (200-201) Cert Prep: 3 Host-Based Analysis
1h 40mIntermediate2024-12-09
Authors

Lisa Bock
Security ambassador with a broad range of IT skills and knowledge
Course details
Cybersecurity specialists and related occupations are in high demand. In this course, instructor Lisa Bock helps you prepare for the host-based analysis portion of the Cisco CyberOps exam. Lisa begins by summarizing key components in a Windows OS. She then walks you through the architecture, file system, and registry, along with ways you can interact with netstat to monitor active processes. Lisa reviews basics on how to monitor the Linux OS, either while working in the shell or a GUI. She describes the importance of having a solid grasp of the network architecture and reinforces how to achieve defense in depth to monitor and protect all endpoints. Lisa then covers the elements of an IPS/IDS log entry, along with ways to examine your network security data. She summarizes methods to generate a malware analysis report. Finally, Lisa explains how to respond effectively to a cybersecurity incident while preserving the chain of custody after an attack.
Skills covered
Software AdministrationNetwork SecurityServer AdministrationIncident ResponseNetwork AdministrationCybersecurityCert PrepNetwork and System Administration
Concepts
0. Introduction
- 01 - Securing the endpoints
- 02 - Set up your test environment
1. Outlining the Window OS
- 03 - Visualize the Windows architecture
- 04 - Dissect the Windows file system
- 05 - Working with Windows Registry
- 06 - Running a Windows OS
- 07 - Manage network settings
- 08 - Use netstat
- 09 - Monitor the Windows OS
2. Discovering the Linux OS
- 10 - Recognize the value of a Linux OS
- 11 - Interact with a Linux OS
- 12 - Use the Linux file system
- 13 - Monitor log files
- 14 - Avoid malware on a Linux host
- 15 - Harden the OS
3. Monitoring the Endpoints
- 16 - Outline the network architecture
- 17 - Provide defense in depth
- 18 - Simple Network Management Protocol
- 19 - Understand NTP
- 20 - Challenge - Configure NTP
- 21 - Solution - Configure NTP
4. Examining Network Security Data
- 22 - Understand data types used in security monitoring
- 23 - Challenge - Configure SNMP
- 24 - Solution - Configure SNMP
- 25 - Generate a malware analysis report
- 26 - Compare HIDS with NIDS
- 27 - Use a sandbox to evaluate malicious activity
5. Responding to Cybersecurity Incidents
- 28 - Cyber attribution
- 29 - Outline the digital forensic investigation
- 30 - Compare different types of evidence
- 31 - Preserve the chain of custody
Conclusion
- 32 - Next steps