Detection and Response with XDR: Integrated Security Solutions to Combat Emerging Threats
3h 50mIntermediate2025-01-30
Authors

Pearson

Katherine McNamara

Steven McNutt

Matt Vander Horst
Course details
Modern security operations face a rapidly evolving threat landscape, making it difficult to gain complete visibility across an array of disparate security tools. Extended detection and response, also known as XDR, can help to bridge that gap by centralizing telemetry, intelligence, and response capabilities from a variety of sources into a single security platform. In this course, join instructors Matt Vander Horst, Steven McNutt, and Katherine McNamara as they explore why XDR is such a game-changer for reducing your detection and response times and optimizing your overall security operations. Along the way, discover practical strategies for implementing XDR within your organization. An ideal fit for cybersecurity professionals, regardless of your technical background or level of experience, this course is designed to equip you with the skills you need to successfully design, implement, and automate threat responses using cutting-edge XDR technology.
Learning objectives
Identify modern cybersecurity threats and vulnerabilities.
Understand how XDR enhances visibility across products and technologies.
Utilize XDR's investigation features to detect and manage breaches.
Leverage automation to isolate and remediate threats swiftly.
Learning objectives
Identify modern cybersecurity threats and vulnerabilities.
Understand how XDR enhances visibility across products and technologies.
Utilize XDR's investigation features to detect and manage breaches.
Leverage automation to isolate and remediate threats swiftly.
Skills covered
Governance, Risk, and ComplianceIncident ResponseCybersecurityOne-Off
Concepts
0. Introduction
- 01 - Detection and response with XDR - Introduction
1. The Modern Security Operations Center
- 02 - Module 1 - Security operations and tooling introduction
- 03 - Learning objectives
- 04 - Describe the goals of the SOC
- 05 - Describe SOC organization
- 06 - Describe SOC roles and responsibilities
- 07 - Describe SOC process flow
2. Security Operations Concepts and Tooling
- 08 - Learning objectives
- 09 - Describe the basics of the NIST Cybersecurity Framework (CSF)
- 10 - Describe major categories of threats
- 11 - Describe major categories of controls
- 12 - Identify some popular open-source tools and their functions
3. Computer Security Incident Response Teams (CSIRT)
- 13 - Learning objectives
- 14 - Describe the goals of a CSIRT
- 15 - Appreciate the differences between a SOC and a CSIRT
4. Trends and Challenges
- 16 - Module 2 - Extended detection and response (XDR) introduction
- 17 - Learning objectives
- 18 - Describe the limitations of existing solutions
- 19 - Identify some of the top roadblocks with existing tools
- 20 - Describe the limitations with SIEMs
- 21 - Describe the limitations with SOARs
5. Introducing XDR
- 22 - Learning objectives
- 23 - Describe the basics of XDR
- 24 - Describe the goals of XDR
- 25 - Describe Cisco's secure approach to XDR
- 26 - Identify the components of XDR
- 27 - Appreciate XDR's differences from a SIEM and SOAR
- 28 - Describe XDR's real-world outcomes
6. XDR's Integrated Security Stack
- 29 - Learning objectives
- 30 - Identify the goals of an integrated security stack
- 31 - Appreciate XDR's native and third-party compatibility
- 32 - Describe XDR's REST APIs
- 33 - Describe XDR's detection analytics
- 34 - Describe XDR's remediation capabilities
- 35 - Describe XDR's orchestration and automation capabilities
- 36 - Describe an effective XDR solution
7. Threat Hunting
- 37 - Module 3 - XDR with Cisco introduction
- 38 - Learning objectives
- 39 - Describe the PICERL model
- 40 - Describe the MITRE Framework
- 41 - Describe adversary tactics, techniques, and procedures (TTPs)
- 42 - Identify the tools and techniques for threat hunting
8. Investigating an Incident
- 43 - Learning objectives
- 44 - Describe an incident in XDR
- 45 - Describe incident priority and MITRE tactics
- 46 - Identify the components of an incident
- 47 - Interact with Cisco XDR's attack graph
- 48 - Identify correlating data using XDR
9. Responding to an Incident
- 49 - Learning objectives
- 50 - Appreciate the value of Cisco XDR integrations for response
- 51 - Describe how XDR can respond to an incident
- 52 - Understand incident response playbooks
10. What Is Security Automation
- 53 - Module 4 - Security automation introduction
- 54 - Learning objectives
- 55 - Describe the advantages of security automation
- 56 - Describe the roles of AI and machine learning
11. How Does Automation Fit into XDR
- 57 - Learning objectives
- 58 - Understand threat hunting and alert investigation
- 59 - Describe response actions
12. Cisco XDR Automation
- 60 - Learning objectives
- 61 - Describe XDR automation and its usage
- 62 - Explain automation components
- 63 - Explore the workflow editor
- 64 - Explain a workflow run and troubleshooting
Conclusion
- 65 - Detection and response with XDR - Summary