GB
/
GBP
/
EN

Shaping the future of IT skills

Maximising IT performance through learning

Cortex XDR 2.0: Prevention, Analysis, and Response - EDU-260

WGAC-PAN-260

Palo Alto Networks

Description

Show Tabs
Introduction

Successful completion of this instructor-led course with hands-on lab activities should enhance the student’s understanding of how to activate a Cortex XDR instance; create agent installation packages to install the Cortex XDR agents; create security policies and profiles to protect endpoints against multi-stage, fileless attacks built using malware and exploits; respond to attacks using response actions;understand behavioral threat analysis, log stitching, agent-provided enhanced endpoint data, and causality analysis; investigate and triage attacks using the incident management page of Cortex XDR and analyze alerts using the Causality and
timeline analysis views; use API to insert alerts; create BIOC rules; and search a lead in raw data sets in Cortex Data Lake using Cortex XDR Query Builder.


Target Audience


Cybersecurity analysts and engineers, and security operations specialists

Prerequisites & Audience

Participants must be familiar with enterprise security concepts.

Course Benefits

This course is three days of instructor-led training that will help you to:

 Differentiate the architecture and components of the Cortex XDR family

 Describe Cortex, Cortex Data Lake, the Customer Support Portal, and the hub

 Activate Cortex XDR, deploy the agents, and work with the management console

 Work with the Cortex XDR management console, describe a typical management page, and work with the tables and filters

 Create Cortex XDR agent installation packages, endpoint groups, policies, and profiles

 Create and manage exploit and malware profiles, and perform response actions

 Describe detection challenges with behavioral threats

 Differentiate the Cortex XDR rules BIOC and IOC, and create and manage them

 Describe the Cortex XDR causality analysis and analytics concepts

 Triage and investigate alerts and incidents, and create alert starring and exclusion policies

 Work with the Causality and Timeline Views and investigate threats in the Query Center

Course Topics

Course Modules

1. Cortex XDR Family Overview

2. Working with the Cortex Apps

3. Getting Started with Endpoint Protection

4. Malware Protection

5. Exploit Protection

6. Exceptions and Response Actions

7. Behavioral Threat Analysis

8. Cortex XDR Rules

9. Incident Management

10. Alert Analysis Views

11. Search and Investigate

12. Basic Troubleshooting

Palo Alto Networks courses


Firewall 10.1: Troubleshooting - EDU-330
CODE: WGAC-PAN-330
Prisma Access SASE Security : Design and Operation - EDU-318
CODE: WGAC-PAN-318
Cortex XDR 2.0: Prevention, Analysis, and Response - EDU-260
CODE: WGAC-PAN-260
Panorama 10.1: Managing Firewalls at Scale - EDU-220
CODE: WGAC-PAN-220
Firewall 10.1: Improving Security Posture and Hardening PANOS Firewalls - EDU-214
CODE: WGAC-PAN-214
Firewall 10.1 Essentials: Configuration and Management - EDU-210
CODE: WGAC-PAN-210
MSSP PLATFORM 10.0 – CONFIGURE AND ADMINISTER - EDU-255
CODE: WGAC-PAN-255
Advanced Workshop on Palo Alto Networks: VPN - Routing - Global Protect
CODE: WGAC-PAN-AWKS-101
Cortex XSOAR 6.2: Automation and Orchestration - EDU-380
CODE: WGAC-PAN-380
We use cookies to understand how you use our site and to improve your experience. To learn more, click here. Read our revised Privacy Policy and Terms and Conditions.