About this course

Course type Premium
Course code QASOCRESP
Duration 3 Days

The Intrusion detection & Incident Response three day course is designed for security practitioners responsible for responding to security incidents, security triage, security detection, response and remediation

Prerequisites

Network Security Foundation and Security Fundamentals are essential prrequisites for this course.

Delegates will learn how to

  • Introduction to Incident Response
  • Introduction to Incident Investigation
  • Investigation Techniques
  • Incident Investigation Preparation
  • Detection & Reporting
  • Triage & Analysis
  • Essential Incident Forensics
  • Incident Containment
  • Post Incident Response

Outline

Module 1 Introduction to Incident Response

  • Security incident response principles
  • Understand the commercial impact of a security incident
  • Incident response plans
  • Computer incident response team (CIRT)

Module 2 Introduction to Incident Investigation

  • Incident investigation techniques
  • Security responders – key skills
  • First responder people vs process
  • Business continuity trade offs

Module 3 Investigation Techniques

  • Detection & reporting
  • Triage & analysis
  • Containment
  • Post incident response

Module 4 Incident Investigation Preparation

  • Policies
  • Communication standards
  • Open source & threat intelligence
  • Proactive response measures

Module 5 Detection & Reporting

  • Detect techniques
  • Deter techniques
  • Defend techniques
  • Reporting

Module 6 Triage & Analysis

  • Security assessment techniques
  • Network security assessments
  • Network security analysis
  • Evidential impact of a security assessment

Module 7 Essential Incident Forensics

  • Chain of custody
  • Legal principles and responsibilities
  • Forensic artefacts
  • Forensic analysis

Module 8 Incident Containment

  • Describe the purpose of incident containment
  • Challenges of incident containment
  • Supply chain security
  • Testing containment solutions


Module 9 Post Incident Response

  • Internal communications
  • External communications
  • Reporting requirements
  • Reporting forensic findings
Premium Course

3 Days

Duration

This course is authored by QA

Delivery Method

Delivery method

Classroom / Attend from Anywhere

Receive classroom training at one of our nationwide training centres, or attend remotely via web access from anywhere.

Trusted, awarded and accredited

Fully accredited to ensure we provide the highest possible standards in learning

All third party trademark rights acknowledged.