CRISC 2023: SIEM & SOAR

placeholder

Security information and event management (SIEM) solutions serve as centralized data ingestion and analysis engines that seek out potential security issues. Security incident response can be partially or fully automated using security orchestration automation and response (SOAR) solutions.

In this course discover the benefits of SIEM and SOAR security incident monitoring and response solutions. Next learn how to deploy the Splunk SIEM on Linux. Then you will configure a Splunk universal forwarder. Finally you will use various tools like Wireshark to capture and analyze industrial control system (ICS) network traffic.

This course can be used to prepare for the ISACA Certified in Risk and Information Systems Control (CRISC) certification.