Instructor

VMware Carbon Black EDR Advanced Administrator Training Course

Curriculum

Master threat hunting & incident response with VMware Carbon Black EDR Advanced Administrator Training. Gain hands-on expertise & industry-recognized certification.

Ratings

( 4.2 Ratings )

Live Online Classes starting on 01 January, 1970

VMware Carbon Black EDR Advanced Administrator

The VMware Carbon Black EDR Advanced Administrator course is an in-depth training program designed for IT professionals who aim to master the administration of the VMware Carbon Black EDR platform. This course provides a comprehensive overview of the Architecture, server datastores, API integration, Threat intelligence feeds, syslog integration, and Troubleshooting techniques.Starting with course logistics and objectives, participants will understand what to expect and what they will achieve. The Architecture module delves into data flows, sizing, and communication channels, ensuring the system is scaled and secured appropriately. Server datastores cover the maintenance of critical databases and storage configurations. Through the EDR API lessons, learners will gain proficiency in automating and integrating with the EDR platform.Learners will also explore Threat intelligence feeds, understanding how to enhance security with custom feeds. Syslog integration is crucial for centralizing alerts and integrating with SIEM systems. Finally, the troubleshooting module equips administrators with the skills to diagnose and resolve issues efficiently.By the end of this course, learners will be adept at managing and optimizing the VMware Carbon Black EDR environment, contributing to their organization's cybersecurity resilience.

 

Course Objectives

By the end of the course, you should be able to:

  • Describe the components and capabilities of the Carbon Black EDR server.

  • Identify the architecture and data flows for Carbon Black EDR communication.

  • Identify the architecture for a cluster configuration and Carbon Black EDR cluster communication.

  • Describe the Carbon Black EDR server data types and data locations.

  • Use the API to interact with the Carbon Black EDR server without using the UI.

  • Create custom threat feeds for use in the Carbon Black EDR server.

  • Perform integration with a syslog server.

  • Use different server-side scripts for troubleshooting.

  • Troubleshoot sensor-side configurations and communication.

 

Who Can Benefit

  • System administrators.

  • Security operations personnel.

  • Analysts.

  • Managers.

 

Prerequisites

This course requires completion of the following:

  • VMware Carbon Black EDR Administrator.

 

Course Outline:

1. Course Introduction

  • Introductions and course logistics

  • Overview of course objectives

2. Architecture

  • Understanding data flows and channels within the EDR framework

  • Considering sizing requirements for optimal performance

  • Identifying communication channels and ports used by the system

3. Server Datastores

  • Overview of the SOLR database and its role in EDR

  • Configuring storage settings and managing data aging

  • Exploring partition states for effective data management

  • Introduction to Postgres and its significance in the architecture

  • Understanding the Modulestore and its functionalities

4. EDR API

  • Overview of CBAPI (Carbon Black API) for interaction with EDR

  • Learning how to view API calls directly in the browser

  • Utilizing the API to access and manipulate data effectively

5. Threat Intelligence Feeds

  • Understanding the structure of threat intelligence feeds

  • Identifying report indicator types for better analysis

  • Creating and adding custom threat feeds to enhance detection capabilities

6. Syslog Integration

  • Exploring SIEM (Security Information and Event Management) support for EDR

  • Configuring syslog integration for effective data collection and analysis

7. Troubleshooting

  • Utilizing server-side scripts for diagnosing issues

  • Analyzing server logs for troubleshooting insights

  • Understanding sensor operations to ensure optimal performance

(4.2 Ratings)

Download Course Contents

Still unsure?
We're just a click away


Course Outline PDF

SpireTec Unique Features

course-img
1-On-1 Training

Benefit from our 1-On-1 Training for personalized, focused, and effective learning experiences.

course-img
Customized Training

Experience our Customized Training service tailored to meet your specific learning needs and goals

course-img
4 - Hours / Weekend Session

Join our Class featuring 4 - Hours / Weekend Session for in-depth learning and expert training.

course-img
Free Demo Class

Join our Free Demo Class to experience top-notch training and expert guidance first hand!

Purchase This Course

Request More Information

CERTIFICATE

Get Ahead With SpireTec Solutions
Training Certificate

Earn your Certificate

Our course is exhaustive and this certificate is proof that you have taken a big leap in mastering the domain.

Differentiate yourself with Masters Certificate

Our course is exhaustive and this certificate is proof that you have taken a big leap in mastering the domain.

Share your achievement

Our course is exhaustive and this certificate is proof that you have taken a big leap in mastering the domain.

Need Customized Curriculum?

Our course is exhaustive and this certificate is proof that you have taken a big leap in mastering the domain.

Talk To Adviser
course-certificate

Top Certifications