title
Please take a moment to fill out this form. We will get back to you as soon as possible.
All fields marked with an asterisk (*) are mandatory.
QRadar EDR: Foundations
Course Description
Overview
In this course, you learn about the IBM Security® QRadar® EDR architecture and how to position the product within your company's landscape of security solutions. You gain skills around how to install the QRadar EDR Hive on your premises and the EDR Agents on your endpoints. You can review the user interface and how to navigate the EDR Dashboard while investigating endpoint threats.
This course applies to version 3.12 of the on-premises QRadar EDR offering.
Objectives
In this course, you learn to perform the following tasks:
- Navigate the QRadar EDR Dashboard
- Describe the QRadar EDR architecture
- Install the on-premises QRadar EDR Hive and configure the initial setup
- Deploy the QRadar EDR Agent on your endpoints
- Investigate threats on endpoints
- Manage endpoints
- Understand and respond to alerts and trends
- Act upon behavioral malware and ransomware attacks
- Configure notifications and Simple Mail Transfer Protocol
- Set up forwarding alerts
- Define policies
- Handle downloaded and quarantined files from your endpoints
- Set up users, groups, and clients
- Configure Hive-Cloud Score
- Create applications
- Monitor audit logs
Audience
Security operations center (SOC) AdministratorSOC AnalystSecurity AnalystIncident ResponderManaged Service Security Provider (MSSP)
Topics
Getting started
- Dashboard overview
- Architecture
- QRadar EDR on-prem installation
- Downloading, installing, and updating the QRadar EDR Agent
Protecting your endpoints
- Investigating threats on endpoints
- Managing endpoints
- Understanding and responding to alerts and trends
- Acting upon behavioral malware and ransomware attacks
- Hunting for threats on your endpoint using a QRadar EDR lab
Administering your environment
- Configuring notifications and Simple Mail Transfer Protocol (SMTP)
- Setting up forwarding alerts
- Defining policies
- Handling downloaded and quarantined files from your endpoints
- Setting up users, groups, and clients
- Configuring Hive-Cloud Score
- Creating applications
- Monitoring audit logs
Related Courses
-
IBM Security QRadar v7.4.3 Deployment Professional
BQ650GW- Duration: 3.5 Hours
- Delivery Format: Self-Paced Training (WBT)
- Price: 155.00 USD
-
QRadar SIEM: Gathering Threat Management Data (v7.5)
BQ310GS- Duration: 4 Hours
- Delivery Format: Self-Paced Training
- Price: 441.00 USD
Self-Paced Training Info
Learn at your own pace with anytime, anywhere training
- Same in-demand topics as instructor-led public and private classes.
- Standalone learning or supplemental reinforcement.
- e-Learning content varies by course and technology.
- View the Self-Paced version of this outline and what is included in the SPVC course.
- Learn more about e-Learning
Course Added To Shopping Cart
bla
bla
bla
bla
bla
bla
Self-Paced Training Terms & Conditions
Exam Terms & Conditions
Sorry, there are no classes that meet your criteria.
Please contact us to schedule a class.
STOP! Before You Leave
Save 0% on this course!
Take advantage of our online-only offer & save 0% on any course !
Promo Code skip0 will be applied to your registration
Purchase Information
title
Please take a moment to fill out this form. We will get back to you as soon as possible.
All fields marked with an asterisk (*) are mandatory.