|
Prerequisites
The knowledge and skills
that a learner must have before attending
this course include the following:
 |
Certification
as a Cisco CCNA or the equivalent knowledge |
 |
Be a CCSP™
or have attained the Cisco Firewall
Specialist, Cisco IDS Specialist, and
Cisco VPN Specialist certifications |
 |
At least six months
practical experience configuring Cisco
IDS Sensors |
 |
Competency in using
the Microsoft Windows operating system |
 |
Familiarity with
implementing network security policies
and with perimeter security system components:
perimeter router, firewall, bastion
host/servers and hosts |
Course Content
Securing Hosts Using
Cisco Security Agent (HIPS) 2.0 is a
two-day, leader-led, lab-intensive course. This task-oriented course teaches
the knowledge and skills needed to configure
and deploy the Cisco Security Agent Management
Center (CSA MC) and Cisco Security Agent
(CSA).
Course Objectives
After completing this course the student
should be able to:
 |
Identify
the platforms and infrastructure that
support CSA and the CSA MC |
 |
Describe the CSA
architecture and the CSA MC |
 |
Configure the way
CSA protects a host system |
 |
Install CSA with
a default Agent kit |
 |
Create host groups
and build Agent kits |
 |
Define application
classes and associate them with the
appropriate security policies |
 |
Use variables for
granular control when creating rules |
 |
Configure security
policies and rules |
 |
Configure system
correlation rules for CSA |
 |
Identify which rules
are for Windows, UNIX, and both platforms |
 |
Perform data analysis
and create policies with CSA Analysis |
 |
Manage the Event
Log and generate reports |
Course Outline
| Lesson
1 |
Security
Fundamentals |
| Lesson
2 |
Cisco
Security Agent Overview |
| Lesson3 |
Cisco Security Agent Quick Start Installation |
| Lesson
4 |
Cisco
Security Agent Management Center Administration |
| Lesson
5 |
Configuring
Groups and Managing Hosts |
| Lesson
6 |
Building
Policies |
| Lesson
7 |
Rule
Basics |
| Lesson
8 |
System
Correlation Rules |
| Lesson
9 |
Defining
Application Classes |
| Lesson10 |
Working
with Variables |
| Lesson
11 |
Using
Cisco Security Agent Analysis |
| Lesson
12 |
Using
Event Logs and Generating Reports |
Recommended Schedule
The above schedule is suggested
for the course. The instructor may make
adjustments to the course based on the attendees.
It is suggested that you study all topics
because they are designed to reinforce the
lesson concepts and ensure that you apply
some of the concepts.
Who Should Attend
|