This course is given on these dates and locations:
Date
Location
Delivery type
September 27, 2010
Regina
Instructor-Led Training
September 27, 2010
Winnipeg
Instructor-Led Training
October 12, 2010
Calgary
Instructor-Led Training
October 12, 2010
Edmonton
Instructor-Led Training
December 06, 2010
Toronto
Instructor-Led Training
December 06, 2010
Ottawa
Instructor-Led Training
This course is part of the Cisco Security Management Suite which provides security monitoring for network security devices and host applications made by Cisco or non-Cisco providers. Areas of study include event correlation, data reduction features, topology awareness, and automatic mitigation features. Network topology knowledge allows for determination of attack origin as well as application of appropriate remedy. This course is a key component in the Cisco Self Defending Network strategy. Together with CS-Manager, CS-Mars provides a unified security management solution for monitoring and provisioning. It is strongly suggested that candidates successfully complete CCNA Security prior to enrollment. This course is designed for network professionals wanting to guarantee the security of their networks.
Students attending this class should have the following:
Fundamental knowledge of implementing network security
CCNA Security
SNRS, SNAF, and IPS
Upon completion of this course, student will be able to use CS-MARS to:
monitor security and host application devices
know CS-MARS architecture and how CS-MARS processes events
run / create / customize reports
investigate an incident and mitigate security threats
archive and restore features
do customer parser for unknown devices in CS-MARS
create / customize rules that detect dark net through best practices example
tune signature / log level on device side and CS-MARS side
Implementing Cisco Security Monitoring, Analysis, and Response System (MARS)
Introducing Cisco Security Monitoring, Analysis, and Response System
Understanding the System Architecture
Configuring a Cisco Security MARS Appliance
Adding Reporting and Mitigation Devices
Viewing the Summary Page
Managing Rules
Understanding Queries and Reports
Investigating and Mitigating Incidents
Working with User-Defined Log Parser Templates
Integrating with Cisco Security Manager
Managing and Administering the System
Troubleshooting and Optimizing Cisco Security MARS
Using the Cisco Security MARS Global Controller
Course Review