Résumé du cours
This one-day course teaches you how to configure and scope the rules within VMware Carbon Black® App ControlTM product to maintain the system according to your organization’s security posture and organizational policies. Additionally, this course covers troubleshooting both the server and the agent for Carbon Black App Control and how to identify issues that impact normal operations. This course provides an in-depth, technical understanding of the Carbon Black App Control product through comprehensive coursework and hands-on scenario-based labs.
Product Alignment
- VMware Carbon Black App Control
Moyens d'évaluation :
- Évaluations formatives pendant la formation, à travers les travaux pratiques réalisés sur les labs à l’issue de chaque module
- Évaluation sous forme de questionnaire à l’issue de la formation
A qui s'adresse cette formation
System administrators and security operations personnel, including analysts and managers
Pré-requis
This course requires completion of one following course:
Objectifs
By the end of the course, you should be able to meet the following objectives:
- Manage and configure the Carbon Black App Control sever based on organizational requirements
- Implement rules to support business processes and automatic approvals
- Identify scenarios and use cases for Custom rules and Event rules
- Describe common troubleshooting scenarios for the Carbon Black App Control server
- Describe common troubleshooting scenarios for the Carbon Black App Control Windows agent
Contenu
Course Introduction
- Introductions and course logistics
- Course objectives
Custom Rules Basics
- Execute / Write action rules
- Precedence
- Paths
Custom Rules Best Practices
- Rule Triad
- Rule multiplication
Rule Types
- Custom rule type overview
Optimizing Custom Rules
- Evaluating events
Event Rules
- Creating and editing
- Testing before implementing
Troubleshooting Considerations
- Server versus agent issues
Server Capabilities
- Tools, logs, common issues, scenarios
Agent Capabilities
- Tools, logs, common issues, scenarios
Moyens Pédagogiques :