top of page

Proofpoint
Threat Protection Analyst

Durée

3 jours

(21 heures)

Prix public

sur demande

Lieu

Présentiel / distanciel

Résumé

The Proofpoint Threat Protection Analyst recommended learning course builds expertise in utilizing Proofpoint's comprehensive suite, including Targeted Account Protection, Threat Response Auto Pull, and Email Protection to skillfully manage incident response, from initial detection and analysis to post-incident activities.
With a strong emphasis on practical application, this course will utilize Proofpoint's products to secure organizations against the most sophisticated threats.

This course provides hands-on experience focusing on Threat Protection Analyst skillsets, along with a classroom lab environment for configuring these services and features. This course is the foundation for many Proofpoint technologies in the cybersecurity space.

Public visé

Messaging and Security Administrators

​​

Contenu

​​

Incident Response Foundations: In this lesson, you will learn:

  • Threat Protection components, including Email Protection, TAP, TRAP, CTR, and NPRE

  • The Incident Response Life Cycle and why following accepted guidelines is good for your organization

  • The responsibilities of an incident responder based on the NIST SP800-61 r2 Computer Security Incident Handling Guidelines

 

The Preparation Phase: In this lesson, you will learn:

  • Development of a security infrastructure

  • Roles and responsibilities of an incident responder

  • Incident response procedures and run books

  • How to investigate event logging locations and identify escalation paths

  • Various incident response tools used by analysts to monitor security events

  • How changes to threat landscapes impact analysts
     


Detection and Analysis: In this lesson, you will learn how to:

  • Identify system or communications issues that may affect your ability to detect suspicious activity

  • Identify activity and alerts that indicate common use cases for information protection 

  • Use the Analytics application to identify significant activity and determine the triage order of alerts and activity

  • Determine if activity meets your organization’s definition of risky behavior

  • Determine if an alert is an active risk or already resolved

  • Identify trends in false positive alerts that may be preventable with changes to the environment or monitoring rules

  • Use Analytics’ workflow tools to track the status, owner, escalation, and timeline of alerts


Containment, Eradication, and Recovery: In this lesson, you will learn how to:

  • Prepare incident reports and show the trends over time

  • Make recommendations regarding the installation, configuration, and maintenance of security tools

  • Present a completed incident report detailing the activity and alerts associated with incidents, including the timeline, users, devices, and tactics involved

  • Present recommendations on ways to avoid future events

Post-Incident Activity: In this lesson, you will learn how to:

  • Preserve evidence related to an information protection incident and build a timeline for the after-event writeup

  • Review alert or activity trends that may help prevent the incident in the future

  • Suggest changes to rules, dictionaries, or policies to improve the platform’s efficiency

  • Generate reports on Endpoint DLP and Cloud DLP activity


This course and related exam are based on the NIST SP800-61 r2 Computer Security Incident Handling Guidelines. This information should be transferable to other guidelines such as SANS Incident Response or ISO 27001 and 270035.
 

Livrable remis au stagiaire

  • Certificat de réalisation.

  • Support de formation.

Moyens Pédagogiques

  • Quiz pré-formation de vérification des connaissances (si applicable)

  • Réalisation de la formation par un formateur agréé par l’éditeur

  • Formation réalisable en présentiel ou en distanciel

  • Mise à disposition de labs distants/plateforme de lab pour chacun des participants (si applicable à la formation)

  • Distribution de supports de cours officiels en langue anglaise pour chacun des participants

    • Il est nécessaire d'avoir une connaissance de l'anglais technique écrit pour la compréhension des supports de cours

Moyens d'évaluation

  • Quiz pré-formation de vérification des connaissances (si applicable)

  • Évaluations formatives pendant la formation, à travers les travaux pratiques réalisés sur les labs à l’issue de chaque module, QCM, mises en situation…

  • Complétion par chaque participant d’un questionnaire et/ou questionnaire de positionnement en amont et à l’issue de la formation pour validation de l’acquisition des compétences

Délai d’accès 

Se référer aux dates figurant au planning. Délai d'accès moyen de 1 mois​​

Nos formations sont accessibles aux personnes en situation de handicap.

Un questionnaire envoyé en amont de la formation invite les participants à nous contacter s’ils ont besoins d’aménagements spécifiques en lien avec leur situation de handicap. Nous nous employons à rechercher, avec les personnes concernées, les moyens de compensation qui leur seront adaptés.

Pour en valider l'accès merci de nous contacter rh@formation-IT.org

public
prérequis
objectifs
contenu
bottom of page