CompTIA Security+: Security Monitoring & Alerting
Learn effective security monitoring and alerting. Explore agent-based and agentless monitoring, monitoring activities, benefits of SCAP, SIEM, SOAR, and antivirus and DLP systems.
About this course
Congratulations. You have convinced your steering committee to give you a huge budget, new hires, and broader access to deploy a ton of security controls at the new regional branch office. However, within weeks you will be brought back to report on the effectiveness of the new expensive toys. This is why solid monitoring and alerting are critical for success. In this course, you will explore security monitoring and alerting, beginning with monitoring computing resources, visibility, and agent-based and agentless monitoring. Then you will focus on monitoring activities like log aggregation, alert response, and validation. Next, you will discover the importance and benefits of Security Content Automation Protocol (SCAP), security information and event management (SIEM), and security orchestration, automation, and response (SOAR) systems. Finally, you will investigate antivirus and data loss prevention (DLP) systems, Simple Network Management Protocol (SNMP) traps, and NetFlow records. This course is part of a series that prepares you for the CompTIA Security+ (SY0-701) exam.
Learning objectives
Discover the key concepts covered in this course
Describe monitoring computing resources like systems, applications, and infrastructure with agents and agentless solutions
Define monitoring activities such as log aggregation, alerting, scanning, reporting, archiving, alert response and remediation, and validation
Show all
There are no reviews yet.