Skip to Content
Cisco CyberOps Associate CBROPS 200-201 Official Cert Guide
book

Cisco CyberOps Associate CBROPS 200-201 Official Cert Guide

by Omar Santos
December 2020
Intermediate to advanced
688 pages
21h 18m
English
Cisco Press
Content preview from Cisco CyberOps Associate CBROPS 200-201 Official Cert Guide

Chapter 10

Network Infrastructure Device Telemetry and Analysis

This chapter covers the following topics:

Network Infrastructure Logs

Traditional Firewall Logs

Syslog in Large-Scale Environments

Next-Generation Firewall and Next-Generation IPS Logs

NetFlow Analysis

Network Packet Capture

Network Profiling

This chapter covers different network and host security telemetry solutions. Network telemetry and logs from network infrastructure devices such as firewalls, routers, and switches can prove useful when you’re proactively detecting or responding to a security incident. Logs from user endpoints can help you not only for attribution if they are part of a malicious activity but also for victim identification.

“Do I Know This Already?” Quiz

Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Start your free trial

You might also like

Cisco Certified DevNet Professional DEVCOR 350-901 Official Cert Guide

Cisco Certified DevNet Professional DEVCOR 350-901 Official Cert Guide

Anwin Kallumpurath, David Wang, Hazim Dahir, Jason Davis
Cisco Certified DevNet Associate DEVASC 200-901 Official Cert Guide

Cisco Certified DevNet Associate DEVASC 200-901 Official Cert Guide

Chris Jackson, Adrian Iliesiu, Ashutosh Malegaonkar, Jason Gooley
CCNP and CCIE Enterprise Core ENCOR 350-401 Official Cert Guide, 2nd Edition

CCNP and CCIE Enterprise Core ENCOR 350-401 Official Cert Guide, 2nd Edition

Brad Edgeworth, Ramiro Garza Rios, David Hucaby, Jason Gooley

Publisher Resources

ISBN: 9780136807964