Home > Technical > Cisco > Cisco Network Security

MARS - Implementing Cisco Security Monitoring, Analysis and Response System v3.0

Book a course:
  Location:
Date:
Please call (03) 9670 3366 for dates.
  Duration: 4 Days
Time:
  Price:
$3,900.00 inc. GST
 

Print Preview | Send to a friend   
Learning Method: Instructor Led

Duration: 4 Days

Overview:
The Cisco Security Monitoring Analysis and Response System (CS-MARS) is part of the Cisco Security Management Suite which provides security monitoring for network security devices and host application made by Cisco or non-Cisco providers. In addition to event correlation and data reduction features found in SIM products, CS-MARS also provides topology awareness and automatic mitigation features. In knowing the topology of a network, CS-MARS can determine where the attack is originating and apply the appropriate remediation. CS-MARS is a key component in the Cisco Self Defending Network strategy. CS-MARS exchanges information with CS-Manager to provide a unified security management solution. For example, an administrator can view IPS signatures or the Firewall block / permit syslog messages received from sensors or firewalls. CS-MARS will communicate with CS-Manager and display the IPS signature table or firewall rule table. From there the IPS signature or firewall rule can be modified as necessary. Together CS-MARS and CS-Manager provide a unified management solution for monitoring and provisioning.
Target Audience:
  • Security Professionals
  • Network Engineers
Pre-requisites:
  • CCNA Security or equivalent knowledge
  • This course/exam is an elective for the CCSP certification.It is recommended that the learner also take SNRS v3.0, SNAF v1.0 and IPS v6.0 prior to this course/exam.
At Course Completion:
  • Use CS-MARS to monitor security and host application devices.
  • Know CS-MARS architecture and how CS-MARS process events.
  • Know how to use archive and restore features.
  • Use CS-MARS to run / create / customize reports
  • Use CS-MARS to investigate an incident and mitigate the security threats.
  • Use CS-MARS to do customer parser for unknown devices in CS-MARS.
  • Use CS-MARS to create / customize rules that detects dark net through best practices example.
  • Know how to tune signature / log level on device side and CS-MARS side.
Outline:
Introducing Cisco Security Monitoring, Analysis, and Response System
Understanding the System Architecture
Configuring a Cisco Security MARS Appliance
Adding Reporting and Mitigation Devices
Viewing the Summary Page
Managing Rules
Understanding Queries and Reports
Investigating and Mitigating Incidents
Working with User-Defined Log Parser Templates
Integrating with Cisco Security Manager
Managing and Administering the System
Troubleshooting and Optimizing Cisco Security MARS
Using the Cisco Security MARS Global Controller
Register Now
Course Ratings
Averaged from 6 responses.
Instructor's Knowledge
Training Quality
Training Objectives
Training Overall
Courseware Quality
What do these ratings mean?

Name:
Company:
Phone:
Email:
Location:
How can we assist you?:

Bookmark & Share
ShareTweetLinkShareDiggShareShare

Home | Search | Site Map | Legal | Privacy Policy | Terms of Use | Contact | Links & Resources | Career Opportunities

Copyright © 2009 New Horizons Learning Centres Holdings Pty Ltd. All rights reserved. ABN: 86 168 459 086


Developed by Globe Web Services