Symantec Data Loss Prevention 14: Administration

 

Czas trwania – 5 dni 

Informacje o szkoleniu

The Symantec Data Loss Prevention 14.0: Administration course is designed to provide you w ith the fundamental know ledge to conf igure and administer the Symantec Data Loss Prevention Enforce platform. The hands-on labs include exercises for conf iguring Enforce server, detection servers, and DLP Agents as well as reporting, work flow, incident response management, policy management and detection, response management, user and role administration, directory integration, and f iltering. Additionally, you are introduced to deployment best practices and the follow ing Symantec Data Loss Prevention products: Netw ork Monitor, Mobile Email Monitor, Mobile Prevent, Network Prevent, Network Discover, Network Protect, Endpoint Prevent, and Endpoint Discover. Note that this course is delivered on a Microsoft Windows platform.

 

Co warto wiedzieć przed szkoleniem?

You must have a working knowledge of Windows serverclass operating systems and commands, as w ell as networking and netw ork security concepts.

 

Dla jakiej grupy odbiorców jest dedykowane szkolenie?

This course is intended for anyone responsible for configuring, maintaining, and troubleshooting Symantec Data Loss Prevention. Additionally, this course is intended for technical users responsible for creating and maintaining Symantec Data Loss Prevention policies and the incident response structure.

 

Zagadnienia

Introduction to Symantec Data Loss Prevention

Symantec Data Loss Prevention overview.
Symantec Data Loss Prevention architecture.

 

Navigation and Reporting

Navigating the user interface.
Reporting and analysis.
Report navigation, preferences, and features.
Report f ilters.
Report commands.
Incident snapshot.
Incident Data Access.
Hands-on labs: Become familiar w ith navigation and tools in the user interface. Create, filter, summarize, customize, and distribute reports. Create users, roles, and attributes.

 

Incident Remediation and Workflow

Incident remediation and w orkf low.
Managing users and attributes.

Custom attribute lookup.
User Risk Summary.

Hands-on labs: Remediate incidents and conf igure a user’s reporting preferences.

 

Policy Management

Policy overview.
Creating policy groups.
Using policy templates.
Building policies.
Policy development best practices.
Hands-on labs: Use policy templates and policy builder to configure and apply new policies.

 

Response Rule Management

Response rule overview.
Conf iguring Automated Response rules.
Conf iguring Smart Response rules.
Response rule best practices.
Hands-On Labs: Create and use Automated and Smart Response rules.

 

Described Content Matching

DCM detection methods.
Hands-on labs: Create policies that include DCM and then use those policies to capture incidents.

 

Exact Data Matching and Directory Group Matching

Exact data matching (EDM).
Advanced EDM.
Directory group matching (DGM).
Hands-on labs: Create policies that include EDM and DGM, and then use those policies to capture incidents.

 

Indexed Document Matching

Indexed document matching (IDM).
Hands-on labs: Create policies that include IDM rules and then use those policies to capture incidents.

 

Vector Machine Learning

Vector Machine Learning (VML).
Hands-on labs: Create a VML prof ile, import document sets, and create a VML policy.

 

Network Monitor

Review of Netw ork Monitor.
Protocols.
Traffic filtering.
Netw ork Monitor best practices.
Hands-On Labs: Apply IP and L7 f ilters.

 

Network Prevent

Netw ork Prevent overview.
Introduction to Netw ork Prevent (Email).
Introduction to Netw ork Prevent (Web).
Hands-On Labs: Conf igure Netw ork Prevent (E-mail) response rules, incorporate them into policies, and use the policies to capture incidents.

 

Mobile Email Monitor and Mobile Prevent

Introduction to Mobile Email Monitor.
Mobile Prevent overview.
Conf iguration.
VPN conf iguration.
Policy and Response Rule Creation.
Reporting and Remediation.
Troubleshooting.

 

Network Discover and Network Protect

Netw ork Discover and Netw ork Protect overvie.
Conf iguring Discover target.
Conf iguring Box cloud target.
Protecting dat.
Auto-discovery of servers and share.
Running and managing scan.
Reports and remediatio.
Netw ork Discover and Netw ork Protect best practice.
Hands-on labs: Create and run a f ile system target using various response rules, including quarantining.

 

Endpoint Prevent

Endpoint Prevent overview.
Detection capabilities at the Endpoint.
Conf iguring Endpoint Prevent.
Creating Endpoint response rules.
View ing Endpoint Prevent incidents.
Endpoint Prevent best practices.
Managing DLP Agents.

Hands-on labs: Create Agent Groups and Endpoint response rules, monitor and block Endpoint actions, view Endpoint incidents, and use the Enforce console to manage DLP Agents.

 

Endpoint Discover

Endpoint Discover overview.
Creating and running Endpoint Discover targets.
Using Endpoint Discover reports and reporting features.
Hands-on labs: Create Endpoint Discover targets, run Endpoint Discover targets, and view Endpoint Discover incidentsrevent (E-mail) response rules, incorporate them into policies, and use the policies to capture incidents.

 

Enterprise Enablement

Preparing for risk reduction.
Risk reduction.
DLP Maturity model.

 

System Administration

Server administration.
Language support.
Incident Deleter.
Credential management.
Troubleshooting.
Diagnostic tools.
Troubleshooting scenario.
Getting support.
Hands-on labs: Interpret event reports and traf f ic reports, configure alerts, and use the Log Collection and Configuration tool.