SSFAMP Protecting against Malware Threats with Cisco AMP for Endpoints

This lab-intensive course introduces students to the powerful features of Cisco AMP for Endpoints software, and is offered by Cisco Learning Services. A number of step by step attack scenarios will provide an understanding of the operational uses of the product. Students will learn how to build and manage a Cisco AMP for Endpoints deployment, create policies for endpoint groups, and deploy connectors .The AMP for Endpoints console provides powerful tools that will enable you to analyze malware detections.

Audience

Technical professionals who need to know how to deploy and manage Cisco AMP for Endpoints software in their network environments.

Prerequisites

Attendees should meet the following prerequisites:

  • Technical understanding of TCP/IP networking and network architecture - ICND2 Recommended
  • Technical understanding of security concepts and protocols - IINS Recommended

Course objectives

After completing this course you should be able to:

  • Identify the key components and methodologies of Cisco Advanced Malware Protection (AMP)
  • Recognize the key features and concepts of the AMP for Endpoints product
  • Navigate the AMP for Endpoints console interface and perform first-use setup tasks
  • Identify and use the primary analysis features of AMP for Endpoints
  • Use the AMP for Endpoints tools to analyze a compromised host
  • Describe malware terminology and recognize malware categories
  • Analyze files and events by using the AMP for Endpoints console and be able to produce threat reports
  • Use the AMP for Endpoints tools to analyze a malware attack and a ZeroAccess infection
  • Configure and customize AMP for Endpoints to perform malware detection
  • Create and configure a policy for AMP-protected endpoints
  • Plan, deploy, and troubleshoot an AMP for Endpoints installation
  • Describe the AMP Representational State Transfer (REST) API and the fundamentals of its use
  • Describe all the features of the Accounts menu for both public and private cloud installations

Certification

This course is recommended preparation for the following proctored exam:

Exam 500-275 - Securing Cisco Networks with Sourcefire FireAMP Endpoints