From the course: SecOps on Google Distributed Cloud (GDC) for Tier 3 Analysts by Google
Tools for advanced incident response - Google Cloud Platform Tutorial
From the course: SecOps on Google Distributed Cloud (GDC) for Tier 3 Analysts by Google
Tools for advanced incident response
- [Instructor] Advanced incident response tools are crucial for improving manual incident response. These tools provide the Tier 3 analysts the capabilities they need to adapt and react effectively when facing unforeseen security challenges. When managing advanced incidents, there's a variety of tools at your disposal that can really make a difference. Examples include monitoring tools, alerting tools, ticketing systems, and post-incident analysis tools. These tools are all designed to help you overcome some of the challenges noted in earlier videos, such as delayed response time, ineffective communication, reduced visibility and difficulties in maintaining historical data. Advanced incident response tools can detect issues and promptly notify you, keep tasks organized, and help you learn from past incidents. This all contributes to a smoother and more effective incident response. Here is a list of common tools you'll use for advanced incident response. In the following videos, you'll explore each one in order to understand their function, explore an example, and uncover best practices.
Practice while you learn with exercise files
Download the files the instructor uses to teach the course. Follow along and learn by watching, listening and practicing.
Contents
-
-
-
Module overview42s
-
Advanced incident response for Tier 3 analysts3m
-
Ad hoc incident response2m 55s
-
Using an incident management plan for ad hoc incident response2m 58s
-
Tools for advanced incident response1m 10s
-
Endpoint detection and response (EDR) tools3m 41s
-
Security information and event management (SIEM) tools4m 21s
-
Vulnerability scanners4m 27s
-
(Locked)
Threat intelligence tools4m 21s
-
(Locked)
Intrusion detection and prevention systems (IDPS) tools4m 25s
-
(Locked)
Digital forensic tools4m 39s
-
(Locked)
Advanced incident response tools at Cymbal Federal3m 46s
-
(Locked)
Metrics for evaluating incident response4m 32s
-
-
-
-
-