Flash Sale: Save 15% on IT Training

closeClose

VMware Carbon Black EDR Advanced Administrator

  • Tuition USD $925
  • Reviews star_rate star_rate star_rate star_rate star_half 1508 Ratings
  • Course Code EDU-VCBEDRAA
  • Duration 1 day
  • Available Formats Classroom, Virtual

This one-day course teaches you how to use the advanced features of the VMware Carbon Black® EDR™ product. This usage includes gaining access to the Linux server for management and troubleshooting in addition to configuring integrations and using the API. This course provides an in-depth, technical understanding of the Carbon Black EDR product through comprehensive coursework and hands-on scenario-based labs. This class focuses exclusively on advanced technical topics related to the technical back-end configuration and maintenance.

Skills Gained

By the end of the course, you should be able to meet the following objectives:

  • Describe the components and capabilities of the Carbon Black EDR server
  • Identify the architecture and data flows for Carbon Black EDR communication
  • Identify the architecture for a cluster configuration and Carbon Black EDR cluster communication
  • Describe the Carbon Black EDR server data types and data locations
  • Use the API to interact with the Carbon Black EDR server without using the UI
  • Create custom threat feeds for use in the Carbon Black EDR server
  • Perform the integration with a syslog server
  • Use different server-side scripts for troubleshooting
  • Troubleshoot sensor-side configurations and communication

Who Can Benefit

System administrators and security operations personnel, including analysts and managers.

Prerequisites

This course requires completion of the following course

  • VMware Carbon Black EDR Administrator

Course Details

Product Alignment

  • VMware Carbon Black EDR

Outline

Course Introduction

  • Introductions and course logistics
  • Course objectives

Architecture

  • Data flows and channels
  • Sizing considerations
  • Communication channels and ports

Server Datastores

  • SOLR database
  • Storage configurations and data aging
  • Partition states
  • Postgres
  • Modulestore

EDR API

  • CBAPI overview
  • Viewing API calls in the browser
  • Utilizing the API to access data

Threat Intelligence Feeds

  • Feed structure
  • Report indicator types
  • Custom threat feed creation and addition

Syslog Integration

  • SIEM support
  • Configuration

Troubleshooting

  • Server-side scripts
  • Server logs
  • Sensor operations

When does class start/end?

Classes begin promptly at 9:00 am, and typically end at 5:00 pm.

Does the course schedule include a Lunchbreak?

Lunch is normally an hour long and begins at noon. Coffee, tea, hot chocolate and juice are available all day in the kitchen. Fruit, muffins and bagels are served each morning. There are numerous restaurants near each of our centers, and some popular ones are indicated on the Area Map in the Student Welcome Handbooks - these can be picked up in the lobby or requested from one of our ExitCertified staff.

How can someone reach me during class?

If someone should need to contact you while you are in class, please have them call the center telephone number and leave a message with the receptionist.

What languages are used to deliver training?

Most courses are conducted in English, unless otherwise specified. Some courses will have the word "FRENCH" marked in red beside the scheduled date(s) indicating the language of instruction.

What does GTR stand for?

GTR stands for Guaranteed to Run; if you see a course with this status, it means this event is confirmed to run. View our GTR page to see our full list of Guaranteed to Run courses.

Does ExitCertified deliver group training?

Yes, we provide training for groups, individuals and private on sites. View our group training page for more information.

Does ExitCertified deliver group training?

Yes, we provide training for groups, individuals, and private on sites. View our group training page for more information.

Very detailed training.Effective for Devops with cloud responsibilities.The Tech explanation and lab is very informative.

I really enjoyed the Architecting on AWS class. The class was very informative about all the AWS tools that we can use and will need when we go to the cloud.

Attended a Power BI class in McLean with this company. The instructor (Mike Staves) was very good and attentive to the groups' learning needs. The facility was very good and the staff was more than accommodating.

This was my second course through ExitCertified, and it continues to be a great way to learn and advance my career!

Instructions were clear, lab exercises were pertinent and self-explanatory, topic was thoroughly covered in the presented course material.

6 options available

undo
  • Dec 8, 2020 Dec 8, 2020 (1 day)
    Location
    Virtual
    Language
    English
    Time
    9:00 AM 5:00 PM PDT
    Enroll
    Enroll
    LIMITED TIME: Get 15% off this course.  Promo Code: FLASH15
  • Dec 10, 2020 Dec 10, 2020 (1 day)
    Location
    Virtual
    Language
    English
    Time
    9:00 AM 5:00 PM EDT
    Enroll
    Enroll
    LIMITED TIME: Get 15% off this course.  Promo Code: FLASH15
  • Jan 5, 2021 Jan 5, 2021 (1 day)
    Location
    Virtual
    Language
    English
    Time
    9:00 AM 5:00 PM PDT
    Enroll
    Enroll
  • Jan 14, 2021 Jan 14, 2021 (1 day)
    Location
    Virtual
    Language
    English
    Time
    9:00 AM 5:00 PM EDT
    Enroll
    Enroll
  • Jan 21, 2021 Jan 21, 2021 (1 day)
    Location
    Virtual
    Language
    English
    Time
    9:00 AM 5:00 PM PDT
    Enroll
    Enroll
  • Jan 26, 2021 Jan 26, 2021 (1 day)
    Location
    Virtual
    Language
    English
    Time
    9:00 AM 5:00 PM EDT
    Enroll
    Enroll
Contact Us 1-800-803-3948
Contact Us Live Chat
FAQ Get immediate answers to our most frequently asked qestions. View FAQs arrow_forward