This comprehensive training equips you with the essential skills to navigate the AWS Security Incident Response service. You will learn how to:
- Set up a central membership account.
- Configure proactive response workflows.
- Manage an incident response team.
- Create and resolve security incident cases.
- Use powerful containment strategies.
By the end of the course, you will be able to use AWS Security Incident Response to reduce the time and cost associated with security incidents.
- Course level: Fundamental
- Duration: 60-120 minutes
Activities
- Presentations
- Demonstrations
- Videos
- Assessments
Course objectives
- Understand the key features and benefits of AWS Security Incident Response
- Navigate the AWS Security Incident Response dashboard
- Manage an incident response team
- Use AWS Organizations to set up account associations
- Configure monitoring and investigation settings
- Create and manage cases
- Use containment strategies and tools
Intended audience
- AWS customers or AWS Partners who have recently enrolled or are interested in enrolling in the AWS Security Incident Response service
Recommended Skills
- None
Course outline
Module 1: Introduction
Module 2: Getting Started
- AWS Security Incident Response Console
- Step 1: Set Up Central Membership Account
- Step 2: Define Membership Details
- Step 3: Permissions for Proactive Response
- Step 4: Review Service Permissions
- Step 5: Review and Sign Up
- Knowledge Check
Module 3: Dashboard
- Using the Dashboard
Module 4: Cases
- Create a Case
- Responding to an AWS Generated Case
- Locating an Existing Case
- Changing the Case Status
- Changing the Resolver
- Action Items
- Edit a Case
- Communications
- Permissions
- Attachments
- Tags
- Case Activities
- Closing a Case
- Knowledge Check
Module 5: Conclusion
- Summary and Resources