Courses
Oracle Courses
Symantec Courses

DLP-A11 --- Symantec Data Loss Prevention 11.0 Administration

Overview

The Symantec Data Loss Prevention 11.0 Administration course is designed to provide you with the fundamental knowledge to configure and administer the Symantec Data Loss Prevention Enforce platform.

Objectives

The Symantec Data Loss Prevention 11.0 Administration course is designed to provide you with the fundamental knowledge to configure and administer the Symantec Data Loss Prevention Enforce platform. The hands-on labs include exercises for installation of the Enforce server, detection servers, and DLP Agents, reporting, workflow, and incident response management, policy management and detection, response management, user and role administration, directory integration, and filtering. Additionally, you are introduced to the following Symantec Data Loss Prevention products: Network Monitor, Network Prevent, Network Discover, Network Protect, Endpoint Prevent, and Endpoint Discover, as well as deployment best practices. Note that this course is delivered on a Microsoft Windows platform.

PreRequisites

You must have a working knowledge of windows serverclass operating systems and commands, as well as networking and network security concepts.

Who Can Benefit

This course is intended for those responsible for the application configuration, maintenance, and troubleshooting of Symantec Data Loss Prevention. Additionally, this course is intended for technical users responsible for creating and maintaining Symantec Data Loss Prevention policies and the incident response structure.

Duration

4 Days

Course Content

Symantec Data Loss Prevention 11.0 Administration Content Details

 
 
Introduction to Symantec Data Loss Prevention
  • Symantec Data Loss Prevention overview
  • Symantec Data Loss Prevention architecture
Navigation and Reporting
  • Navigating the user interface
  • Reporting and analysis
  • Report navigation, preferences, and features
  • Report filters
  • Report commands
  • Incident snapshot
  • Hands-On Labs: Become familiar with navigation and tools in the user interface. Create, filter, summarize, and distribute reports. Create users, roles, and attributes.
Incident Remediation and Workflow
  • Incident remediation and workflow
  • Managing users and attributes
  • Custom attribute lookup
  • Hands-On Labs: Remediate incidents, configure a user’s reporting preferences, and custom attribute look-ups using a .csv file.
Policy Management
  • Policy overview
  • Creating policy groups
  • Using policy templates
  • Building policies
  • Policy development best practices
  • Hands-On Labs: Use policy templates and policy builder to configure and apply new policies.
Response Rule Management
  • Response rule overview
  • Creating Automated Response rules
  • Creating Smart Response rules
  • Response rule best practices
  • Hands-On Labs: Create and use Automated and Smart
  • Response rules.
Described Content Matching
  • DCM detection methods
  • Use cases
  • Using DCM in policies
  • Hands-On Labs: Create policies that include DCM and then use those policies to capture incidents.
Exact Data Matching and Directory Group Matching
  • Exact data matching (EDM)
  • Directory group matching (DGM)
  • Advanced EDM
  • Hands-On Labs: Create policies that include EDM, and DGM and then use those policies to capture incidents.
Indexed Document Matching
  • IDM detection methods
  • Use cases
  • Using IDM in policies
  • Hands-On Labs: Create policies that include IDM rules and then use those policies to capture incidents.
 
Vector Machine Learning
  • How VML works
  • Similarity Threshold
  • VML Profile
  • Creating a VML policy
  • Hands-On Labs: Create a VML profile, import document sets, and create a VML policy.
Network Monitor Review
  • Review of Network Monitor
  • Protocols
  • Traffic filtering
  • Network Monitor best practices
  • Hands-On Labs: Apply IP and L7 Filters.
Introduction to Network Prevent
  • Network Prevent overview
  • Introduction to Network Prevent (Email)
  • Introduction to Network Prevent (Web)
  • Hands-On Labs: Configure Network Prevent (Email) response rules, incorporate them into policies, and use the policies to capture incidents.
Introduction to Network Discover and Network Protect
  • Network Discover and Network Protect overview
  • Configuring Discover targets
  • Protecting data
  • FlexResponse platform
  • Running and managing scans
  • Reports and remediation
  • Network Discover and Network Protect best practices
  • Hands-On Labs: Create and run a file system target using various response rules, including quarantining
Introduction to Endpoint Prevent
  • Endpoint Prevent overview
  • Configuring Endpoint Prevent
  • Detection capabilities at the Endpoint
  • Managing agents
  • Creating Endpoint response rules
  • Capturing Endpoint Prevent incidents and viewing them in reports
  • Endpoint Prevent best practices
  • Hands-On Labs: Create Endpoint response rules, monitor and block Endpoint actions, and view Endpoint Incidents.
Introduction to Endpoint Discover
  • Endpoint Discover overview
  • Creating and running Endpoint Discover targets
  • Using Endpoint Discover reports and reporting features
  • Hands-On Labs: Create Endpoint Discover targets, run Endpoint Discover targets, and view Endpoint Discover incidents.
Enterprise Enablement
  • Preparing for risk reduction
  • Risk reduction
System Administration
  • Server administration
  • Troubleshooting
  • Hands-On Labs: Interpret event reports and traffic Reports, configure alerts, use the ECU tool, and use the Log Collection and Configuration tool.



Interested in any of our courses. Use this form to contact us