Study Guides
Browse all available certification study guides with full question banks and detailed explanations.
18 products found
Cisco
200-201 CCNACBR
200-201 CCNACBR
200-201 CCNACBR Study Guide200-question practice exam for Cisco CCNA Cybersecurity 200-201 CCNACBR — Understanding Cisco Cybersecurity Operations Fundamentals.
Cisco
200-301
200-301
CCNA 200-301 Study Guide150-question original study guide mapped to the CCNA 200-301 v1.1 blueprint. Covers all 6 exam domains with scenario, configuration, and command-interpretation questions.
Cisco
200-901 DEVASC
200-901 DEVASC
200-901 DEVASC Study Guide200-question practice exam for Cisco CCNA Automation 200-901 DEVASC — DevNet Associate.
Cisco
300-215 CBRFIR
300-215 CBRFIR
300-215 CBRFIR Study Guide200 original study guide questions for Cisco 300-215 CBRFIR, mapped to the Conducting Forensic Analysis and Incident Response Using Cisco Technologies for Cybersecurity blueprint.
Cisco
300-435 ENAUTO
300-435 ENAUTO
300-435 ENAUTO Study Guide200 original study guide questions for Cisco 300-435 ENAUTO, mapped to the Automating Cisco Enterprise Solutions v2.0 blueprint.
Cisco
300-610 DCID
300-610 DCID
300-610 DCID Study Guide200 original study guide questions for Cisco 300-610 DCID, mapped to the Designing Cisco Data Center Infrastructure for Traditional and AI Workloads blueprint.
Cisco
300-615 DCIT
300-615 DCIT
300-615 DCIT Study Guide200 original study guide questions for Cisco 300-615 DCIT, mapped to the Troubleshooting Cisco Data Center Infrastructure blueprint.
Cisco
300-620 DCACI
300-620 DCACI
300-620 DCACI Study Guide200 original study guide questions for Cisco 300-620 DCACI, mapped to the Implementing Cisco Application Centric Infrastructure blueprint.
Cisco
300-635 DCNAUTO
300-635 DCNAUTO
300-635 DCNAUTO Study Guide200 original study guide questions for Cisco 300-635 DCNAUTO, mapped to the Automating Cisco Data Center Networking Solutions blueprint.
Cisco
300-640 DCAI
300-640 DCAI
300-640 DCAI Study Guide200 original study guide questions for Cisco 300-640 DCAI, mapped to the Implementing Cisco Data Center AI Infrastructure blueprint.
Cisco
300-815 CLACC
300-815 CLACC
300-815 CLACC Study Guide200 original study guide questions for Cisco 300-815 CLACC, mapped to the Implementing Cisco Advanced Call Control On-Premises v2.0 blueprint.
Cisco
350-201
350-201
Cisco CCNP Cybersecurity 350-201 CBRCOR Practice ExamPerforming Cybersecurity Using Cisco Security Technologies (CBRCOR) — comprehensive practice exam aligned to the 350-201 exam objectives for the CCNP Cybersecurity certification.
Cisco
350-401 ENCOR
350-401 ENCOR
350-401 ENCOR Study Guide200 original study guide questions for Cisco 350-401 ENCOR, mapped to the Implementing Cisco Enterprise Network Core Technologies blueprint.
Cisco
350-601 DCCOR
350-601 DCCOR
350-601 DCCOR Study Guide200 original study guide questions for Cisco 350-601 DCCOR, mapped to the Implementing and Operating Cisco Data Center Core Technologies blueprint.
Cisco
350-801 CLCOR
350-801 CLCOR
350-801 CLCOR Study Guide200 original study guide questions for Cisco 350-801 CLCOR, mapped to the Implementing Cisco Collaboration Core Technologies v2.0 blueprint.
Cisco
350-901 AUTOCOR
350-901 AUTOCOR
350-901 AUTOCOR Study Guide200 original study guide questions for Cisco 350-901 AUTOCOR, mapped to the Designing, Deploying and Managing Network Automation Systems v2.0 blueprint.
Splunk
SPLK-5001
SPLK-5001
Splunk Certified Cybersecurity Defense Analyst# Splunk Certified Cybersecurity Defense Analyst (SPLK-5001) Study Guide ## Domain 1: The Cyber Landscape, Frameworks, and Standards ### SOC Roles and Organization **Explanation:** A Security Operations Center (SOC) is a centralized unit that deals with security issues. Roles are typically tiered: Tier 1 (Analyst) monitors and triages; Tier 2 (Incident Responder) investigates deeply; Tier 3 (Hunter/Architect) handles advanced threats and infrastructure design. **Key Concepts:** - **Analyst:** Focuses on monitoring and initial triage of notable events. - **Engineer:** Maintains the Splunk infrastructure and data ingestion pipelines. - **Architect:** Designs the overall security posture and scaling strategies. ### Cyber Industry Controls and Frameworks **Explanation:** Frameworks provide a common language for security. Splunk integrates these to map alerts to known adversary behaviors. **Key Concepts:** - **MITRE ATT&CK:** A globally-accessible knowledge base of adversary tactics and techniques based on real-world observations. - **NIST Cybersecurity Framework:** Provides a policy framework of computer security guidance (Identify, Protect, Detect, Respond, Recover). - **Splunk Integration:** Splunk Security Essentials (SSE) maps searches directly to MITRE ATT&CK techniques. ## Domain 2: Threat and Attack Types, Motivations, and Tactics ### Attack Vectors and Tactics **Explanation:** Understanding how attackers enter a network (vectors) and what they do once inside (tactics). **Key Concepts:** Phishing, Brute Force, SQL Injection, and Lateral Movement. ### Data Source Assessment **Explanation:** Analysts must know if they have the right data to detect specific threats. **Tools:** - **Splunk Security Essentials (SSE):** Used to perform a Data Inventory and see which MITRE techniques are covered by current data. - **Common Sourcetypes:** `WinEventLog:Security`, `linux_secure`, `cisco:asa`, `stream:http`. ## Domain 4: Investigation, Event Handling, Correlation, and Risk ### Investigation Stages and Monitoring **Explanation:** Splunk defines a structured approach to investigation: 1. Detection, 2. Triage, 3. Investigation, 4. Response, 5. Reporting. **Metrics:** - **MTTR (Mean Time to Respond):** The average time taken to neutralize a threat. - **Dwell Time:** The duration an attacker remains undetected in the environment. ### Risk Based Alerting (RBA) **Explanation:** RBA shifts focus from individual noisy alerts to high-risk entities. Instead of alerting on a single failed login, RBA assigns "Risk Scores" to objects (users/systems). When a threshold is met, a **Risk Notable** is generated. **Key Terms:** - **Risk Object:** The entity (user/system) being tracked. - **Contributing Events:** The individual events that added to the risk score. ## Domain 5: SPL and Efficient Searching ### Security-Focused SPL Commands **Explanation:** Efficient searching is critical for large-scale security data. - **TSTATS:** Extremely fast; searches indexed metadata rather than raw data. Use for high-level summaries. - **REX:** Used for field extraction at search time using regular expressions. - **TRANSACTION:** Groups events together (e.g., a web session), but is resource-intensive. - **EVAL:** Calculates expressions and creates new fields. **Example Query:** `| tstats count from datamodel=Authentication by Authentication.user, Authentication.src` ### Search Best Practices - **Filter Early:** Use specific indexes and sourcetypes at the beginning of the search. - **Avoid Wildcards at the Start:** `*error` is slower than `error*`. - **Use Data Models:** Leverage Accelerated Data Models for faster reporting in ES. ## Domain 6: Threat Hunting and Remediation ### Threat Hunting Techniques **Explanation:** Proactive searching for threats that evaded existing security controls. - **Long Tail Analysis:** Looking for rare events (e.g., a process that only ran once across 10,000 machines). - **Outlier Detection:** Using commands like `anomalydetection` to find statistical deviations. ### SOAR and Adaptive Response **Explanation:** Splunk SOAR (formerly Phantom) automates response actions. - **Adaptive Response Actions:** Actions triggered from a correlation search (e.g., pinging a host, adding an IP to a blocklist, or running a SOAR playbook). - **Playbooks:** Automated workflows that execute security tasks at machine speed.
Cisco
300-830 CLCCE
300-830 CLCCE
300-830 CLCCE Study GuideStudy guide for 300-830 CLCCE covering Expressway, MRA, and cloud/edge collaboration solutions.
All-Vendor Lifetime Access
Get lifetime access to every study guide for an entire vendor — current and future exams included. One price, unlimited access.
All Cisco Access
Lifetime access to all Cisco exam study guides
All Splunk Access
Lifetime access to all Splunk exam study guides