When you enroll in this course, you'll also be enrolled in this Professional Certificate.
Learn new concepts from industry experts
Gain a foundational understanding of a subject or tool
Develop job-relevant skills with hands-on projects
Earn a shareable career certificate from Google Cloud
There are 4 modules in this course
Wow, you’re already on the fourth course of the Google Cloud Cybersecurity Certificate. Sharpen your security senses as you learn about log retention policies, intrusion detection and prevention systems, and the intricacies of monitoring and alerts. Learn how to effectively manage and respond to security incidents through business continuity and disaster recovery. Happy learning!
Gear up for a deep dive into the heart of security operations! In this module, you’ll delve into crucial topics for detecting security activities, focusing on log retention policies, intrusion detection and prevention systems, and the intricacies of monitoring and alerts. You'll learn about incident management and attack mitigation strategies. And you’ll take a guided tour through logging fundamentals and monitoring best practices, equipping you with the knowledge to effectively manage and respond to security incidents.
Seline: Make an impact in cloud security•1 minute
Welcome to module 1•1 minute
SecOps and its components•5 minutes
Vulnerability management techniques•6 minutes
Incident detection basics•3 minutes
Phases of incident response and management•8 minutes
Incident response plans•8 minutes
Intrusion detection systems•6 minutes
Signature and anomaly-based detection•3 minutes
Logs for analysis and monitoring•6 minutes
Log management: The skills needed for success•7 minutes
Alerts and notifications•5 minutes
Alert search techniques•4 minutes
Wrap-up•1 minute
12 readings•Total 120 minutes
Course 4 overview•10 minutes
Helpful resources and tips•10 minutes
Lab technical tips•10 minutes
Explore your course 4 scenario: Cymbal Bank•10 minutes
Essential SecOps skills•10 minutes
Vulnerability scanning, penetration testing, and tabletop exercises•10 minutes
AI in SecOps: Red teams•10 minutes
More about incident response phases•10 minutes
Log types: A breakdown•10 minutes
Alert and log optimization•10 minutes
Guide to event threat detection•10 minutes
Glossary terms from module 1•10 minutes
5 assignments•Total 82 minutes
Module 1 challenge•50 minutes
Test your knowledge: Security operations foundations•8 minutes
Test your knowledge: Incident management foundations•8 minutes
Test your knowledge: Logging and log retention fundamentals•8 minutes
Test your knowledge: Alerts, notifications, and log optimization•8 minutes
1 app item•Total 90 minutes
Determine the difference between normal activity and an incident•90 minutes
1 plugin•Total 15 minutes
Accessing and completing labs•15 minutes
Detection in practice
Module 2•4 hours to complete
Module details
Get ready to outsmart cyber adversaries! In this module, we'll dissect the attack playbook step by step, learning to spot those sneaky intrusion attempts before they wreak havoc. You’ll also learn how to create detection rules, expand your toolbelt with query tools to analyze logs, and identify indicators of compromise (IoC).
What's included
11 videos6 readings4 assignments1 app item
Show info about module content
11 videos•Total 45 minutes
Welcome to module 2•1 minute
Introduction to Lockheed Martin’s Cyber Kill Chain®•5 minutes
False positive analysis•3 minutes
Introduction to security monitoring•4 minutes
Tim: Analytical skills for detection and response•3 minutes
Tools for proactive security monitoring•4 minutes
Indicators of compromise (IOCS)•5 minutes
Essentials of threat hunting•6 minutes
Aggregations and correlations•5 minutes
Introduction to query tools•7 minutes
Wrap-up•1 minute
6 readings•Total 60 minutes
Lockheed Martin’s Cyber Kill Chain® in practice•10 minutes
Guide to false positive analysis•10 minutes
Security monitoring key concepts•10 minutes
IOCs for threat detection•10 minutes
Query tools: RegEx and YARA-L•10 minutes
Glossary terms from module 2•10 minutes
4 assignments•Total 74 minutes
Module 2 challenge•50 minutes
Test your knowledge: False positives and Lockheed Martin’s Cyber Kill Chain®•8 minutes
Test your knowledge: Proactive security monitoring and alerting•8 minutes
Test your knowledge: Threat hunting and indicators of compromise•8 minutes
1 app item•Total 90 minutes
Explore false positives through incident detection•90 minutes
Incident response management and attack mitigation
Module 3•5 hours to complete
Module details
Ready to become an incident response expert? From the first sign of trouble to those crucial lessons learned. You'll learn to communicate like a pro, keeping everyone in the loop while you contain the chaos. We'll delve into the art of the post-mortem, figuring out exactly what went down and how to prevent it next time. And get this – you'll become an expert of automation, designing playbooks that streamline the response and give you back precious time. By the end, you'll be the go-to expert, orchestrating security operations with efficiency.
What's included
12 videos10 readings6 assignments1 app item
Show info about module content
12 videos•Total 47 minutes
Welcome to module 3•2 minutes
The importance of evidence preservation•4 minutes
How security teams preserve evidence•5 minutes
Incident response in Google Cloud•5 minutes
Incident identification•4 minutes
Coordination for incident response•4 minutes
Documentation fundamentals•4 minutes
Elements of successful documentation•4 minutes
Actionable alert identification•5 minutes
Security orchestration with playbooks•6 minutes
Fatima: A day in the life of a detection and response team manager•3 minutes
Wrap-up•1 minute
10 readings•Total 100 minutes
Digital evidence preservation: Techniques and best practices•10 minutes
Incident response best practices with Chronicle SOAR•10 minutes
Guide to log queries, exports, and analysis•10 minutes
Documentation in practice•10 minutes
Activity: Document a timeline of events•10 minutes
Activity Exemplar: Document a timeline of events•10 minutes
Incident response partners•10 minutes
Incident response orchestration versus automation•10 minutes
Playbooks' role in incident response•10 minutes
Glossary terms from module 3•10 minutes
6 assignments•Total 90 minutes
Module 3 challenge•50 minutes
Test your knowledge: Evidence preservation•8 minutes
Test your knowledge: Incident management•8 minutes
Activity Quiz: Document a timeline of events•8 minutes
Test your knowledge: Documentation•8 minutes
Test your knowledge: Response in action using automation•8 minutes
1 app item•Total 90 minutes
Analyze audit logs using BigQuery•90 minutes
Incident recovery
Module 4•5 hours to complete
Module details
Brace yourself for the ultimate resilience challenge! In this module, you'll become the architect of disaster-proof cloud systems. We'll cover everything from bulletproof backup strategies to lightning-fast recovery plans – because when systems fail, every second counts. You'll harness the power of automation to detect attacks and respond like a digital SWAT team. We'll explore the ins and outs of BCDR (Business Continuity and Disaster Recovery) tools, your ultimate weapons in the fight against downtime. Remember, recovery is your secret weapon – and this module will teach you how to wield it with precision.
What's included
12 videos10 readings5 assignments1 app item
Show info about module content
12 videos•Total 40 minutes
Welcome to module 4•1 minute
Recovery plans in action•3 minutes
Information recovery and system restoration•3 minutes
Business continuity and disaster recovery (BCDR) basics•3 minutes
BCDR in Google Cloud•6 minutes
Recovery options and measures of success•5 minutes
Components of a disaster recovery plan (DRP)•5 minutes
Business continuity and disaster recovery plans•3 minutes
Disaster recovery plan stakeholders•4 minutes
Wrap-up•1 minute
Patrick and Pedro: Interview role play•5 minutes
Course wrap-up•2 minutes
10 readings•Total 110 minutes
System recovery steps and scenarios•10 minutes
The role of BCDR tools•10 minutes
Guide to backups and VM recovery•10 minutes
Disaster recovery planning in Google Cloud: Build a DRP•10 minutes
Disaster recovery planning in Google Cloud: Implement a DRP•10 minutes
Create and manage effective BCDR plans•10 minutes
Interview tip: End responses with positive takeaways•20 minutes
Glossary terms from module 4•10 minutes
Course 4 resources and citations•10 minutes
Glossary terms from course 4•10 minutes
5 assignments•Total 82 minutes
Module 4 challenge•50 minutes
Test your knowledge: Recovery plans and system restoration•8 minutes
Test your knowledge: Business continuity and disaster recovery•8 minutes
Test your knowledge: Disaster recovery plan fundamentals•8 minutes
Test your knowledge: BCDR roles and responsibilities•8 minutes
1 app item•Total 90 minutes
Recover VMs with Google Backup and DR Service•90 minutes
Earn a career certificate
Add this credential to your LinkedIn profile, resume, or CV. Share it on social media and in your performance review.
Instructor
Instructor ratings
Instructor ratings
We asked all learners to give feedback on our instructors based on the quality of their teaching style.
We help millions of organizations empower their employees, serve their customers, and build what’s next for their businesses with innovative technology created in—and for—the cloud. Our products are engineered for security, reliability, and scalability, running the full stack from infrastructure to applications to devices and hardware. Our teams are dedicated to helping customers apply our technologies to create success.
When will I have access to the lectures and assignments?
To access the course materials, assignments and to earn a Certificate, you will need to purchase the Certificate experience when you enroll in a course. You can try a Free Trial instead, or apply for Financial Aid. The course may offer 'Full Course, No Certificate' instead. This option lets you see all course materials, submit required assessments, and get a final grade. This also means that you will not be able to purchase a Certificate experience.
What will I get if I subscribe to this Certificate?
When you enroll in the course, you get access to all of the courses in the Certificate, and you earn a certificate when you complete the work. Your electronic Certificate will be added to your Accomplishments page - from there, you can print your Certificate or add it to your LinkedIn profile.