К содержимому
learnspaceYOUR NEXT CHAPTER
ПРОСТРАНСТВО ОБУЧЕНИЯ
ГлавнаяКаталог курсовМоё обучениеCoursera

Знания без границ

Учитесь у лучших университетов и компаний мира.

Открыть Coursera
Интеграция
Пространство университета
Моё пространствоСтраница курса
↵
ЯЛичный кабинетСтудент
© 2026 LearnSpaceКаждый день — возможность узнать больше.Помощь
Sound the Alarm: Detection and Response · LearnSpace
Назад в каталог
courseraПрограммирование

Sound the Alarm: Detection and Response

Курс от Google
Начальный≈ 17.5 чАнглийский
О курсеНавыкиПрограммаПреподаватели

О курсе

This is the sixth course in the Google Cybersecurity Certificate. Learners will focus on incident detection and response. They will learn what defines a security incident and explain the incident response lifecycle, including the roles and responsibilities of incident response teams. Learners will analyze and interpret network communications to detect security incidents using packet sniffing tools to capture network traffic. By assessing and analyzing artifacts, learners will explore the incident investigation and response processes and procedures. Additionally, they will develop a conceptual overview of log data and their role in intrusion detection systems (IDS) and Security Information Event Management (SIEM) tools. Learners who complete this certificate will be equipped to apply for entry-level cybersecurity roles. No previous experience is necessary. By the end of this course, you will: - Explain the lifecycle of an incident. - Describe the tools used in documentation, detection, and management of incidents. - Analyze packets to interpret network communications. - Perform artifact investigations to analyze and verify security incidents. - Identify the steps to contain, eradicate, and recover from an incident. - Determine how to read and analyze logs during incident investigation. - Interpret the basic syntax and components of signatures and logs in Intrusion Detection Systems (IDS) and Network Intrusion Detection Systems (NIDS) tools. - Perform queries in Security Information and Event Management (SIEM) tools to investigate an event.

Навыки, которые вы освоите

Incident ResponseIntrusion Detection and PreventionSecurity Information and Event Management (SIEM)SplunkNetwork ProtocolsTCP/IPNetwork AnalysisComputer Security Incident ManagementEndpoint Detection and ResponseDocument ManagementNetwork SecurityNetwork MonitoringSecurity ControlsEvent MonitoringQuery LanguagesContinuous MonitoringIncident ManagementCyber Threat IntelligenceThreat Detection

Программа курса

4 модулей · 121 учебных материалов

01Introduction to detection and incident response26 материалов

Get started with the course

Introduction to Course 6 ВидеоCourse 6 overviewЧтениеHelpful resources and tipsЧтениеDave: Grow your cybersecurity career with mentorsВидео

The incident response lifecycle

Учитесь у экспертов

Google Career Certificates

Преподаватель курса

Sound the Alarm: Detection and Response
В каталоге вашей программы

Инвестируйте в себя

Новые знания — в удобное для вас время.

Начать на Coursera

Обучение откроется на Coursera
в новой вкладке

Обучение на Coursera

≈ 17.5 ч

4 модулей

Язык: Английский

Субтитры: Арабский, Французский, Украинский, Бразильский португальский, Вьетнамский, Корейский, Немецкий, Индонезийский, Турецкий, Испанский, Японский

Часть программы вашего университета
Welcome to module 1 Видео
Introduction to the incident response lifecycle Видео
Explore: Apply the NIST lifecycle to a vishing scenarioPLUGIN
Portfolio Activity: Document an incident with an incident handler's journalЗадание
Portfolio Activity Exemplar: Document an incident with an incident handler's journalЧтение
Test your knowledge: The incident response lifecycleЗадание

Incident response operations

Incident response teams ВидеоFatima: The importance of communication during incident responseВидеоRoles in response ЧтениеIncident response plansВидеоTest your knowledge: Incident response operationsЗадание

Incident response tools

Incident response tools ВидеоThe value of documentation ВидеоIntrusion detection systems ВидеоOverview of detection tools ЧтениеTest your knowledge: Detection and documentation tools ЗаданиеAlert and event management with SIEM and SOAR toolsВидеоOverview of SIEM technology ЧтениеTest your knowledge: Management toolsЗадание

Review: Introduction to detection and incident response

Wrap-up ВидеоGlossary terms from module 1Чтение Module 1 challengeЗадание
02Network monitoring and analysis28 материалов

Understand network traffic

Welcome to module 2ВидеоCasey: Apply soft skills in cybersecurityВидеоThe importance of network traffic flowsВидеоMaintain awareness with network monitoring ЧтениеData exfiltration attacksВидеоTest your knowledge: Understand network trafficЗадание

Capture and view network traffic

Packets and packet capturesВидеоLearn more about packet captures ЧтениеInterpret network communications with packetsВидеоReexamine the fields of a packet headerВидеоInvestigate packet detailsЧтениеResources for completing labsЧтение

Packet inspection

Packet captures with tcpdumpВидеоOverview of tcpdump ЧтениеActivity: Capture your first packetВнешний инструментOptional Exemplar: Capture your first packetВнешний инструментExemplar: Capture your first packetЧтениеTest your knowledge: Packet inspectionЗадание

Review: Network monitoring and analysis

Wrap-upВидеоGlossary terms from module 2ЧтениеModule 2 challengeЗадание
03Incident investigation and response31 материалов

Incident detection and verification

Welcome to module 3 ВидеоThe detection and analysis phase of the lifecycle ВидеоCybersecurity incident detection methodsЧтениеOngoing Monitoring of CI/CDЧтениеMK: Changes in the cybersecurity industryВидеоIndicators of compromiseЧтениеIdentify: Indicators of compromisePLUGINAnalyze indicators of compromise with investigative toolsЧтениеActivity: Investigate a suspicious file hashЗаданиеActivity Exemplar: Investigate a suspicious file hashЧтениеTest your knowledge: Incident detection and verificationЗадание

Create and use documentation

The benefits of documentation ВидеоDocument evidence with chain of custody forms ВидеоBest practices for effective documentation ЧтениеThe value of cybersecurity playbooks ВидеоActivity: Use a playbook to respond to a phishing incidentЗаданиеActivity Exemplar: Use a playbook to respond to a phishing incidentЧтение

Response and recovery

The role of triage in incident response ВидеоRobin: Foster cross-team collaborationВидеоThe triage process ЧтениеThe containment, eradication, and recovery phase of the lifecycleВидеоBusiness continuity considerationsЧтениеTest your knowledge: Response and recoveryЗадание

Post-incident actions

The post-incident activity phase of the lifecycle ВидеоPost-incident review ЧтениеActivity: Review a final reportЗаданиеIdentify: Explore an incident event timelinePLUGINTest your knowledge: Post-incident actions Задание

Review: Incident investigation and response

Wrap-up ВидеоGlossary terms from module 3ЧтениеModule 3 challengeЗадание
04Network traffic and logs using IDS and SIEM tools36 материалов

Overview of logs

Welcome to module 4 ВидеоThe importance of logs ВидеоBest practices for log collection and managementЧтениеTest your knowledge: Overview of logsЗаданиеRebecca: Learn new tools and technologiesВидеоVariations of logs ВидеоOverview of log file formatsЧтениеIdentify: Match log files to their file formatPLUGINTest your knowledge: Log components and formatsЗадание

Overview of intrusion detection systems (IDS)

Security monitoring with detection tools Видео Detection tools and techniquesЧтениеGrace: Security mindset in detection and responseВидеоComponents of a detection signature ВидеоExamine signatures with SuricataВидеоExamine Suricata logsВидео

Overview of security information event management (SIEM) tools

Reexamine SIEM toolsВидеоLog sources and log ingestionЧтениеQuery for events with SplunkВидеоQuery for events with Google SecOpsВидеоSearch methods with SIEM toolsЧтениеTest your knowledge: Overview of SIEM toolsЗадание

Review: Network traffic and logs using IDS and SIEM tools

Coach dialogue: Explore network security technologiesDIALOGUEWrap-up ВидеоGlossary: Network traffic and logs using IDs and SIEM ToolsЧтениеModule 4 challengeЗаданиеPortfolio Activity: Finalize your incident handler's journalЗаданиеPortfolio Activity Exemplar: Finalize your incident handler's journalЧтение

Congratulations on completing Course 6!

Reflect and connect with peersЧтениеCourse wrap-up ВидеоCourse 6 glossaryЧтениеGet started on the next course Чтение
Lab tips and troubleshooting stepsЧтение
Activity: Analyze your first packetВнешний инструмент
Optional Exemplar: Analyze your first packetВнешний инструмент
Exemplar: Analyze your first packetЧтение
Test your knowledge: Capture and view network trafficЗадание
Activity: Research network protocol analyzersЗадание
Activity Exemplar: Research network protocol analyzersЧтение
Overview of SuricataЧтение
Activity: Explore signatures and logs with SuricataВнешний инструмент
Optional Exemplar: Explore signatures and logs with SuricataВнешний инструмент
Exemplar: Explore signatures with SuricataЧтение
Test your knowledge: Overview of intrusion detection systems (IDS) Задание