Web Application Security Version 13.0 Training Course

Similar documents
CNS-220-1I: Citrix NetScaler Essentials and Traffic Management

SASAC v1.0 Implementing Core Cisco ASA Security Cisco Training

Developing Microsoft SharePoint Server 2013 Core Solutions

VMware AirWatch Certificate Authentication for Cisco IPSec VPN

Cisco EPN Manager Operations

CNS-222-1I: NetScaler for Apps and Desktops

NiceLabel LMS. Installation Guide for Single Server Deployment. Rev-1702 NiceLabel

STANLEY Healthcare University Training & Certification Portal. Quick Reference Guide

RISKMAN REFERENCE GUIDE TO USER MANAGEMENT (Non-Network Logins)

(CNS-220) Citrix NetScaler Essentials and Traffic Management

Integrating QuickBooks with TimePro

Cisco EPN Manager Network Administration

WDBWL v1.2 Cisco Deploying Basic Wireless LANs

Overview. Recommended pre-requisite courses: Key Skills. : CNS-220-1I: Citrix NetScaler Traffic Management

Getting Started with the SDAccel Environment on Nimbix Cloud

Course Name: VMware vsphere: Install, Configure, Manage [V6.5] Duration: 5 Days

CNS-301 Citrix NetScaler 10.5 Advanced Implementation

Packet Tracer - Configuring a Zone-Based Policy Firewall (ZPF)

55114: Planning, Deploying and Managing Microsoft Project Server 2010 Duration: 3 Days Method: Instructor-Led

CXA-206-1I Citrix XenApp 6.5 Administration

Enterprise Chat and Developer s Guide to Web Service APIs for Chat, Release 11.6(1)

These tasks can now be performed by a special program called FTP clients.

Secure File Transfer Protocol (SFTP) Interface for Data Intake User Guide

Please contact technical support if you have questions about the directory that your organization uses for user management.

Date: October User guide. Integration through ONVIF driver. Partner Self-test. Prepared By: Devices & Integrations Team, Milestone Systems

ABELDent Platform Setup Conventions

Technical Paper. Installing and Configuring SAS Environment Manager in a SAS Grid Environment

Overview of Data Furnisher Batch Processing

Course 6368A: Programming with the Microsoft.NET Framework Using Microsoft Visual Studio 2008

E-Lock Policy Manager White Paper

CounterSnipe Software Installation Guide Software Version 10.x.x. Initial Set-up- Note: An internet connection is required for installation.

A Purchaser s Guide to CondoCerts

BMC Remedyforce Integration with Remote Support

Click Sign In button. Click Register Employer. Click Forgot Username and/or Password to Create a unique user ID and password.

Single File Upload Guide

HPE LoadRunner Best Practices Series. LoadRunner Upgrade Best Practices

DocAve 6 Content Manager

VMware AirWatch SDK Plugin for Apache Cordova Instructions Add AirWatch Functionality to Enterprise Applicataions with SDK Plugins

Update: Users are updated when their information changes (examples: Job Title or Department). o

HPE AppPulse Mobile. Software Version: 2.1. IT Operations Management Integration Guide

Genesys Certification Study Guide

Frequently Asked Questions

Investor Services Online Quick Reference Guide FTP Delivery

CXD-203: Managing App and Desktop Solutions with Citrix XenApp and XenDesktop 7.6

First Aid and Choking, Fire Safety, Medication Administration, and Standard Precautions Roster Submission:

Configuring Database & SQL Query Monitoring With Sentry-go Quick & Plus! monitors

CXD Citrix XenDesktop 5 Administration

App Orchestration 2.6

Technical Paper. Installing and Configuring SAS Environment Manager in a SAS Grid Environment with a Shared Configuration Directory

Implementing a SQL Data Warehouse

Compliance Guardian 4. User Guide

DocAve Governance Automation 2

CLOUD & DATACENTER MONITORING WITH SYSTEM CENTER OPERATIONS MANAGER. Course 10964B; Duration: 5 Days; Instructor-led

Virtual Office

Class Roster. Curriculum Class Roster Step-By-Step Procedure

OATS Registration and User Entitlement Guide

SAS Viya 3.2 Administration: Mobile Devices

Managing Your Access To The Open Banking Directory How To Guide

ABELMed Platform Setup Conventions

Dolby Conference Phone Support Frequently Asked Questions

Launching Xacta 360 Marketplace AMI Guide June 2017

Planning, installing, and configuring IBM CMIS for Content Manager OnDemand

Student Quick Reference Guide

Cisco Smart Software Manager satellite

CXA Basic Administration for Citrix XenApp 6

Implementing a Data Warehouse with Microsoft SQL Server

Kaltura Video Extension for SharePoint 2013 Deployment Guide for Microsoft Office 365. Version: 1.0

Refreshing Axiom TEST with a Current Copy of Production Axiom EPM June 20, 2014

Admin Report Kit for Exchange Server

VMware vsphere 6: Fast Track

Cisco EPN Manager Network Administration - Optical

NSE 8 Certification. Exam Description for FortiGate 5.2 and higher

istartsmart 3.5 Upgrade - Installation Instructions

Customer Information. Agilent 2100 Bioanalyzer System Startup Service G2949CA - Checklist

Enterprise Installation

White Paper. Contact Details

Introduction to Mindjet on-premise

Xerox WorkCentre 7120/7125 Series User Instructions

AppSense Management Center. Product Guide Version 10.1

Your New Service Request Process: Technical Support Reference Guide for Cisco Customer Journey Platform

BMC Remedyforce Integration with Bomgar Remote Support

CNS-207 Implementing Citrix NetScaler 10.5 for App and Desktop Solutions

DocAve 6 Control Panel

CCNA Security v2.0 Chapter 9 Exam Answers

Reference Guide. Service Pack 3 Cumulative Update 2. Revision J Issued October DocAve 6: Control Panel

iallworx User s Guide

TDR and Kaspersky. Integration Guide

SDMS Training Parnter Support Portal Manual Version 1.0

DB2 10 for z/os System Administration. Day(s): 5. Overview

CCNA 1 Chapter v5.1 Answers 100%

Troubleshooting Citrix- Published Resources Configuration in VMware Identity Manager

FedVTE Training Advisor Guide

WinEst 15.2 Installation Guide

VISITSCOTLAND - TOURS MANAGEMENT SYSTEM Manual for Tour Operators

SMART Room System for Microsoft Lync. Software configuration guide

How to Be Found on LinkedIn

Knowledge Exchange (KE) System Cyber Security Plan

Essentials for IBM Cognos BI (V10.2) Day(s): 5. Overview

Token Guide for RB-1. with. BlackShield ID. Copyright 2009 CRYPTOCard Inc.

BlackBerry Server Installation and Upgrade Service

Transcription:

Web Applicatin Security Versin 13.0 Training Curse SecureSphere Web Applicatin Security Versin 13.0 Required Training Units: 4 (TR-UNIT) Training Units are gd fr 1 year frm the time f purchase. Length: 4 Days Overview In this 4-day hands-n curse, students will learn: Hw t cnfigure SecureSphere fr an n premises Web Applicatin Firewall including ThreatRadar subscriptin services. Hw t evaluate the cnfiguratin f the Web Applicatin Firewall t ensure it is mnitring prtected assets yu have identified. Hw t implement detectin and prtectin cntrls using Plicies and Fllwed Actins Hw t cnfigure Web Prfiling. Hw t analyze Vilatins and Alerts. Hw t perfrm best practice tuning tasks. Hw t cnfigure Active Blcking and errr pages. Hw t integrate external web scanner data with SecureSphere and manage identified vulnerabilities. Hw and why t cnfigure SecureSphere Web Gateway t wrk in a Reverse Prxy deplyment mde. On the final day f class, students will perfrm a capstne exercise t reinfrce their understanding and ability t apply the cncepts learned during class. Wh Shuld Attend This curse is intended fr security administratrs, security analysts,security engineers, and Web applicatin develpers wh are respnsible fr securing and mnitring Web applicatins with SecureSphere. Prerequisites Befre taking this curse, yu shuld have the fllwing skills: General understanding f applicatin layer security cncepts, applicatin layer Web, and/r database prtcls. Basic understanding f HTML and HTTP. URLs, Parameters, headers, methds, HTTP server respnse cdes, etc. Experience implementing r managing data center security r database applicatins.

Lessn Objectives Lessn 1: Lab Envirnment and SecureSphere Web UI Review the SecureSphere Architecture Becme familiar with the presentatin f the training materials. Learn t use the Imperva training prtal t find supplemental curse materials. Becme familiar with the lab envirnment, tplgy, and user accunts. Becme familiar with the SecureSphere Web UI s majr cmpnents and navigating the Web UI. Lessn 2: Initial Web UI Cnfiguratin Set passwrd strength requirements. Enable users t enter cmments when making changes t security plicies. Create SecureSphere user accunts and rles. Cnfigure Active Directry authenticatin. Update ADC cntent. Lessn 3: Sites Tree Cnfiguratin Create a Site. Create a Server Grup. Create a Service and default Applicatin. Discver and secure previusly unknwn servers n the netwrk. Add discvered servers t a Site. Lessn 4: HTTP Service Cnfiguratin Cnfigure Frwarded Cnnectins (Lad Balanced Traffic) Install Prtected Web Servers SSL Keys Cnfigure Data Masking Cnfigure Web Errr Pages Lessn 5: HTTP Applicatin Cnfiguratin Create and Cnfigure Web Applicatins as needed. Direct HTTP client traffic t the apprpriate Web Applicatin. Adjust initial learning threshlds s that SecureSphere mre accurately prfile web traffic. Lessn 6: Actins Define, cmpare, and cntrast Actin Interfaces, Actin Sets, and Fllwed Actins. Explain placehlders, and where t find cmplete details regarding them. Create Email, FTP, Syslg, etc., Actin Interfaces as needed. Create Email, FTP, Syslg, etc., Actin Sets as needed. Use Fllwed Actins t implement Actin Sets n system administratin jbs.

Lessn 7: Security Plicies Given different types f Web attacks, cnfigure apprpriate plices t defend Web applicatins. Implement Fllwed Actins in Security Plicies. Cnfigure and apply: Signature plicies t defend Web applicatins frm attacks with easily recgnizable signatures. Prtcl plicies t defend Web applicatins frm prtcl attacks. Crrelatin plicies t prtect against multi-frnt Web attacks. Custm Web plicies t prtect specific applicatin weaknesses. Explain the factrs that determine when t use mdify a built-in plicy, and when t create a cpy f a built-in plicy and mdify it instead. Lessn 8: Web Applicatin Prfiling Describe the cmpnents f the Web Applicatin Prfile. Explain hw the Web Applicatin Prfile learns and prtects web applicatins. Define and explain hw applicatin activity is mapped t the prfile applicatin mapping. Identify cmmn web applicatin cmpnents used in the learning prcess. Define and explain hw web applicatin user tracking perates. Explain hw t select Web Prfile Plicy rules fr the prtected web applicatin. Lessn 9: ThreatRadar Identify and cnfigure apprpriate ThreatRadar feeds t help secure web applicatins. Identify when t use and hw t cnfigure TR Reputatin Services. Identify when t use and hw t cnfigure ThreatRadar Bt Prtectin. Identify when t use and hw t cnfigure Intelligence (Cmmunity Defense). Lessn 10: Alerts and Vilatins Use the Mnitring Dashbard t view a summary f current Vilatins and Alerts. Perfrm detailed analysis f Alerts and Vilatins t identify false psitives, attacks, and tuning pprtunities. Use the Add as Exceptin and add t prfile buttns t tune plicies and prfiles. Manage the wrkflw f Security Mnitring by using SecureSphere s Alert Flags. Lessn 11: Reprting Describe the features f SecureSphere s Reprt Settings. Describe hw t wrk with reprt Keywrds. Create reprts f varius types, including System Events, Cnfiguratin, and Alerts reprts. Schedule Reprts and the Reprts Archive jb. Create security-fcused reprts, such as Daily r Weekly Tp 10 Alert reprts. Lessn 12: Web Applicatin Security Tuning Use Reprts t identify where t tune SecureSphere.

Use the Prfile Optimizatin Wizard t help tune Prfiles. Explain the impact and trade-ffs f varius Prfile tuning ptins. Examine multiple ways t tune Security Plicies. Lessn 13: Active Blcking Cnfigure SecureSphere t enfrce the tuned cnfiguratin. Mve SecureSphere frm Simulatin t Active Blcking mde. Verify the nn-default errr page is wrking. Identify and manage Fllwed Actin Blck events. Cnfigure additinal Web Errr Page Grups as needed. Lessn 14: Reverse Prxy Select the apprpriate reverse prxy mde based n deplyment requirements fr URL rewriting, ckie signing, SSL terminatin, and/r respnse rewriting. Cnfigure Reverse Prxy mde settings. Cnfigure and apply SSL Cipher Suites t inbund and utbund prxy rules. Create and cnfigure default and custm web errr pages fr use in security plicies. Cnfigure URL rewrite and redirectin rules. Cnfigure SecureSphere t wrk with SSL Client Certificates. Lessn 15: End f Class Capstne Exercise The Capstne Exercise challenges students t perfrm a series f tasks designed t help students reinfrce learning by recalling and applying the cncepts and skills presented during the class. Tasks include: Cnfigure a Site Hierarchy t prtect a Web Applicatin. Mask sensitive data, such as credit card numbers, s they are nt expsed. Cnfigure SecureSphere s Web Applicatin prfiles and map web traffic t apprpriate Web Applicatins. Cnfigure SecureSphere t prperly supprt and inspect traffic that is lad balanced r prxied befre reaching the prtected web servers. Autmate and archive regular SecureSphere system backups. Cnfigure SecureSphere t prtect web servers against data leakage. Cnfigure SecureSphere t share infrmatin with external mnitring servers, such as a syslg server. Perfrm Security Tuning t ptimize SecureSphere s cnfiguratin. Create a variety f reprts. Find and prtect unexpected / rgue servers n the netwrk.

Getting Started Delivery Optins Open Classrm Virtual Classrm Private On-site Instructr-Led, in persn classes hsted at an Imperva training facility. Class includes: Electrnic Training Material Sandbx fr hands-n labs Instructr-Led, yu attend class via web cnferencing. Class includes: Electrnic Training Materials Sandbx fr hands-n labs Instructr-Led, in persn classes hsted at yur facility fr 6 t 12 participants. (purchase TR-4-DAY- ONSITE-6 fr 6 participants) Class includes: Electrnic Training Materials Sandbx fr hands-n labs Hw t Purchase Purchase Training Units via Purchase Order Cntact yur lcal Imperva sales representative r cntact yur lcal Imperva partner fr training unit price qute and t submit a Purchase Order fr training units. Yu will receive an Imperva SRV# fr use in class enrllment. If yu d nt have a sales cntact, please call 1-866-926-4678, r cmplete ur infrmatin frm. Purchase Classes via Credit Card Training can be purchased using a majr credit card, during the curse enrllment prcess. Hw t Enrll IMPORTANT: Only individuals with an Imperva prtal accunt username and passwrd can enrll in classes. If yu d nt have a Custmer r Partner prtal accunt, yu may request ne frm ur site. If yu need assistance with the accunt request, cntact supprt@imperva.cm. T enrll, have yur prtal username and passwrd available, visit the Imperva Training website and register fr yur class frm the Training Calendar. Select either Credit Card r Training Units (Purchase Order) as yur payment ptin. If yu select Training Units, yu may be asked t enter an Imperva SRV# (received when Purchase Order is finalized). Nte: Cmpany PO#s are nt accepted fr payment during class enrllment prcess. Schedule If yu purchased nsite training and wuld like t schedule delivery, please call us at +1-972-887-5922 r email training@imperva.cm Please refer t Imperva Terms and Cnditins when registering fr training fr additinal infrmatin. 2017 Imperva, Inc. All rights reserved. Imperva, the Imperva lg, SecureSphere and Incapsula are trademarks f Imperva, Inc. and its subsidiaries. All ther brand r prduct names are trademarks r registered trademarks f their respective hlders. Tech-Name-Date-rev#