Course ID: #N/A

CyberSec First Responder – Threat Detection and Response (Exam CFR-310)

Duration: 5 days Dates: 14 December 2026 15 March 2027 28 June 2027 13 September 2027

This course covers the tasks of people responsible for monitoring and detecting security incidents in information systems and networks, and for responding appropriately to such incidents. Depending on the size of the organisation, this person works alone or is a member of a Cybersecurity Incident Response Team (CSIRT). The course introduces tools and tactics for managing cybersecurity risks, recognising various common types of threats, assessing the organisation's security, gathering and analysing cybersecurity information, and handling incidents as they occur. Ultimately, the course provides a comprehensive security approach for everyone on the front line of defence. This course helps participants prepare for the CyberSec First Responder™ certification exam (Exam CFR-310). What you learn and practise in this course can form a substantial part of your preparation.

1 – Assessing Information Security Risk

  • Topic A: Identifying the Importance of Risk Management
  • Topic B: Assessing Risk
  • Topic C: Mitigating Risk
  • Topic D: Integrating Documentation into Risk Management

2 – Analysing the Threat Landscape

  • Topic A: Classifying Threats and Threat Profiles
  • Topic B: Performing Ongoing Threat Research

3 – Analysing Reconnaissance Threats to Computer and Network Environments

  • Topic A: Implementing Threat Modelling
  • Topic B: Assessing the Impact of Reconnaissance
  • Topic C: Assessing the Impact of Social Engineering

4 – Analysing Attacks on Computer and Network Environments

  • Topic A: Assessing the Impact of System Hacking Attacks
  • Topic B: Assessing the Impact of Web-Based Attacks
  • Topic C: Assessing the Impact of Malware
  • Topic D: Assessing the Impact of Hijacking and Impersonation Attacks
  • Topic E: Assessing the Impact of DoS Incidents
  • Topic F: Assessing the Impact of Threats to Mobile Security
  • Topic G: Assessing the Impact of Threats to Cloud Security

5 – Analysing Post-Attack Techniques

  • Topic A: Assessing Command and Control Techniques
  • Topic B: Assessing Persistence Techniques
  • Topic C: Assessing Lateral Movement and Pivoting Techniques
  • Topic D: Assessing Data Exfiltration Techniques
  • Topic E: Assessing Anti-Forensics Techniques

6 – Managing Vulnerabilities in the Organisation

  • Topic A: Implementing a Vulnerability Management Plan
  • Topic B: Assessing Common Vulnerabilities
  • Topic C: Conducting Vulnerability Scans

7 – Implementing Penetration Testing to Assess Security

  • Topic A: Conducting Penetration Tests on Network Assets
  • Topic B: Following Up on Penetration Testing

8 – Collecting Cybersecurity Intelligence

  • Topic A: Deploying a Security Intelligence Collection and Analysis Platform
  • Topic B: Collecting Data from Network-Based Intelligence Sources
  • Topic C: Collecting Data from Host-Based Intelligence Sources

9 – Analysing Log Data

  • Topic A: Using Common Tools to Analyse Logs
  • Topic B: Using SIEM Tools for Analysis

10 – Performing Active Asset and Network Analysis

  • Topic A: Analysing Incidents with Windows-Based Tools
  • Topic B: Analysing Incidents with Linux-Based Tools
  • Topic C: Analysing Malware
  • Topic D: Analysing Indicators of Compromise (IoCs)

11 – Responding to Cybersecurity Incidents

  • Topic A: Deploying an Incident Handling and Response Architecture
  • Topic B: Containing and Mitigating Incidents
  • Topic C: Preparing for Forensic Investigation as a CSIRT

12 – Investigating Cybersecurity Incidents

  • Topic A: Applying a Forensic Investigation Plan
  • Topic B: Securely Collecting and Analysing Electronic Evidence
  • Topic C: Following Up on the Results of an Investigation

13 – Appendix A: Mapping Course Content to CyberSec First Responder™ (Exam CFR-310)

14 – Appendix B: Regular Expressions

15 – Appendix C: Security Resources

16 – Appendix D: U.S. Department of Defense Operational Security Practices

Learning Solution

Blended Learning, Firmenseminar, Individualcoaching, Klassenraumtraining, Online Live Webinar

Language

Deutsch, Englisch, Französisch, Italienisch

Dates

2026/12/14, 2027/03/15, 2027/06/28, 2027/09/13, flexibel, auf Anfrage

This course is primarily aimed at cybersecurity professionals whose task is to protect information systems by ensuring their availability, integrity, authentication, confidentiality and non-repudiation. The course focuses on the knowledge, skills and competencies required to defend these information systems in a cybersecurity context, including the processes for protection, detection, analysis, investigation and response. In addition, the course ensures that all members of an IT team – from helpdesk staff to the Chief Information Officer – understand their role in these security processes.

In this course, you will assess security threats, respond to them, and operate a platform for the security analysis of systems and networks.

  • Assessing information security risk in computer and network environments.
  • Analysing the threat landscape in cybersecurity.
  • Analysing reconnaissance threats to computer and network environments.
  • Analysing attacks on computer and network environments.
  • Analysing post-attack techniques on computer and network environments.
  • Implementing a vulnerability management programme.
  • Assessing the organisation’s security through penetration testing.
  • Collecting cybersecurity intelligence.
  • Analysing data from security and event logs.
  • Performing active analysis of assets and networks.
  • Responding to cybersecurity incidents.
  • Investigating cybersecurity incidents.

 

 

CHF3'250 excl. VAT

Clear

SIGN UP

Newsletter

Receive news about new courses, offers and promotions by email.

← Back

Thank you for your response. ✨

Email Subscription
Amazon
VMware and Virtualisation