This website uses cookies. By clicking Accept, you consent to the use of cookies. Click Here to learn more about how we use cookies.
Accept
Reject

NetWitness Community

  • Home
  • Products
    • NetWitness Platform
      • Advisories
      • Documentation
        • Platform Documentation
        • Known Issues
        • Security Fixes
        • Hardware Documentation
        • Threat Content
        • Unified Data Model
        • Videos
      • Downloads
      • Integrations
      • Knowledge Base
    • NetWitness Cloud SIEM
      • Advisories
      • Documentation
      • Knowledge Base
    • NetWitness Detect AI
      • Advisories
      • Documentation
      • Knowledge Base
    • NetWitness Investigator
    • NetWitness Orchestrator
      • Advisories
      • Documentation
      • Knowledge Base
      • Legacy NetWitness Orchestrator
        • Advisories
        • Documentation
  • Community
    • Blog
    • Discussions
    • Events
    • Idea Exchange
  • Support
    • Case Portal
      • Create New Case
      • View My Cases
      • View My Team's Cases
    • Community Support
      • Getting Started
      • News & Announcements
      • Community Support Forum
      • Community Support Articles
    • Product Life Cycle
    • Support Information
    • General Security Advisories
  • Training
    • Blog
    • Certification Program
    • Course Catalog
      • Netwitness XDR
      • EC-Council Training
    • New Product Readiness
    • On-Demand Subscriptions
    • Student Resources
    • Upcoming Events
    • Role-Based Training
  • Technology Partners
  • Trust Center
Sign InRegister Now
cancel
Turn on suggestions
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
Showing results for 
Search instead for 
Did you mean: 
NetWitness Education Blog
cancel
Turn on suggestions
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
Showing results for 
Search instead for 
Did you mean: 
  • NetWitness Community
  • NetWitness Education
  • NetWitness Education Blog
  • NetWitness Education - Specialist Analyst Certification

NetWitness Education - Specialist Analyst Certification

JorgeMares
Occasional Contributor JorgeMares Occasional Contributor
Occasional Contributor
Options
  • Subscribe to RSS Feed
  • Mark as New
  • Mark as Read
  • Bookmark
  • Subscribe
  • Printer Friendly Page
  • Report Inappropriate Content
‎2022-07-03 04:33 PM

Netwitness-Education-2C.png

 

 

NW-XDR-Specialist-Analyst.png

 

The NetWitness Specialist Analyst certification reflects the fundamental knowledge required of security analysts performing incident response and analysis with the NetWitness Platform. The prerequisite for this certification is the NetWitness Certified Associate certification.

 

$110 USD ⁓ 110 Training Credits

Who should take the exam

Examination Domains

SKU: ED-NW-CERT

Domains Detail

Taking the exam

Exam Registration
for Customers/Partners

Exam Registration
for NetWitness Employees

 

 

 Who Should Take the Exam

 

Anyone with at least two years experience as an analyst using the NetWitness Platform (recommended versions 11.5 or 11.6)

 

and/or

 

Anyone who has successfully completed and mastered the content in these NetWitness Education courses:

 

  • Introduction to NetWitness
  • NetWitness Platform Foundations
  • NetWitness Endpoint Foundations
  • NetWitness Platform Analysis
  • NetWitness Platform Intro to Hunting

Additional Recommended Background and Experience 

 

Certification candidates are most likely to pass with a minimum of two years of experience in at least one of the following technical areas:

Take FREE Practice Test
for Customers/Partners

Take FREE Practice Test
for NW Employees

 

  • Network operations
  • Information security analysis
  • Operating systems
  • IT administration

Go to top ⬆

 

 Examination Domains

 

The exam is comprised of several Domains or topical subject areas. Each Domain is represented by a series of questions designed to evaluate competence and knowledge of elements relating to that area. Exam questions for this certification include the following Domains:

 

Domain

% of Examination

Investigation

30%

Endpoint Investigation

20%

Hunting

20%

Incident Response

15%

NetWitness Metadata

15%

Total

100%

 

Go to top ⬆

 

 Domain Details

 

Investigation
Topics include the various techniques and tools used to investigate data in your organization.

 

Topic examples

  • Investigative tools
    • Navigate view
    • Events view
    • Queries
  • Optimizing investigation
    • Recommended methodology phases
    • Profiles
    • Enrichments for ESA alerts

 

Endpoint Investigation
Topics include the analysis tools provided by NetWitness Endpoint.

 

Topic examples

  • Endpoint interface
    • Risk score interpretation
    • Risk score resets
    • Reputations and signatures
  • Endpoint investigation tools
    • Application rules
    • Blacklisting and whitelisting
    • Image and kernel hook detection
    • MFT analysis
    • Endpoint memory dump

 

Hunting
Topics include the hunting tools provided by NetWitness Platform as well as recommended hunting methodologies and basic hunting terminology.

 

Topic examples

  • Hunting tools
    • Content Packs
    • Hunting Guide
    • Hunt Cards
    • Context Hub
  • Methodology and concepts for hunters
    • Recommended methodology phases
    • Traffic flow filtering
    • Investigation feed
    • WebShells

 

Incident Response
Topics include general Incident Response roles and processes.

 

Topic examples

  • Incident Response model
    • Typical roles
    • Model types
  • Recommended Incident Response processes
    • Prioritization of alerts (triage)
    • Incident creation and assignment
    • Add events to incident
    • Review incident metadata

 

NetWitness Metadata
Topics include characteristics of metadata in NetWitness, as well as hands-on metadata analysis techniques.

 

Topic examples

  • Characteristics of metadata in NetWitness
    • Definition of NetWitness metadata
    • Unified Data Model
    • NetWitness Investigation Model
  • Analysis techniques
    • Indicators of suspicious activity
    • Context-level meta keys
    • Network layer queries

 

Go to top ⬆

 

 Certification overview

 

Examination Preparation


Although NetWitness Platform product training is not a strict requirement in preparation for the exam, it is highly recommended you complete the courses listed.

 

For more about our NetWitness Platform course offerings, visit: https://community.netwitness.com/t5/netwitness-education-courses/tkb-p/netwitness-training

 

Exam Questions

The exam consists of 70 multiple choice questions to be completed in 85 minutes. One valid answer should be selected for each question. The exam is computer-based and closed book – you may not utilize any printed material, personal computers, calculators, cell phones, etc. during the test.

 

The minimum passing score is 70%. Test results are calculated automatically at the conclusion of the test and testing center personnel can often provide you with an authorized copy of your results before you leave the testing center.

 

Exam Costs
The fee for taking the exam is US$ 110.00.

 

Language Availability
NetWitness exams are available in North American English.

 

How is the testing conducted

Please be advise that we use the SABA Cloud testing platform to conduct the assessments. SABA uses remote proctoring technology to supervise the exam. 

 

This help us ensure integrity of the exam, for additional details click here.

 

Technical Instructions before starting the exam:  
  aymanm2_0-1660900804345.png Check your Internet Connectivity.
  aymanm2_0-1660900804345.png Use Mozilla Firefox or Google Chrome browser.
  aymanm2_0-1660900804345.png Clear your browser cache.
  aymanm2_0-1660900804345.png Your Device/Laptop/PC should have a webcam.
  aymanm2_0-1660900804345.png Allow Mic and Webcam access to browser.
  aymanm2_0-1660900804345.png Avoid using Multiple Screens
  aymanm2_0-1660900804345.png Avoid navigating to other browser tabs/windows

Proctoring2.png         permissions.png
 

Re-taking the Exam
There is no limit on the number of times that you can re-take the certification exam. However, to maintain integrity and confidentiality of the test items, 14 days is the required elapsed time before retaking the test a third time. Please note that you must pay the full exam fee each time that you retake the exam.

 

Exam Registration
for Customers/Partners

Exam Registration
for NetWitness Employees

 

 

Additional resources

 

  • Create a NW LMS account
  • View Course Catalog
  • Enterprise Training 
  • FAQ
  • Employee FAQ

Go to top ⬆

 

 

For additional questions please contacts us at education.support@netwitness.com 

Netwitness-Education-2C.png

 

1 Like
Share
1 Comment

You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.

  • Comment
Latest Articles
  • How to Redeem Your NetWitness Training Credits User Guide
  • NetWitness Education Certification Program User Guide
  • NetWitness Education Using Credit Card to Purchase Training User Guide
  • NetWitness Education Community User Guide
  • NetWitness Education Webinar User Guide
  • NetWitness Education - Customers Newsletter - Q423
  • NetWitness Education - Newsletter Q423
  • NetWitness Education - Customers NEWSLETTER - Q323
  • Netwitness Education - Platform 11.6: What's New
  • Netwitness Education - Become Certified
Labels
  • Announcements 2
  • Videos 62
Powered by Khoros
  • Blog
  • Events
  • Discussions
  • Idea Exchange
  • Knowledge Base
  • Case Portal
  • Community Support
  • Product Life Cycle
  • Support Information
  • About the Community
  • Terms & Conditions
  • Privacy Statement
  • Acceptable Use Policy
  • Employee Login
© 2022 RSA Security LLC or its affiliates. All rights reserved.