LABSEC-2852 - Unified Endpoint Security: Cisco Secure Client & XDR Lab
Proctors | Paul Carco None |
This lab focuses on securing the endpoint, providing hands-on experience with the following Cisco security products: • Cisco Secure Client – Formerly AnyConnect, Cisco Secure Client 5.x unifies security functionalities, integrating Cisco Secure Endpoint (AMP) into its UI as a new module. In this lab, we will also deploy the Network Visibility Module (NVM) to send traffic data to Cisco Secure Cloud Analytics (SCA). • Cisco Secure Client + Secure Endpoint Orbital – We will enable Host Firewall and Remote Scripts, two newer features of Cisco Secure Endpoint (CSE). Additionally, Orbital Queries will be performed to enhance endpoint visibility. • XDR (Extended Detection & Response) – Using Client Management in XDR, we will build Cisco Secure Client deployments that include: o AnyConnect VPN Module o DART (Diagnostic and Reporting Tool) o Cisco Secure Endpoint o Cisco Orbital, assigned via Secure Endpoint Policy. o Cisco XDR NVM • Cisco Secure Cloud Analytics (SCA) – Linked to XDR organizations in the lab, SCA will receive flow data from Cisco Secure Client's Network Visibility Module (NVM) for advanced network traffic analysis.