LABSEC-2852 - Unified Endpoint Security: Cisco Secure Client & XDR Lab
Proctors |
Paul Carco None |
This lab focuses on securing the endpoint, providing hands-on experience with the following Cisco security products:
• Cisco Secure Client – Formerly AnyConnect, Cisco Secure Client 5.x unifies security functionalities, integrating Cisco Secure Endpoint (AMP) into its UI as a new module. In this lab, we will also deploy the Network Visibility Module (NVM) to send traffic data to Cisco Secure Cloud Analytics (SCA).
• Cisco Secure Client + Secure Endpoint Orbital – We will enable Host Firewall and Remote Scripts, two newer features of Cisco Secure Endpoint (CSE). Additionally, Orbital Queries will be performed to enhance endpoint visibility.
• XDR (Extended Detection & Response) – Using Client Management in XDR, we will build Cisco Secure Client deployments that include:
o AnyConnect VPN Module
o DART (Diagnostic and Reporting Tool)
o Cisco Secure Endpoint
o Cisco Orbital, assigned via Secure Endpoint Policy.
o Cisco XDR NVM
• Cisco Secure Cloud Analytics (SCA) – Linked to XDR organizations in the lab, SCA will receive flow data from Cisco Secure Client's Network Visibility Module (NVM) for advanced network traffic analysis.