| Topic | Details |
| Topic 1 | - Threat Intelligence Management: This domain focuses on threat intelligence operations including indicator creation and configuration, indicator relationships, enrichment with source reliability, external intelligence sharing, and exclusion list management.
|
| Topic 2 | - Incident Interactions and Reporting: This domain covers incident operations including states and actions, War Room activities, incident relationships, and dashboard and report configuration for metrics and visualization.
|
| Topic 3 | - Planning, Installation, and Maintenance: This domain covers system setup and administration including authentication configuration, engine deployment, dev
- prod environment planning, Marketplace pack management, integration instance configuration, and system maintenance.
|
| Topic 4 | - Playbook Development: This domain addresses automation through playbook creation including task configuration, context data manipulation, various task types, sub-playbooks with looping, filters and transformers, debugger usage, built-ins and scripts, automation script creation, and job management.
|
| Topic 5 | - Use Case Planning and Development: This domain focuses on designing security use cases through incident and indicator lifecycle management, field and layout customization, classifier and mapper configuration, incident creation methods, pre
- post-processing, and incident type configuration with playbooks, layouts, SLAs, and lists.
|