...

Download Our Latest Course Catalog | Download Now

[woo_multi_currency_layout10]

Security Operations Architect

In this course, you will learn how to design, deploy, operate, and manage a Fortinet Security Operations Center using FortiSIEM and FortiSOAR. Through practical exercises, you will work with incident handling, threat hunting, and SOC playbooks. It’ll also include automation, FortiAI, data ingestion, security rules, containment, and recovery workflows.

Overview

Overview

The Security Operations Architect course provides the advanced knowledge required to design and operate a Fortinet SOC solution using FortiSIEM and FortiSOAR.

You will learn how to detect, investigate, and respond to security incidents using industry-aligned frameworks and incident-handling practices. The course covers attack surface analysis, common attack vectors, FortiSIEM rules, data ingestion, incident workflows, and threat-hunting processes.

In addition, you’ll explore FortiSOAR playbooks, connectors, indicator enrichment, containment, eradication, and recovery. The course also introduces FortiAI capabilities and explains how they support FortiSIEM and FortiSOAR workflows.

Prerequisites

To get the most out of this course, you should have:

  • An understanding of the topics covered in the FortiSIEM Analyst course
  • Equivalent hands-on experience working with FortiSIEM and SOC operations
Scope

Topics include:

  • SOC concepts and security frameworks
  • FortiSIEM and FortiSOAR architecture
  • Incident detection and handling
  • Data ingestion and FortiSIEM rules
  • SOC playbook development
  • Threat hunting
  • FortiAI capabilities
  • Containment, eradication, and recovery
Target Audience

Ideal for:

  • Security professionals designing Fortinet SOC solutions
  • SOC architects implementing FortiSIEM and FortiSOAR
  • Analysts responsible for incident detection and response
  • Security teams managing threat-hunting and automation workflows
  • Professionals monitoring and operating enterprise SOC environments
Best Practices

You will learn these skills as part of this course:

  • Applying recognized frameworks to analyze attacker behavior
  • Configuring reliable data ingestion and incident-detection rules
  • Building playbooks to automate incident enrichment and response
  • Using connectors to contain compromised users, devices, and hosts
  • Developing threat-hunting hypotheses using available security data
  • Managing incidents through containment, eradication, and recovery
Certification

After completing this course, you will be able to prepare for the Fortinet NSE 7 – Security Operations 7.6 Architect exam.

The exam evaluates your applied knowledge of how to design, deploy, operate, and manage a Fortinet SOC solution using FortiSIEM and FortiSOAR.

It covers SOC frameworks, incident analysis, FortiSIEM detection capabilities, FortiSOAR incident handling, threat hunting, playbook development, integrations, and troubleshooting.

FAQs

Q: Does this course cover both FortiSIEM and FortiSOAR?
A: Yes. You will learn how both products work together for incident detection, investigation, automation, and response.

Q: Are playbook development and automation included?
A: Yes. The course covers FortiSOAR playbook steps, connectors, indicator enrichment, containment actions, and playbook monitoring.

Q: Does the course include threat hunting?
A: Yes. You will learn how to develop hypotheses, configure data sources, analyze security data, and perform proactive and reactive threat hunting.

Exam Resources

Datasheet

Credits Guide

Credits Datasheet

Credits FAQ

Objectives

After completing this course, you should be able to:

  • Describe the main functions and roles within a Security Operations Center
  • Identify security challenges that can be addressed using the Fortinet SOC solution
  • Describe the MITRE ATT&CK Enterprise Matrix
  • Describe the Cyber Kill Chain
  • Explain how to identify and reduce the attack surface
  • Describe common attack vectors
  • Describe the benefits of using FortiSIEM and FortiSOAR
  • Describe different Fortinet SOC deployment architectures
  • Describe the FortiSOAR Content Hub and connectors
  • Describe FortiAI features
  • Explain how FortiAI is used in FortiSIEM and FortiSOAR
  • Describe reactive and proactive threat-hunting processes
  • Generate threat-hunting hypotheses
  • Identify and configure data sources
  • Configure data ingestion
  • Configure FortiSIEM rules
  • Execute attack vectors
  • Describe the NIST SP 800-61 incident-handling process
  • Describe the incident-handling workflow using FortiSIEM and FortiSOAR
  • Analyze, handle, and tune incidents in FortiSIEM
  • Ingest FortiSIEM incidents into FortiSOAR
  • Escalate FortiSOAR alerts into incidents
  • Describe security automation requirements
  • Describe FortiSOAR playbook steps
  • Run playbooks to enrich indicators
  • Configure a playbook to retrieve hash ratings from FortiSandbox
  • Perform containment on FortiGate using FortiSOAR connectors
  • Perform containment in Windows Active Directory using FortiSOAR connectors
  • Perform containment using FortiClient EMS and FortiSOAR connectors
  • Eradicate artifacts from a compromised host
  • Release a compromised host from quarantine after recovery
  • Manage FortiSOAR playbook history logs
Note : A representative from Datacipher will contact you with further details
Payment Methods

At DataCipher, we offer a variety of payment options for our Fortinet courses. Here are the methods available:

Purchase Order (PO) – If your organization prefers using a purchase order, begin the registration process by clicking the Register button. At the conclusion of the registration form, choose the option “My company will pay for it, please send an invoice with the payment details.” Our training team will then provide an official quote and any necessary additional information that your accounts department might need to issue the PO.

Bank Transfer – DataCipher maintains bank accounts in both the US and Europe, accommodating all standard bank transfer methods such as IBAN/BIC, Swift, ACH, or wire transfer. To make a payment via bank transfer, simply use the Register button to sign up for your selected course.

Credit Card Payments – We accept payments from all major credit cards, including Mastercard, VISA, American Express, Discover & Diners, and Cartes Bancaires. Payments can be made directly through the registration link or by requesting an invoice that includes a web link for online payment. All transactions are secure, and DataCipher does not store any credit card information.

These options are designed to make the registration process as smooth and flexible as possible for all participants.

Status

Guaranteed to Run – DataCipher is committed to running this class unless unforeseen events such as an instructor’s accident or illness occur.

Guaranteed on Next Booking – The course will proceed once an additional student registers.

Scheduled Class – We have scheduled this course and rarely cancel due to low enrollment. We offer a “Cancel No More Than Once” guarantee, ensuring that if a class is canceled due to insufficient enrollment, the next session will run regardless of the number of attendees.

Sold Out – If the class is fully booked, please use our contact form to join the waiting list or to inquire about additional sessions. We’re here to accommodate your training needs and keep you informed of new opportunities.

Half and Full-Day Training

At DataCipher, we offer our training courses in both traditional full-day and convenient half-day formats. Our half-day classes are specifically designed for IT professionals who cannot be away from their workplaces for consecutive full days. This flexible schedule allows participants to dedicate a few hours to learning and then return to their regular work responsibilities.

The curriculum for both the full-day and half-day formats is identical. The primary difference is that the half-day classes spread the coursework over a more extended period, providing a balanced approach to professional education. DataCipher has been successfully running these half-day training sessions for several years, receiving consistently positive feedback from our customers. They appreciate the flexibility and report that the extended timeframe facilitates a deeper understanding of the material, as it gives them more time to absorb and reflect on the information learned.

The Security Operations Architect course provides advanced, hands-on knowledge for designing and operating a Fortinet SOC using FortiSIEM and FortiSOAR.

You will work with incident detection, threat hunting, SOC playbooks, automation, FortiAI, containment, eradication, recovery, and incident-response workflows.

REQUEST CUSTOM DELIVERY

REQUEST a Quote

Become An Expert By Practice – Get Your Hands On Labs

Don’t let your tech outpace the skills of your people

TRUSTED BY TOP COMPANIES LIKE IBM, DELOITTE, ERICSSON, AND MORE.
DISCOVER OUR CUSTOMER PORTFOLIO.

Dedicated to excellence, we cultivate strong partnerships with worldwide technology innovators.

Testimonials

What Our Clients Say

You’re all set!

Thanks for registering. Our training team will be in touch soon to confirm your class schedule and help you get started.