<?xml version="1.0" encoding="utf-8" ?>
<!DOCTYPE FL_Course SYSTEM "https://www.flane.de/dtd/fl_course095.dtd"><?xml-stylesheet type="text/xsl" href="https://portal.flane.ch/css/xml-course.xsl"?><course productid="37263" language="en" source="https://portal.flane.ch/swisscom/en/xml-course/fortinet-ndr-ca" lastchanged="2026-08-07T02:17:45+02:00" parent="https://portal.flane.ch/swisscom/en/xml-courses"><title>FortiNDR Cloud Analyst</title><productcode>NDR-CA</productcode><vendorcode>FO</vendorcode><vendorname>Fortinet</vendorname><fullproductcode>FO-NDR-CA</fullproductcode><version>26</version><objective>&lt;p&gt;After completing this course, you should be able to:
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Describe FortiNDR Cloud architecture&lt;/li&gt;&lt;li&gt;Navigate the FortiNDR Cloud portal&lt;/li&gt;&lt;li&gt;Identify the sensor types&lt;/li&gt;&lt;li&gt;Describe metadata production&lt;/li&gt;&lt;li&gt;Describe event types and fields&lt;/li&gt;&lt;li&gt;Describe core IQL concepts&lt;/li&gt;&lt;li&gt;Describe detections&lt;/li&gt;&lt;li&gt;Explain behavioral observations&lt;/li&gt;&lt;li&gt;Describe how to write a query&lt;/li&gt;&lt;li&gt;Describe how to tune a detector&lt;/li&gt;&lt;li&gt;Describe investigations&lt;/li&gt;&lt;li&gt;Identify supported integrations&lt;/li&gt;&lt;li&gt;Describe the essentials solution pack&lt;/li&gt;&lt;li&gt;Explain the Fortinet Automation Service benefits&lt;/li&gt;&lt;li&gt;Explain threat hunting concepts&lt;/li&gt;&lt;/ul&gt;</objective><essentials>&lt;p&gt;You must have knowledge of networking, cybersecurity, and SOC concepts.&lt;/p&gt;</essentials><audience>&lt;p&gt;Security professionals involved in the day-to-day management and monitoring of FortiNDR Cloud should attend this course.&lt;/p&gt;</audience><outline>&lt;ul&gt;
&lt;li&gt;Introduction&lt;/li&gt;&lt;li&gt;Sensors&lt;/li&gt;&lt;li&gt;Events&lt;/li&gt;&lt;li&gt;Internal Query Language&lt;/li&gt;&lt;li&gt;Detections&lt;/li&gt;&lt;li&gt;Creating Decetors&lt;/li&gt;&lt;li&gt;Investigations&lt;/li&gt;&lt;li&gt;Integrations&lt;/li&gt;&lt;li&gt;Threat Hunting Supplement&lt;/li&gt;&lt;/ul&gt;</outline><objective_plain>After completing this course, you should be able to:



- Describe FortiNDR Cloud architecture
- Navigate the FortiNDR Cloud portal
- Identify the sensor types
- Describe metadata production
- Describe event types and fields
- Describe core IQL concepts
- Describe detections
- Explain behavioral observations
- Describe how to write a query
- Describe how to tune a detector
- Describe investigations
- Identify supported integrations
- Describe the essentials solution pack
- Explain the Fortinet Automation Service benefits
- Explain threat hunting concepts</objective_plain><essentials_plain>You must have knowledge of networking, cybersecurity, and SOC concepts.</essentials_plain><audience_plain>Security professionals involved in the day-to-day management and monitoring of FortiNDR Cloud should attend this course.</audience_plain><outline_plain>- Introduction
- Sensors
- Events
- Internal Query Language
- Detections
- Creating Decetors
- Investigations
- Integrations
- Threat Hunting Supplement</outline_plain><duration unit="d" days="2">2 days</duration><pricelist/><miles/></course>