- Describe the capabilities and components of these APIs
o Cisco Cloud Security APIs (such as Umbrella APIs, Investigate APIs)
o Cisco Secure Endpoint (formerly AMP for Endpoints) API
o Cisco Secure Malware Analytics (formerly ThreatGRID) API
o Cisco XDR solution APIs (such as SecureX API and Threat Response API)
- Construct an Umbrella Investigate API request
- Construct Cisco Secure Endpoint API requests for event, computer, and policies
- Construct Cisco Secure Malware Analytics API request for search, sample feeds, IoC feeds, and threat disposition
- Construct Cisco XDR solution API calls
- Describe the orchestration capabilities of Cisco XDR solution