Palo Alto Authorized Global Training Partner Logo

Cortex XSIAM Training

Security Operations and Automation
(EDU-270)

!! Legacy Course !!

Palo Alto Networks Authorized Global Training Partner Logo

Award-winning live online course

Experienced Instructor

Virtual Lab Access

Video Recordings

Important Update: Cortex XSIAM: Security Operations and Automation (EDU-270) Course Retirement

Effective May 30, 2025, the “Cortex XSIAM for Security Operations and Automation” (EDU-270) course has been retired.

To better reflect the evolving roles within the Security Operations Centre (SOC) and the latest capabilities of Cortex XSIAM, Palo Alto Networks has introduced an updated training programme, splitting the former EDU-270 content into two distinct, role-based courses:

 

New Courses

  1. Cortex XSIAM: Security Operations, Integration, and Automation (3-day course, recommended for XSIAM Engineers)
    This course is the direct successor for engineers previously taking EDU-270. It focuses on configuring Cortex XSIAM, managing integrations, data ingestion, and automation workflows.
    If your role centres on implementing, integrating, and automating Cortex XSIAM, this is the course for you.
  2. Cortex XSIAM: Investigation and Analysis (2-day course, recommended for XSIAM Analysts)
    Tailored for analysts, this course covers the use of Cortex XSIAM for investigating incidents and alerts.
    If your daily work involves incident response and threat analysis using Cortex XSIAM, you’ll find all the tools and techniques you need here.

Which course should I take?

Why the change?
This split ensures deeper, role-based expertise and allows customers to focus on the skills most relevant to their job function. Think of it as less “one-size-fits-all” and more “tailor-made to fit you.”

 

For more details on these new courses and to find the best fit for your needs, please contact us.

What you’ll learn

The Palo Alto Networks Cortex XSIAM: Security Operations and Automation (EDU-270) course is an instructor-led training that will help you to:

  • Deploy, configure, and install XDR agents and configure Agent Groups and profiles
  • Investigate incidents, examine assets and artifacts, and understand the causality chain
  • Create correlation rules, use XQL to query logs, and analyze incidents using available tools and resources

The course is designed to enable cybersecurity professionals, particularly those in SOC/CERT/CSIRT and Security Engineering roles, to use Cortex XSIAM.

 

The course reviews XSIAM intricacies, from fundamental components to advanced strategies and automation techniques, including skills needed to navigate incident handling, optimize log sources, and orchestrate cybersecurity excellence.

 

Please see the course content for the detailed agenda.

Best Practices & Real Life Experience

​Let the Experience and Passion of our instructor guide you – Consigas is an Authorized Global Training Partner and was recognised with the “Excellence in Training Award” in 2022, 2019 and 2016 by Palo Alto Networks. The difference is made by our instructors, who have many years of field experience, which they bring with them into the classroom.

Certification

The Cortex XSIAM Security Operations and Automation (PAN EDU 270) course covers all the content required for the Palo Alto Networks Certified Security Operations Generalist and the Cortex XSIAM Analyst.

Palo Alto Networks requires students to take the exam at a Pearson Vue test centre or via Online Proctoring.

Video Recordings

Recognizing that retention is a challenge in learning, we record our sessions. This allows you to review the training material at your own pace, ensuring better understanding and recall.

Lab Access

You will have access to your own dedicated lab for practical exercises as described in the lab guide. The lab consists of a dedicated Windows VM, a Next-Generation FireWall and a Broker VM as well as access to a shared Cortex XSIAM instance. The lab is available 24h during the week of training, so you can also use it after class for additional practice.

Scope

  • Level: Introductory
  • Duration: 4 days (delivered over four full-day sessions – see class schedule)
  • Format: Instructor-led lectures and hands-on labs delivered either as live online training or a presential classroom course
  • Platform support: Cortex

Target Audience

SOC/CERT/CSIRT/XSIAM engineers and managers, MSSPs and service delivery partners/system integrators, internal and external professional-services consultants and sales engineers, incident responders and threat hunters.

Prerequisites

No previous Palo Alto Networks experience is required to take this Cortex XSIAM EDU 270 Palo Alto course while familiarity with enterprise product deployment, networking, and security concepts is recommended.

FAQ

Can I take the course online?
Yes, we are offering all courses as instructor-led online training. Students join a web meeting (Zoom), which the instructor uses to explain all the topics using the official Palo Alto Networks training slides and a lot of whiteboarding and live demos. In addition, students have access to their own dedicated lab to put the theory into practice. We have been running Palo Alto Networks courses online since 2013, and with this, our instructors have gained a lot of experience in delivering virtual classes.

 

Do you offer classroom training?
Yes, we offer classroom training as public classes in our own facilities or dedicated training at the customer’s premises. Please check the availability of public classroom courses under “Price and Dates” or request a quote for dedicated on-site training.

 

Will I receive an official coursebook?
Yes, you will receive the official Palo Alto Networks coursebook. It includes all the slides and a more detailed description of the topic shown in the slide. We will also record the training, and the instructor will share the videos and the whiteboard drawings that he presented during class. The coursebook is provided as an OnSecure Secure eBook.

 

Can I print the electronic coursebook?
Yes, Palo Alto Networks allows printing the electronic coursebook via the eBook reader.

 

Will I receive an official certificate of completion?
Yes, you will be able to download an official certificate of completion from Palo Alto Networks Learning Platform Beacon after attending the course.

“Students Love Our Instructors”

Palo Alto Training Excellence Award
Palo Alto Networks Online Training

Experience & Passion

The difference is made by our instructors who have many years of field experience which they bring with them into the classroom

Palo Alto Authorized Global Training Partner Logo

Top Companies choose Consigas to build in-demand firewall skills

Top Companies choose Consigas to build in-demand firewall skills