The Qualys Certification and Training Center offers free training courses with hands-on labs featuring the latest Qualys Suite functionalities and best practices. Learners can access online certified courses, instructor-led training programs, and video libraries of multiple resources, making it flexible for online course seekers. These courses cover up-to-date training on essential security and compliance topics, allowing participants to gain practical experience and earn industry-recognized certifications.
Certified Courses
Qualys offers certified courses under different categories, as following -
Vulnerability Management Learning Path
- Vulnerability Management Foundation
This course introduces the fundamentals of vulnerability management, including defining vulnerabilities, setting scope, identifying options, and understanding network risk management.
USP: Covers best practices for effective vulnerability management and ensures a comprehensive understanding of VM solutions in network monitoring.
- VMDR with TruRisk
Focuses on organizing assets, running effective scans, and prioritizing remediation using TruRisk, along with generating reports and managing role-based access in Qualys VMDR.
USP: Provides hands-on experience with TruRisk for precise vulnerability prioritization and effective asset management.
- CyberSecurity Asset Management (CSAM)
A self-paced course that explores CSAM for data normalization, asset organization, external attack surface analysis, and dashboard creation.
USP: Offers detailed insights into CSAM application, including ServiceNow CMDB integration and asset lifecycle management.
- Scanning Strategies and Best Practices
Covers scanning techniques such as authenticated scanning, agentless tracking, scanner deployment, VLANs, firewalls, and continuous monitoring.
USP: Provides a deep dive into various scanning strategies, ensuring efficient and secure scanning across diverse IT environments.
- Reporting Strategies and Best Practices
Teaches best practices for data collection, maintaining data hygiene, and using Qualys tools for interactive reporting, including dashboards and templates.
USP: Emphasizes effective reporting strategies, including report scheduling, distribution, and vulnerability reporting for practical use cases.
- Patch Management
Introduces patch management concepts, including patch assessment, deployment, uninstallation, and asset management.
USP: Focuses on efficient patch deployment and management to enhance security posture through timely updates.
Policy Compliance Learning Path Courses
- Policy Compliance Foundation This course introduces IT Policy Compliance, its benefits, applicable standards, and best practices, emphasizing the importance of automation in achieving compliance.
USP: Ideal for beginners, offering a foundational understanding of IT policy standards and automation needs, with certification upon completion.
- Policy Compliance Covers policy compliance setup, control library, compliance scanning, reporting, and security assessment within Qualys.
USP: Provides hands-on training for managing and ensuring IT policy compliance using Qualys tools.
PCI Compliance Learning Path Courses
- PCI Compliance Foundation Explains PCI standards, associated risks for merchants, compliance tools, and steps for maintaining PCI DSS compliance.
USP: Essential for newcomers to PCI standards, covering key requirements and compliance steps with certification.
- PCI Compliance Focuses on PCI DSS basics, scope, scanning, reporting, web application scanning, and self-assessment within Qualys.
USP: Comprehensive training on PCI compliance processes using Qualys solutions.
Endpoint Detection and Response (EDR) Learning Path Courses
- Endpoint Detection and Response (EDR) Foundation
Covers endpoint security, malware threats, protection frameworks, and the need for EDR solutions.
USP: Beginner-friendly course offering foundational knowledge on endpoint security and threat response.
- Learn EDR Foundation Provides training on deploying Qualys EDR using Cloud Agents, investigating suspicious activities, and integrating with other Qualys applications.
USP: Offers practical EDR deployment and response training with cloud-based security enhancements.
Foundational Courses in Security and Compliance
- 1. Endpoint Detection and Response (EDR) Foundation
Introduces endpoint security, malware threats, and the importance of endpoint protection using available security frameworks and tools.
USP: Perfect for beginners, providing a comprehensive foundation in endpoint security with certification upon completion.
- Vulnerability Management Foundation:
Covers vulnerability definitions, management scope, network monitoring, risk identification, and best practices.
USP: Essential course for understanding the basics of vulnerability management, with practical insights into network security.
- Policy Compliance Foundation
Explains IT policy compliance, its benefits, relevant standards, best practices, and the need for automation.
USP: Provides foundational knowledge of policy compliance, ideal for newcomers seeking certification.
- PCI Compliance Foundation
Focuses on PCI standards, risks for merchants, PCI DSS requirements, compliance tools, and reporting.
USP: Offers a solid introduction to PCI compliance, ensuring beginners understand key standards and compliance steps.
Additional Certified Courses
Course Name |
USPs |
Administration |
Learn about subscription administration and using the Qualys Administration Utility. |
Qualys Flow (QFlow) |
Automate detection and remediation with no-code workflows using Qualys Flow. |
Custom Assessment and Remediation (CAR) |
Create reusable custom detections and remediations, including deploying custom configurations and applications. |
Endpoint Detection and Response |
Secure endpoints and hunt for malware with Qualys EDR. |
Qualys Query Language (QQL) |
Learn to build search queries to fetch information from Qualys databases using QQL. |
API Fundamentals |
Understand the basics of the Qualys API in Vulnerability Management. |
Cloud Agent |
Configure and deploy Cloud Agents for continuous monitoring and security. |
Container Security |
Explore core features and best practices for securing containers using Qualys. |
File Integrity Monitoring |
Log and track file changes across global IT systems for enhanced security. |
PCI Compliance |
Scan and assess assets for PCI Compliance using Qualys tools. |
Web Application Scanning |
Learn core features of Qualys Web Application Scanning to identify and mitigate vulnerabilities. |
Instructor-Led Training
Qualys also offers instructor-led training programs, which are usually 2-day long and are conducted entirely online on Zoom. These programs are covered on specific dates. For more details about the dates of the respective programs, we recommend you visit the course website.
The following are some of the topics covered under instructor-led training programs -
- Web Application Scanning
- Cloud Agent
- Unlock the Full Potential of Your Asset Tags
- Web Application Scanning
- Patch Management
- Vulnerability Management Detection and Response
- CyberSecurity Asset Management (CSAM)
- Policy Compliance
- TotalCloud
You would need to create a Qualys Training and Certification "learner" account. A Qualys trial account is NOT required to enrol to these instructor-led training programs.