Skip to content
Register

cybersecurity

Security Operations

Work like a SOC analyst: monitoring, triage, investigation and reporting.

The follow-on from Foundations, and the closest thing in the catalogue to a real job simulation.

You will monitor a live-fire lab environment, triage alerts, investigate what happened, and write the report. Wrong conclusions get discussed rather than marked down — that is how analysts actually learn.

Maps to CompTIA CySA+ and Microsoft SC-200.

Jobs this leads towards

Real roles people do after this course and the ones that follow it.

  • SOC analyst

    Sits in a security operations centre watching alerts, deciding what is real, and responding.

  • Incident responder

    Called when something has gone wrong; works out what happened and stops it spreading.

  • Threat hunter

    Looks for attackers who got in without setting off any alarm.

Certifications

What this course prepares you to sit. Exam vouchers are included.

  • Microsoft SC-200 (Security Operations Analyst)

Is this for me?

Ninety seconds, no wrong answers, nothing recorded. It tells you how closely this course matches what you enjoy — and where to look if it does not.

Try it — two minutes

The kind of thing you would actually do in this course. Nothing is saved; it is just to see if you enjoy it.

What a week looks like

Day to day, so nobody is surprised.

  1. Two evenings a week: attacks explained, then defences built.
  2. A lab machine you are allowed to break into, and a defended one you have to protect.
  3. Real-world cases each week: what went wrong, what would have stopped it.
  4. Practice exams from halfway through.

Three questions from week one

Get them wrong and you belong here. Get them right and you belong here too. Nothing is recorded.

Books worth having

None of these is required — the course lends what it needs. These are the ones worth owning.

  • CompTIA Security+ Get Certified Get Ahead

    Darril Gibson

    Straight to the point and matched to the exam.

    Find it ↗
  • Professor Messer's Security+ videos (free, YouTube)

    Watch ahead of each class.

What to bring

Usually nothing. Where something small helps, it is here.

  • A laptop that can run a virtual machine (8 GB RAM or more; we lend them).
  • A hardware security key if you can (about $25) — you will use it for real.
  • A notebook for the things you would never type into a computer.

Do this at home

Between sessions. Ten to twenty minutes; the people who do this are the ones who finish.

  • Habit 1Turn on two-factor authentication on every account you own. Every one.
  • Habit 2Read one security news story a day and write down the mistake.
  • Habit 3Run a password manager and move your accounts into it, five a day.

What you will be able to do

  • Triage and prioritise a queue of security alerts
  • Investigate an incident across endpoint, identity and network telemetry
  • Distinguish a true positive from a noisy detection
  • Write an incident report a manager can act on
  • Tune detections to reduce false positives

What you will use

  • Microsoft Sentinel
  • Defender for Endpoint
  • CrowdStrike Falcon
  • KQL

What the course covers

The lesson plan for this course is being written. Register and we will tell you the moment it opens.