The follow-on from Foundations, and the closest thing in the catalogue to a real job simulation.
You will monitor a live-fire lab environment, triage alerts, investigate what happened, and write the report. Wrong conclusions get discussed rather than marked down — that is how analysts actually learn.
Maps to CompTIA CySA+ and Microsoft SC-200.
Jobs this leads towards
Real roles people do after this course and the ones that follow it.
-
SOC analyst
Sits in a security operations centre watching alerts, deciding what is real, and responding.
-
Incident responder
Called when something has gone wrong; works out what happened and stops it spreading.
-
Threat hunter
Looks for attackers who got in without setting off any alarm.
Certifications
What this course prepares you to sit. Exam vouchers are included.
- Microsoft SC-200 (Security Operations Analyst)
Is this for me?
Ninety seconds, no wrong answers, nothing recorded. It tells you how closely this course matches what you enjoy — and where to look if it does not.
Try it — two minutes
The kind of thing you would actually do in this course. Nothing is saved; it is just to see if you enjoy it.
What a week looks like
Day to day, so nobody is surprised.
- Two evenings a week: attacks explained, then defences built.
- A lab machine you are allowed to break into, and a defended one you have to protect.
- Real-world cases each week: what went wrong, what would have stopped it.
- Practice exams from halfway through.
Three questions from week one
Get them wrong and you belong here. Get them right and you belong here too. Nothing is recorded.
Books worth having
None of these is required — the course lends what it needs. These are the ones worth owning.
-
CompTIA Security+ Get Certified Get Ahead
Darril Gibson
Straight to the point and matched to the exam.
Find it ↗ -
Professor Messer's Security+ videos (free, YouTube)
Watch ahead of each class.
What to bring
Usually nothing. Where something small helps, it is here.
- ▸A laptop that can run a virtual machine (8 GB RAM or more; we lend them).
- ▸A hardware security key if you can (about $25) — you will use it for real.
- ▸A notebook for the things you would never type into a computer.
Do this at home
Between sessions. Ten to twenty minutes; the people who do this are the ones who finish.
- Habit 1Turn on two-factor authentication on every account you own. Every one.
- Habit 2Read one security news story a day and write down the mistake.
- Habit 3Run a password manager and move your accounts into it, five a day.
What you will be able to do
- Triage and prioritise a queue of security alerts
- Investigate an incident across endpoint, identity and network telemetry
- Distinguish a true positive from a noisy detection
- Write an incident report a manager can act on
- Tune detections to reduce false positives
What you will use
- Microsoft Sentinel
- Defender for Endpoint
- CrowdStrike Falcon
- KQL
What the course covers
The lesson plan for this course is being written. Register and we will tell you the moment it opens.