
Certified SOC Analyst (C|SA)
Course Description
SOC Analyst (C|SA)
Course Code: C|SA 101 — Security Operations Center Analyst
The Certified SOC Analyst (C|SA) program provides the foundational and advanced skills required
to monitor, detect, analyze, and respond to security incidents within a Security Operations Center (SOC).
Developed by leading cybersecurity experts, this intensive course delivers both theory and
hands-on training through real-world SOC simulations.
Over the span of three days, participants will gain a deep understanding of SOC architecture,
log management, SIEM deployment, incident detection, and response coordination.
Students will also learn how to collaborate effectively with Computer Security Incident Response Teams (CSIRT)
and enhance their organization’s ability to detect and respond to evolving cyber threats.
specialists looking to gain practical SOC experience and certification for entry-level or mid-level cybersecurity roles.
What You’ll Learn
- Core functions and structure of a Security Operations Center (SOC)
- Log management, correlation, and analysis techniques
- Deployment and configuration of Security Information and Event Management (SIEM) tools
- Incident detection and triage using real-world attack scenarios
- Threat intelligence, indicators of compromise (IOCs), and correlation rules
- Incident response lifecycle and communication best practices
- Collaboration with CSIRT and cross-functional response teams
Topics Covered
- SIEM concepts: data ingestion, correlation, and visualization
- Security monitoring and alert tuning to reduce false positives
- Intrusion detection and log analysis (firewalls, IDS/IPS, EDR)
- Malware behavior and attack pattern recognition
- Incident escalation, playbooks, and response automation
- Threat hunting methodologies and continuous improvement
Format & Materials
- Intensive 3-day instructor-led training with hands-on labs
- Virtual SOC lab access for live simulation of detection and response activities
- Guided exercises, SIEM dashboards, and reporting templates
Prerequisites
- Basic understanding of networking and cybersecurity concepts
- Completion of Cybersecurity Fundamentals (CIS 101) recommended
Outcomes & Next Steps
- Perform real-time security monitoring and incident detection
- Analyze logs, events, and alerts using SIEM tools and methodologies
- Apply structured incident response workflows and communication techniques
- Prepare for the Certified SOC Analyst (C|SA) certification exam
- Advance toward roles such as Security Analyst, Incident Responder, or Threat Hunter
Course Info
- Start Course: Weekly
- Duration: 5 days
- Prerequisites: No