CySA+ / SOC Analyst Blue Team Course

0 of 18 lessons complete (0%)

The SOC and the Analyst

How a Security Operations Centre Works

This is a preview lesson

Register or sign in to take this lesson.

A SOC is the team, tooling and process that watches an organisation’s systems for attacks and responds when they happen. Before any tool or technique, an analyst needs to understand how the operation fits together and where they sit in it.

The pipeline

Telemetry flows from endpoints, networks, identity systems and cloud into a central platform. Detections run against it and produce alerts. Analysts triage alerts, escalate real incidents, and feed what they learn back into better detections. Everything the SOC does is a loop around that pipeline.

Tiers and roles

First-tier analysts triage and handle known patterns fast. Second-tier analysts investigate deeper and handle incidents. Detection engineers build the rules. Threat hunters look for what the rules miss. Small SOCs combine these in a few people; the functions still exist.

How the SOC is measured

Time to detect, time to triage, time to contain, alert volume and the false-positive rate. A good analyst improves all of these, not just their own ticket count.

Action Step

Draw the pipeline for a SOC you know or a hypothetical one: sources, platform, detections, triage, escalation and the feedback loop. Label where each role sits.

Educational and defensive only. Techniques are taught for detection and response on systems you are authorised to protect; unauthorised access to any system is illegal. This course is independent — not affiliated with, endorsed by or accredited by CompTIA or any vendor; issues no credential; contains no exam content or exam figures. Trademarks are used for identification only.