Festival Season Offer15% off on all our programmes — claim it before you enrol
MODULE 3 OF 5  ·  30 Hrs  ·  3 Weeks

Inside a Security Operations Center

This module steps inside a real Security Operations Center — how it's structured and staffed, what each tier actually does, and how people, process and technology come together to run detection around the clock.

Who This Module Is For
Students who have completed the threat-landscape module and are ready to understand how a real SOC team operates day to day.
Real-World Relevance
Every SOC analyst job starts with understanding where you sit in the team — the tier structure, escalation paths and delivery model behind the role are exactly what interviewers probe for first.
Program OverviewView Hands-On Labs
Curriculum

What You Will Learn

A detailed, industry-aligned breakdown of every topic covered in this module.

  • What a SOC does, and why it matters
  • Key SOC functions: triage, investigation & hunting
  • How a SOC is structured and staffed
  • Key SOC roles and responsibilities
  • Modern-day SOCs: people, process & technology
  • SOC as a Service (SOCaaS) and delivery models
  • NOC vs. SOC — how the two teams differ
  • Cyber security monitoring essentials
Technology Stack

Tools You Will Use

Hands-on time with the same tools used in real Security Operations Centers today.

SIEM

Security Information & Event Management platform used to collect, correlate and analyse security events centrally.

NIDS / NIPS

Network intrusion detection and prevention systems used to spot and block malicious network activity.

SOAR

Security orchestration, automation and response tooling used to speed up triage and incident handling.

EDR / XDR

Endpoint and extended detection & response platforms used to monitor and contain threats on hosts.

DLP

Data Loss Prevention tooling used to detect and stop unauthorised movement of sensitive data.

IAM

Identity and Access Management systems used to control who can access what across the environment.

Firewalls

Network security devices used to enforce traffic rules and segment the environment.

Vuln. Mgmt

Vulnerability management tooling used to discover, prioritise and track security weaknesses.

Practical Work

Hands-On Labs

Production-style SOC lab scenarios, built using the same stack real security teams monitor with.

01

Map the structure, tiers and staffing model of a modern SOC.

02

Compare SOC-as-a-Service delivery models against an in-house SOC.

03

Distinguish NOC responsibilities from SOC responsibilities in a shared scenario.

04

Walk a sample alert through the Tier 1 to Tier 2 to Tier 3 escalation path.

05

Document the people, process and technology behind a SOC monitoring workflow.

Evaluation

Assessment

Knowledge Assessment

Quiz covering SOC structure, roles, the tier system and SOC vs. NOC responsibilities.

Practical Evaluation

Students must produce a SOC operating-model brief covering tiers, roles and escalation paths for a sample organisation.

Portfolio

Projects

Industry-style deliverables added directly to your project portfolio.

Portfolio Project 01

SOC Operating Model Brief

Document how a live SOC is staffed, tiered and structured, using a real-world case study.

Module Outcome

What This Module Builds

Students understand how a SOC is structured and staffed, and can explain the tools, roles and workflows that keep a security team running around the clock.

Maps to job roles
SOC Analyst (L1)Security Monitoring AnalystAlert Triage SpecialistIT Security Trainee

Continue building your SOC analyst portfolio

Next up: Module 4 — SIEM Platforms & Security Monitoring

Go to Module 4Full Roadmap