SOC Analyst / Cybersecurity Analyst
Real portfolio pieces built during the course, not a certificate for its own sake. Each one is work you can show.
- Alert triage logA row per alert across the simulation week: what fired, which sources you checked and over what window, what you found in plain words, the classification, and the action taken or requested.
- Phishing analysis writeupOne page on a reported message: headers and sending infrastructure, why it was malicious and which evidence did not help, who else received and interacted with it, and what you did about the account behind it.
- Incident reportThe full write up of the intrusion on day four: summary for a manager, scope, a sourced timeline, observation kept separate from inference, containment with times and authorisation, impact, and owned actions.
- Escalation noteHalf a screen written under pressure: what you believe is happening and how confident you are, scope, evidence, what you already contained, what you have ruled out, and the decision you need.
- Detection tuning recommendationA one page argument with numbers: firing volume and classification split, the property behind the noise, a narrowly scoped change, what the rule still catches, the coverage lost and how it is covered instead, and a review date.
- Benign activity determinationThe closing writeup for a cluster of alerts that turned out to be authorised work: the account and the source host established from the underlying events, every event tied to one logon session, the change record read for what it omits, the engineer who confirmed it by name, and what would have made the same evidence an intrusion.
What you'll learn
Course content · 7 modules, 28 lessons
Sign up to unlock every lesson - the titles below show exactly what is inside.
Just enough to work a queue: what a SOC is for, what an alert actually is, where evidence lives, how you classify what you find, and the shapes of attack you are looking for.
Requirements
- No prior experience in this field is required to start.
- A computer with a reliable internet connection.
- Comfortable using a web browser - no software to install.
Description
Every CertClue course follows the same seven-part shape: fundamentals, the role translated out of job-posting language, a real working day, the job's recurring rhythms, a multi-day simulation, the portfolio you build along the way, and a handoff into your next move. Here is what that looks like for junior soc analyst.
Who this course is for
Anyone aiming to become a junior soc analyst, including career changers with no background in it yet. This is the entry rung of a realistic ladder:
Triages alerts, follows playbooks, and escalates confirmed incidents.
Investigates escalated incidents, tunes detection rules, and leads containment on confirmed threats.
Owns detection strategy across the SOC, and proactively hunts for threats not caught by existing rules.
Where it leads
This course prepares you for the CompTIA Security+, then CySA+ role or credential path. Named for preparation only - no partnership or endorsement is implied.
No reviews yet. Reviews come from learners who have taken the course, so this stays empty until someone leaves one.
Sign in to leave a review.



