SOC Analyst Tier 2 / Incident Responder
Real portfolio pieces built during the course, not a certificate for its own sake. Each one is work you can show.
- Incident timeline and scopeThe intrusion in order, from delivery to the third machine: how the attacker got in, who received and opened the message, which machines reached the attacker, what has been contained, and what was missed.
- Evidence registerEverything collected from the attacker's base machine, in order of volatility, each item with where it came from, how it was collected, its hash and every hand-over.
- Breach briefing for the data protection officerA one-page briefing that gives the data protection officer what they need to decide about reporting: what data, whose, when it left, when it was confirmed, the deadline and what is contained.
- Post-incident reportThe incident written up for the IT director: what happened, what was lost, why it lasted as long as it did, and the actions that stop it happening again, each with an owner, a date and a check.
What you'll learn
Course content · 7 modules, 20 lessons
Sign up to unlock every lesson - the titles below show exactly what is inside.
What changes when you move from working alerts to owning incidents: the frameworks, the severity scale and the limits of your authority.
Requirements
- Comfortable with the fundamentals this course's own Module 1 covers, or equivalent experience.
- No prior experience in this field is required to start.
- A computer with a reliable internet connection.
- Comfortable using a web browser - no software to install.
Description
Every CertClue course follows the same seven-part shape: fundamentals, the role translated out of job-posting language, a real working day, the job's recurring rhythms, a multi-day simulation, the portfolio you build along the way, and a handoff into your next move. Here is what that looks like for soc analyst tier 2 / incident responder.
Who this course is for
Anyone aiming to become a soc analyst tier 2 / incident responder, including career changers with no background in it yet. This is the entry rung of a realistic ladder:
Works the alert queue on a shift: triages, closes what is benign with a reason, and escalates what is not with the evidence attached.
Takes escalations and reviews Tier 1's closures, owns incidents end to end within a written authority, preserves evidence, briefs decision-makers, and turns each incident into a better detection.
Runs major incidents and the team that handles them: sets playbooks and authority, decides severity and escalation, and reports to the board.
Where it leads
This course prepares you for the CompTIA CySA+ role or credential path. Named for preparation only - no partnership or endorsement is implied.
No reviews yet. Reviews come from learners who have taken the course, so this stays empty until someone leaves one.
Sign in to leave a review.



