CertClue
Courses · Security
SOC Analyst Tier 2 / Incident Responder

SOC Analyst Tier 2 / Incident Responder

Own a real intrusion from a wrongly closed alert to the review: reopen Tier 1's call, contain within your authority, scope and time-line the attack, preserve evidence in order, brief the data protection officer, recover cleanly and fix the detection that missed it.
2 hrs taught · 6 to 10 hrs applied 7 modules 20 lessons 4 portfolio artifacts Completion certificate Updated September 2026
Created by the CertClue team
What you'll build

Real portfolio pieces built during the course, not a certificate for its own sake. Each one is work you can show.

  • Incident timeline and scopeThe intrusion in order, from delivery to the third machine: how the attacker got in, who received and opened the message, which machines reached the attacker, what has been contained, and what was missed.
  • Evidence registerEverything collected from the attacker's base machine, in order of volatility, each item with where it came from, how it was collected, its hash and every hand-over.
  • Breach briefing for the data protection officerA one-page briefing that gives the data protection officer what they need to decide about reporting: what data, whose, when it left, when it was confirmed, the deadline and what is contained.
  • Post-incident reportThe incident written up for the IT director: what happened, what was lost, why it lasted as long as it did, and the actions that stop it happening again, each with an owner, a date and a check.

What you'll learn

From the queue to the incident
The job, decoded
A day in the seat
The rhythm of the job
Into the simulation: the Ardenmoor intrusion
Building the portfolio
What comes next

Course content · 7 modules, 20 lessons

Sign up to unlock every lesson - the titles below show exactly what is inside.

What changes when you move from working alerts to owning incidents: the frameworks, the severity scale and the limits of your authority.

From Tier 1 to Tier 2
Incident response frameworks
Severity and authority

Requirements

  • Comfortable with the fundamentals this course's own Module 1 covers, or equivalent experience.
  • No prior experience in this field is required to start.
  • A computer with a reliable internet connection.
  • Comfortable using a web browser - no software to install.

Description

Every CertClue course follows the same seven-part shape: fundamentals, the role translated out of job-posting language, a real working day, the job's recurring rhythms, a multi-day simulation, the portfolio you build along the way, and a handoff into your next move. Here is what that looks like for soc analyst tier 2 / incident responder.

Who this course is for

Anyone aiming to become a soc analyst tier 2 / incident responder, including career changers with no background in it yet. This is the entry rung of a realistic ladder:

entry
SOC Analyst (Tier 1)

Works the alert queue on a shift: triages, closes what is benign with a reason, and escalates what is not with the evidence attached.

Alert triageLog readingPhishing analysisEscalation with evidence
mid
SOC Analyst (Tier 2) / Incident Responder

Takes escalations and reviews Tier 1's closures, owns incidents end to end within a written authority, preserves evidence, briefs decision-makers, and turns each incident into a better detection.

Incident ownershipScoping and timelinesContainment decisionsEvidence handlingDetection engineering
senior
Incident Response Lead / SOC Manager

Runs major incidents and the team that handles them: sets playbooks and authority, decides severity and escalation, and reports to the board.

Incident commandPlaybooks and readinessThreat hunting programmesLeading analysts

Where it leads

This course prepares you for the CompTIA CySA+ role or credential path. Named for preparation only - no partnership or endorsement is implied.

Reviews

No reviews yet. Reviews come from learners who have taken the course, so this stays empty until someone leaves one.

Sign in to leave a review.

Students also explore