EC-Council Certified SOC Analyst® (CSA®)

What you'll learn
On this accelerated EC-Council Certified SOC Analyst (CSA) course, you'll learn to identify, monitor and analyse cyber-attacks, and use the information to quickly respond to security incidents.
In just 2 days, you'll build the skill-set you need to work effectively within a security operations centre (SOC). You'll also learn about security information and event management (SIEM), deployment and architecture.
At the end of your course, you'll sit Exam 312-39 and return to the office an EC-Council Certified SOC Analyst (CSA).
On this accelerated course, you'll learn how to:
- Recognise attacker tools, behaviours, tools and procedures
- Use the Centralised Log Management (CLM) process
- Make use of constantly changing threat information
If you're an aspiring SOC analyst or already are one at a Tier 1 and Tier 2 level, this course is ideal for you.
This course is also designed for security professionals who handle and manage network security operations, like network and security administrators or engineers, or network security operators.
You’ll train at twice the speed with Firebrand's unique Lecture | Lab | Review methodology. Learn in a distraction-free environment and become an EC-Council Certified SOC Analyst (CSA) in just 2 days.
Curriculum
34 modulesModule 1: Security operations and management
- Understand the SOC Fundamentals
- Discuss the components of SOC: People, processes and technology
- Understand the implementation of SOC
Module 2: Understanding cyber threats, IoCs, and attack methodology
- 2.1 Describe the term cyber threats and attacks
- 2.2 Understand the Network Level attacks
- 2.3 Understand the Host Level attacks
- 2.4 Understand the Application Level attacks
- 2.5 Understand the Indicators of Compromise (IoCs)
- 2.6 Discuss the attacker's Hacking Methodology
Module 3: Incidents, events and logging
- 3.1 Understand the fundamentals of incidents, events, and logging
- 3.2 Explain the concepts of local logging
- 3.3 Explain the concepts of centralised logging
Module 4: Incident detection with Security Information and Event Management (SIEM)
- 4.1 Understand the basic concepts of Security Information and Event Management (SIEM)
- 4.2 Discuss the different SIEM Solutions
- 4.3 Understand the SIEM Deployment
- 4.4 Learn different use case examples for Application Level Incident Detection
- 4.5 Learn different use case examples for Insider Incident Detection
- 4.6 Learn different use case examples for Network Level Incident Detection
- 4.7 Learn different use case examples for Host Level Incident Detection
- 4.8 Learn different use case examples for Compliance
- 4.9 Understand the concept of handling alert triaging and analysis
Module 5: Enhanced incident detection with threat intelligence
- 5.1 Learn fundamental concepts on threat intelligence
- 5.2 Learn different types of threat intelligence
- 5.3 Understand how threat intelligence strategy is developed
- 5.4 Learn different threat intelligence sources from which intelligence can be obtained
- 5.5 Learn different Threat Intelligence Platform (TIP)
- 5.6 Understand the need of threat intelligence-driven SOC
Module 6: Incident response
- 6.1 Understand the fundamental concepts of incident response
- 6.2 Learn various phases in Incident Response Process
- 6.3 Learn how to respond to Network Security Incidents
- 6.4 Learn how to respond to Application Security Incidents
- 6.5 Learn how to respond to Email Security Incidents
- 6.6 Learn how to respond to Insider Incidents
- 6.7 Learn how to respond to Malware Incidents
Prerequisites
Before attending this accelerated course, you should have 1 year of work experience in network admin or security.
Exam info
You'll sit the following exam at the Firebrand Training centre, covered by your Certification Guarantee:
- EC-Council Certified SOC Analyst (CSA) - Exam 312-39
- Exam format: Multiple-choice
- Exam duration: 120 minutes
- Number of questions: 100
- Passing score: 70%
- Language: English
- Domains:
- 1: Security operations and management (5%)
- 2: Understanding cyber threats, IoCs, and attack methodology (11%)
- 3: Incidents, events and logging (21%)
- 4: Incident detection with Security Information and Event Management (SIEM) (26%)
- 5: Enhanced incident detection with threat intelligence (8%)
- 6: Incident response (29%)
Course Dates
Sorry, there are currently no dates available for this course. Please submit an enquiry and one of our team will contact you about potential future dates or alternative options.
FAQs
4 questionYes, we do provide courses suitable for beginners. However, Firebrand's accelerated courses aren't easy and it's essential that you are interested and actively pursuing a career in IT.
Traditional training providers usually run their courses from 9am to 5pm. At Firebrand Training we maximise the number of learning hours to minimise the number of training days, so you’ll be back to your job as quickly as possible. You don’t waste time travelling to several courses and finding an exam centre after that.
Firebrand's accelerated courses are constantly reviewed. We ask our delegates for feedback after every course. We are official partners with leading vendors and therefore, we're provided with certification changes and updates, which we can then implement in our course delivery at a very early stage. This feedback is then analysed in view of changes or discrepancies. We will then address the topics mentioned and have a panel of subject matter experts provide us with valuable suggestions for improvement and solutions.
If you need to learn new skills and you want to be able to put them into practice quickly, then Firebrand is the right training company for you.
Our unique accelerated training method means that we are your fastest way to learn. By delivering training for up to 12 hours per day, seven days per week, with exam centres on-site, we ensure that you are trained and certified quicker than anywhere else, having spent less time out of the office away from the day job.
Can't find the answer you're looking for?
Our expert learning advisors are ready to help. Whether you need course recommendations, have technical queries, or want to discuss your learning goals, we're just a message away.
Related courses
All EC-Council Courses
Train your team
Since 2001 we've trained 134,561 employees from thousands of large and small organisations, saving them more than one million hours in training time.
Learn More