Week 1: The Cybersecurity Analyst and Security Operations
This part of the course introduces the cybersecurity analyst role, SOC workflows, governance, risk, and the CySA+ exam domains. Learners review security architecture across on-premises, cloud, hybrid, operational technology, and Zero Trust environments, and identify the telemetry required for effective monitoring and investigation.
Week 2: Security Monitoring, Logging and Data Analysis
This part of the course focuses on collecting, normalising, and analysing security data. It covers system and application logs, network traffic, identity events, cloud telemetry, data formats, and time synchronisation. Learners use security information and event management (SIEM) concepts to correlate events, investigate alerts, and distinguish normal activity from potential compromise.
Week 3: Threat Intelligence, Threat Hunting and Adversary Behaviour
This part of the course examines threat intelligence sources, indicators of compromise, adversary tactics, techniques, and procedures, and threat-modelling frameworks. Learners develop hypotheses, perform structured threat hunts, assess intelligence quality, and use behavioural evidence to identify suspicious activity.
Week 4: Detection and Analysis of Malicious Activity
This part of the course develops practical skills in analysing endpoint, network, email, web, identity, and cloud indicators. Learners interpret packet captures and logs, examine suspicious files and processes, and apply SIEM, endpoint detection and response (EDR), extended detection and response (XDR), and sandboxing concepts to validate and prioritise alerts.
Week 5: Vulnerability Discovery and Assessment
This part of the course introduces the vulnerability management lifecycle. It covers asset discovery, vulnerability scanning, configuration assessment, application and cloud testing, common scoring systems, scanner limitations, and the interpretation of technical findings. Learners perform controlled assessments and distinguish true positives, false positives, and environmental exceptions.
Week 6: Vulnerability Prioritisation and Remediation
This part of the course focuses on risk-based vulnerability analysis. Learners combine technical severity, threat intelligence, exploitability, asset criticality, exposure, and business impact to prioritise remediation. The week also covers compensating controls, patch and configuration management, validation, exception handling, and remediation tracking.
Week 7: Incident Response and Digital Investigation
This part of the course covers preparation, detection, analysis, containment, eradication, recovery, and post-incident activity. Learners practise triage, evidence preservation, timeline construction, scoping, escalation, and coordination while considering legal, regulatory, privacy, and business requirements.
Week 8: Response Automation, Cloud Security and AI in the SOC
This part of the course examines security orchestration, automation and response (SOAR), playbooks, scripting, APIs, and workflow optimisation. It also addresses cloud-native and hybrid security monitoring and the responsible use of AI for analysis, correlation, documentation, and automation, including risks such as data exposure, hallucination, model manipulation, and weak governance.
Week 9: Reporting, Communication and Security Metrics
This part of the course develops the communication skills required of a cybersecurity analyst. Learners produce vulnerability and incident reports for technical and non-technical stakeholders, define meaningful metrics and key performance indicators, document root causes and lessons learned, and communicate remediation priorities, risk, and escalation decisions.
Week 10: Integrated SOC Investigation and Exam Preparation
This part of the course integrates the four CySA+ domains through a realistic SOC case study. Learners analyse security telemetry, investigate malicious activity, prioritise vulnerabilities, recommend response actions, and present an evidence-based report. The course concludes with scenario-based revision, performance-based question practice, a mock examination, and guidance on cybersecurity analyst career pathways.