Build the foundations
Review networks, operating systems, identity and common attack paths.
Turn alerts into evidence and a defensible response.
Review networks, operating systems, identity and common attack paths.
Build a legal defensive lab and collect endpoint, identity and network logs.
Investigate an alert, assess impact and document containment, recovery and evidence handling.
Write a concise incident report with detection improvements and communicate risk to a non-technical stakeholder.
Your checklist stays in this page session only. It is a self-check, not a skills assessment.
Pick one credential that matches the technology in your target vacancies. Check prerequisites and prove the skills with a project before booking.
For building a broad base of applied security knowledge.
Before booking: Build hands-on practice in the relevant job role; compare your experience with CompTIA’s recommendations.
A practical specialisation for SOC analysts investigating and responding to threats in Microsoft security tools.
Before booking: Build familiarity with security operations and Microsoft threat detection tools.
For analysts investigating and responding to security events.
Before booking: Build hands-on practice in the relevant job role; compare your experience with CompTIA’s recommendations.
Review the official source for fees, assessment format, prerequisites and award/renewal requirements. Guidance reviewed 13 September 2026.
Simulate a suspicious sign-in in an authorised lab and produce a triage timeline, detection query and response report.
Use these original practice scenarios to structure your answers. They are not leaked exam questions or an employer’s interview script.
A strong answer covers: Correlate identity, device, location and activity evidence; validate impact before taking proportionate action.
A strong answer covers: Consider exploitation, exposure, asset importance and compensating controls, then track remediation.