Cybersecurity
Security operations
Security operations never closes: it is a standing team, fed by logs from every system, deciding many times a day whether what it has just seen is an attack. Many first security jobs begin here, and the work is judged less by the tools it buys than by how quickly and calmly it separates a real signal from the noise around it.
Why this topic exists: Monitoring, detection and the SOC are the largest Security+ domain (28 %) and the whole of SC-200 and CySA+: SIEM, logging, alert triage, threat hunting.
Security operations gathers evidence of what is happening across an organisation's systems, turns some of it into alerts, and decides which alerts are real. The team doing this is usually called a security operations centre, whether it sits in one room, spans several time zones or is bought in from a managed provider. Its central instrument is a SIEM, a searchable store of logs with rules that flag suspicious patterns; SIEM products such as Splunk or Microsoft Sentinel are the names that recur in job adverts.
An alert, from arrival to verdict
- Collection. Logs arrive from identity providers, endpoints, firewalls, cloud control planes and applications. Nothing uncollected can be detected, and data collected without a purpose costs money while burying the rest.
- Detection. Rules, correlations and behavioural analytics raise an alert when events match a pattern. Writing and tuning those rules is detection engineering, a specialism in its own right.
- Triage. An analyst decides within minutes whether the alert is noise, a harmless oddity or worth escalating, using context: whose account, which device, what else happened around the same time.
- Investigation. A confirmed case is scoped: what did the intruder touch, and are they still present? Here the work hands over to incident response.
- Improvement. Every false positive is a rule to tune and every missed attack a gap to close. Threat hunting, the deliberate search for intruders no rule has caught, feeds this last step.
Security+ gives operations its largest domain, and two specialist exams live entirely here. CySA+ covers monitoring, detection, response and the vulnerability management that fills quieter days, and it assumes several years of analyst experience. Microsoft's SC-200 tests the same work on one vendor's stack and expects fluency in its query language. The free Defender XDR applied skill is a practical assessment, a reasonable way to show an employer you have worked an incident end to end in a lab.
Alert fatigue is a design flaw, not a character flaw
Beginners imagine the job as spotting clever intruders. Most of it is managing volume. A fresh SIEM with default rules produces far more alerts than any team can read, analysts learn to close them on reflex, and the genuine intrusion gets closed along with everything else. What marks out a good analyst is knowing what normal looks like for a particular user or server, which is why people arriving from system administration often overtake those who arrive from courses alone. Learn one log source deeply, such as sign-in events from an identity provider, before learning a dozen shallowly.
Next steps from here
Incident response and forensics picks up where triage ends, and vulnerability management is the planned, non-urgent half of operations; both sit beneath this topic in the silo. Anyone heading for a SOC should also know the attacker's side well enough to recognise it, which is the ground threats and attacks covers.
Within this topic
- Incident response and forensicsWhat happens after detection has its own standard (NIST SP 800-61), its own NICE work roles (Incident Response and Digital Forensics under Protection and Defense, evidence work under Investigation) and its own exams (CySA+, CHFI): containment, eradication, recovery, evidence.
- Vulnerability managementFinding, rating (CVSS) and fixing weaknesses is a continuous programme, separate from testing them: scanners, patch cycles, exceptions (CySA+; SAMM Defect Management).
- Security fundamentalsEvery blueprint opens here: the CIA triad, control types and the threat, vulnerability and risk vocabulary (SY0-701 General Security Concepts, 12 %; CISSP domain 1).
- Network securityFirewalls, segmentation, IDS/IPS, VPNs and zero trust are where most defensive work starts (CISSP Communication and Network Security, 13 %; Network+ and CCNA security domains).
- Identity and access managementWho may do what is its own discipline with its own exam (SC-300) and a full CISSP domain (13 %): authentication, MFA, SSO, directories and least privilege.
- CryptographyEncryption, hashing, keys and PKI underlie every other topic; the exams test them as applied choices, not maths (CISSP Security Architecture and Engineering; SY0-701 domain 1).
- Threats and attacksThe second-largest Security+ domain (Threats, Vulnerabilities and Mitigations, 22 %; only Security Operations weighs more): malware, phishing, social engineering, ransomware and the attack techniques defenders must recognise.
- Penetration testing and ethical hackingAuthorised attack as a profession: scoping, reconnaissance, exploitation, reporting (PTES; PenTest+ and CEH). Also the most-searched security topic on the course side.
- Governance, risk and compliancePolicies, risk assessment, frameworks (NIST CSF, ISO 27001) and audit are the management half of the field: CISSP domain 1 (16 %), CISM, CISA, Security+ Program Management (20 %).
- Application securityA large share of breaches begins in software: secure design, secure build, security testing and the OWASP Top 10 (OWASP SAMM; CISSP Software Development Security, 10 %).
- Cloud securityShared responsibility, cloud identity and posture management are tested in every cloud exam (SAA-C03 Design Secure Architectures, 30 %) and in SC-900; the cloud silo owns the platforms, this topic owns the defence.
- Security awareness for everyoneMost incidents start with a person, not a port: what every employee and freelancer must know about phishing, passwords, MFA, backups and updates (NICE Oversight and Governance; the management side of every blueprint).
Concepts to know
Glossary entries with the reason each one matters here.
Certifications that test it
Vendor exams and free certificates; facts, cost and the preparation path are on each page, and the certifications hub has them all.
- Microsoft · SC-200Microsoft Certified: Security Operations Analyst AssociateThe security operations analyst exam.
- CompTIA · CS0-004CompTIA CySA+Detection and monitoring analysis.
- CompTIA · SY0-701CompTIA Security+Security operations is its largest domain.
- Microsoft · Lab-based assessment · freeMicrosoft Applied Skills: Defend against cyberthreats with Microsoft Defender XDRA free lab-based credential in a real SOC tool.
Tools of the trade
- Splunk
The SIEM many SOCs run.
- Microsoft Sentinel and Defender
Microsoft's SIEM and XDR.
Frequently asked
- Is a SOC analyst post a good first security job?
- For many people it is the most realistic one. Entry-level analyst roles exist in larger numbers than most other security jobs, and the work teaches how attacks look in real data. Expect shifts, repetitive triage at first, and fast learning if you ask why each alert fired.
- CySA+ or SC-200: which should I take?
- SC-200 if your employer, or the one you want, runs Microsoft's security stack, since it tests those products directly. CySA+ if you want a vendor-neutral credential that also covers vulnerability management. Many analysts eventually hold both.
- Do I need to learn a query language?
- Yes. Every SIEM is searched with one, whether that is KQL, SPL or a SQL dialect, and the analyst who can write a precise query in two minutes resolves cases the others escalate. Learn one well; the others then take days rather than months.
Courses in the directory
31 courses are filed here; the top 6 by our ranking, details and the provider link on each course page.
Last reviewed 26 September 2026 · Getting Digital
