Skip to content
Getting Digital

Cybersecurity

Security operations

Security operations never closes: it is a standing team, fed by logs from every system, deciding many times a day whether what it has just seen is an attack. Many first security jobs begin here, and the work is judged less by the tools it buys than by how quickly and calmly it separates a real signal from the noise around it.

Why this topic exists: Monitoring, detection and the SOC are the largest Security+ domain (28 %) and the whole of SC-200 and CySA+: SIEM, logging, alert triage, threat hunting.

Security operations gathers evidence of what is happening across an organisation's systems, turns some of it into alerts, and decides which alerts are real. The team doing this is usually called a security operations centre, whether it sits in one room, spans several time zones or is bought in from a managed provider. Its central instrument is a SIEM, a searchable store of logs with rules that flag suspicious patterns; SIEM products such as Splunk or Microsoft Sentinel are the names that recur in job adverts.

An alert, from arrival to verdict

  1. Collection. Logs arrive from identity providers, endpoints, firewalls, cloud control planes and applications. Nothing uncollected can be detected, and data collected without a purpose costs money while burying the rest.
  2. Detection. Rules, correlations and behavioural analytics raise an alert when events match a pattern. Writing and tuning those rules is detection engineering, a specialism in its own right.
  3. Triage. An analyst decides within minutes whether the alert is noise, a harmless oddity or worth escalating, using context: whose account, which device, what else happened around the same time.
  4. Investigation. A confirmed case is scoped: what did the intruder touch, and are they still present? Here the work hands over to incident response.
  5. Improvement. Every false positive is a rule to tune and every missed attack a gap to close. Threat hunting, the deliberate search for intruders no rule has caught, feeds this last step.

Security+ gives operations its largest domain, and two specialist exams live entirely here. CySA+ covers monitoring, detection, response and the vulnerability management that fills quieter days, and it assumes several years of analyst experience. Microsoft's SC-200 tests the same work on one vendor's stack and expects fluency in its query language. The free Defender XDR applied skill is a practical assessment, a reasonable way to show an employer you have worked an incident end to end in a lab.

Alert fatigue is a design flaw, not a character flaw

Beginners imagine the job as spotting clever intruders. Most of it is managing volume. A fresh SIEM with default rules produces far more alerts than any team can read, analysts learn to close them on reflex, and the genuine intrusion gets closed along with everything else. What marks out a good analyst is knowing what normal looks like for a particular user or server, which is why people arriving from system administration often overtake those who arrive from courses alone. Learn one log source deeply, such as sign-in events from an identity provider, before learning a dozen shallowly.

Next steps from here

Incident response and forensics picks up where triage ends, and vulnerability management is the planned, non-urgent half of operations; both sit beneath this topic in the silo. Anyone heading for a SOC should also know the attacker's side well enough to recognise it, which is the ground threats and attacks covers.

Within this topic

Concepts to know

Glossary entries with the reason each one matters here.

  • SOC

    The team and the room the topic describes.

  • SIEM

    The system a SOC analyst spends the day in.

  • IDS/IPS

    Alerts are where the SOC's work begins.

Certifications that test it

Vendor exams and free certificates; facts, cost and the preparation path are on each page, and the certifications hub has them all.

Tools of the trade

Frequently asked

Is a SOC analyst post a good first security job?
For many people it is the most realistic one. Entry-level analyst roles exist in larger numbers than most other security jobs, and the work teaches how attacks look in real data. Expect shifts, repetitive triage at first, and fast learning if you ask why each alert fired.
CySA+ or SC-200: which should I take?
SC-200 if your employer, or the one you want, runs Microsoft's security stack, since it tests those products directly. CySA+ if you want a vendor-neutral credential that also covers vulnerability management. Many analysts eventually hold both.
Do I need to learn a query language?
Yes. Every SIEM is searched with one, whether that is KQL, SPL or a SQL dialect, and the analyst who can write a precise query in two minutes resolves cases the others escalate. Learn one well; the others then take days rather than months.

Courses in the directory

31 courses are filed here; the top 6 by our ranking, details and the provider link on each course page.

Browse the directory shelf

Last reviewed 26 September 2026 · Getting Digital