Incident Response and Security Operations Center (SOC) Operations

Online price: SAR 2596

Offline Price: SAR 4096

Course Duration: 5 Day PM6 To PM10

Duration (Hrs) 20 Hours/Hours

Course date (1): 13/12/2026

Buy course from below.

Course Description

A practical program integrating Security Operations Center (SOC) operations with cyber incident response from detection through containment, recovery, and improvement. It covers monitoring, alerting, analysis, triage, escalation, log and evidence management, response-team coordination, and incident communications. The course also addresses operating procedures, incident classification, decision documentation, post-incident reviews, and lessons learned. It aims to improve SOC and response-team effectiveness while reducing detection and response time.

Course Objectives

  • Understand SOC roles and operating tiers.
  • Recognize security log and alert sources.
  • Analyze and prioritize alerts.
  • Apply the incident response lifecycle.
  • Collect and preserve evidence appropriately.
  • Perform containment, eradication, and recovery actions.
  • Develop response playbooks and scenarios.
  • Prepare incident reports and lessons learned.

Course Content

  • SOC structure and roles
  • Logs and telemetry sources
  • SIEM fundamentals
  • Alert triage
  • Incident classification and severity
  • Incident response lifecycle
  • Initial analysis and validation
  • Evidence and chain of custody
  • Containment
  • Eradication and recovery
  • Playbooks and use cases
  • Escalation and communication
  • Documentation and reporting
  • Post-incident review
  • Simulation exercises

Target Audience

SOC analysts, cybersecurity and incident response teams, network/system administrators, and security monitoring staff.

Duration

5 training days

Share this page