Incident Response & SOC Operations

Incident Response & SOC Operations

Course Description

This course provides hands-on training in threat detection, incident response, and compliance using Microsoft’s security tools, including Defender XDR, Sentinel, Entra ID, and Defender for Cloud. Learners will build practical skills in identity management, threat investigation, and regulatory alignment, guided by the NIST Cybersecurity Framework. Ideal for those entering or upskilling in SOC roles, the course combines real-world labs with exam-focused preparation to build operational security confidence. 

Course Objectives

  • Navigate Microsoft’s security and compliance tools, including Entra ID, Defender XDR, Sentinel, and Defender for Cloud. 
  • Configure and manage identity, access, and compliance controls using Conditional Access, MFA, RBAC, and DLP. 
  • Detect and investigate threats using Microsoft Sentinel and Kusto Query Language (KQL). 
  • Execute incident response workflows and automate remediation with Microsoft Defender tools and playbooks. 
  • Apply cloud security best practices to protect Azure workloads and hybrid environments. 
  • Align security operations with the NIST Cybersecurity Framework and practice real-world SOC tasks through labs and simulations 

Modules

Audience: SOC analysts, IT security professionals, and cybersecurity learners 

Pre-requisites 

  • Basic cybersecurity knowledge 
  • Familiarity with Microsoft cloud services is recommended 


Career Pathways: SOC Analyst, Security Operations Engineer, Cybersecurity Specialist 

Assessment

Certification

Dates:

Module Date Time Zone Duration (Days)
Content
Content
Content
Content
Content

Course Includes: