Security Operations
- System and network architecture in security operations: architecture components, identity concepts, logging; Zero Trust Network Access (ZTNA) and SASE, cloud and hybrid environments
- Analyse indicators of malicious activity in networks, on endpoints, in the cloud and in identity systems
- Detection tools: SIEM, EDR and XDR, packet analysis, threat intelligence platforms
- Threat intelligence and threat hunting: frameworks, data sources and methods
- Efficiency and process improvement: automation with SOAR, workflows, automated threat intelligence processes
- AI in security operations: use cases, risks and governance
Vulnerability Management
- Select and implement suitable scanning methods for systems, networks and applications
- Analyse results from vulnerability scans and assessment tools and classify security gaps
- Prioritise and remediate vulnerabilities based on risk: scoring systems such as EPSS, threat intelligence and business context
- Software supply chain and Software Bill of Materials (SBOM)
- Control types, policies, risks and compliance in vulnerability management
Incident Response and Incident Management
- Models for attack methods: MITRE ATT&CK and the Cyber Kill Chain
- The incident response process: preparation, detection, analysis, containment, eradication and recovery
- Incident handling techniques: triage, handling evidence, escalation, remediation and root cause analysis
Reporting and Communication
- Vulnerability management reports and dashboards, stakeholder communication and escalation for security events
- Incident documentation, post-incident reviews and metrics such as detection time, response time and remediation effectiveness