The Certified SOC Analyst (CSA) program is the first step to joining a security operations center (SOC). It is engineered for current and aspiring Tier I and Tier II SOC analysts to achieve proficiency in performing entry-level and intermediate-level operations.
CSA is a training and credentialing program that helps the candidate acquire trending and in-demand technical skills through instruction by some of the most experienced trainers in the industry. The program focuses on creating new career opportunities through extensive, meticulous knowledge with enhanced level capabilities for dynamically contributing to a SOC team. Being an intense 3-day program, it thoroughly covers the fundamentals of SOC operations, before relaying the knowledge of log management and correlation, SIEM deployment, advanced incident detection, and incident response. Additionally, the candidate will learn to manage various SOC processes and collaborate with CSIRT at the time of need.
A SOC team offers high-quality IT-security services to
detect potential cyber threats/attacks actively
and quickly respond to security incidents.
To handle sophisticated threats, enterprises need
advanced cyber security solutions
along with traditional methods of defense.
A SOC Analyst
continuously monitors and detects
potential threats, triages the alerts, and appropriately escalates them.
Organizations need
skilled SOC Analysts
who can serve as the front-line defenders, warning other professionals of emerging and present cyber threats.
CSA maps 100 percent to the National Initiative for Cybersecurity Education (NICE) framework under the “Protect and Defend (PR)” category for the role of Cyber Defense Analysis (CDA). It is designed as per the realtime job roles and responsibilities of a SOC analyst.
The CSA course trains the candidate to use various defensive measures and data collected from multiple sources to identify, analyze, and report events that might occur or are already present in the network to protect data, systems, and networks from threats.
CSA offers an insightful understanding of end-to-end SOC overflow. It includes all SOC procedures, technologies, and processes to collect, triage, report, respond, and document the incident.
Training on various use cases of SIEM (Security Information and Event Management) solutions to detect incidents through signature and anomaly-based detection technologies. Candidates will learn incident detection on different levels - Application level, Insider level, Network level, and Host level.
CSA covers a module dedicated to rapid incident detection with Threat Intelligence. The module also imparts knowledge on integrating Threat Intelligence feeds into SIEM for enhanced threat detection.
It covers 45 elaborated use cases which are widely used across all the SIEM deployments.
CSA being a practically-driven program, offers hands-on experience on incident monitoring, detection, triaging, and analysis. It also covers containment, eradication, recovery, and reporting of the security incidents. To that end, there are 80 tools incorporated into the training.
There are 22 labs in total in the CSA program, which demonstrates processes aligned to the SOC Workflow. These include, but are not restricted to, activities such as:
The CSA program comes with additional reference material, including a list of 291 common and specific use cases for ArcSight, Qradar, LogRhythm, and Splunk’s SIEM deployments.
24 hours - 2 classes per week
Graduate and one year of work experience in the Network Admin/Security.
Rs.25,500/-
+ 18% GST
Rs.35,500/-Rs.25,500/-
+ 18% GST
24 Hours
in-depth training by best faculties from cyber security industry
Study Materials
and examination voucher
CSA Certificate
of completion after examination and alumni status
Important Notice for International Students: The EC-Council global course fee and Exam Voucher fee will depend on the candidate's location and foreign currency exchange rate.
The CSA exam is designed to test and validate a candidate’s comprehensive understanding of the job tasks required as a SOC analyst. Thereby, validating their comprehensive understanding of a complete SOC workflow.
Fields marked with * are mandatory.
The Profiles that count for CSA Certified Individuals include the following:
SOC Analyst | Information Security Analyst | IT Security Analyst | Cyber Threat Analyst |
24 hours
Complete 12th board exam and basic networking knowledge or CCNA.
This certification program focuses on creating new career opportunities through extensive, meticulous knowledge with enhanced level capabilities for dynamically contributing to a SOC team.
You can apply to join a security operations center (SOC)