FAQ: SOC Fundamentals

This FAQ, collaboratively created by the community, addresses the contents of the course titled “SOC Fundamentals”.

This course includes these lessons:

  • Introduction to SOC
  • SOC Types and Roles
  • SOC Analyst and Their Responsibilities
  • SIEM and Analyst Relationship
  • Log Management
  • EDR - Endpoint Detection and Response
  • SOAR (Security Orchestration Automation and Response)
  • Threat Intelligence Feed
  • Common Mistakes made by SOC Analysts

You can locate this exercise within the LetsDefend content:

When you close an alert, which channel can you access it from?

Please, how do i answer the questions under EDR? i have use the practice feature but i can’t seems to expand it enough to be able to analyze the processes.

What is the type of log that has a destination port number of 52567 and a source IP address of 8.8.8.8?