Overview
Google, IBM & Meta Certificates – 40% Off
One Coursera Plus subscription covers most Professional Certificates on Coursera.
Unlock All Certificates
The Cybersecurity Operations Fundamentals Specialization gives you the basic skills you need to begin a career as an entry-level cybersecurity analyst. As you progress through this Specialization, you'll gain the foundational knowledge that organizations require to protect their network.
Completing this Specialization will prepare you to start your career as a Security Operations Center Analyst.
Previous IP networking knowledge is preferred.
Syllabus
- Course 1: Security Operations Center (SOC)
- Course 2: Endpoints and Systems
- Course 3: Network Security
- Course 4: Data Security
- Course 5: Threat Analysis
- Course 6: Threat Investigation
- Course 7: Threat Response
Courses
-
Encrypted traffic now dominates modern networks, and with more than 50 percent of internet traffic protected by TLS/SSL, SOC analysts need the skills to detect threats hidden inside that blind spot. This cybersecurity course teaches associate-level analysts how cryptography, encrypted network communication, and network security monitoring (NSM) intersect in real-world security operations. Designed for learners with CCNA-level networking knowledge, it covers the data that powers network security analysis, including session data, full packet capture, transaction data, extracted content, alert data, statistical data, and metadata. Learners explore how SIEM and SOAR platforms collect, prioritize, and report alarms, while also examining Cisco SecureX and the Security Onion toolset for practical security operations workflows. The course also explains PCAP storage requirements, packet capture investigation with tcpdump, and the importance of correlating NSM data during incident response. Unique differentiators include real-world examples such as SHA-1, plus coverage of privacy and compliance constraints tied to HIPAA, FISMA, PCI DSS, and Sarbanes-Oxley. Ideal for SOC analysts seeking stronger skills in cryptography, packet analysis, and encrypted traffic investigation.
-
Launch your cybersecurity training with a hands-on network security course that teaches how to secure enterprise networks, control access, and defend against real-world attacks. Designed for aspiring associate-level cybersecurity analysts and learners with CCNA-level knowledge, this program builds practical skills in infrastructure security, secure device access, and access control using standard and extended ACLs, including both numbered and named configurations. You’ll also learn control plane security with Control Plane Policing (CoPP) and get introduced to MQC for building CoPP policies on Cisco IOS. The course covers core network security technologies and protocols, including Authentication, Authorization, and Accounting (AAA), RADIUS, TACACS+, firewalls, IPS, and NAT, while explaining how AAA improve scalability, manageability, and control. A key differentiator is its dual perspective: you’ll study both defensive security and attacker techniques by examining TCP/IP vulnerabilities and common threats such as Man-in-the-Middle, spoofing, and Denial-of-Service attacks. By the end, learners will be prepared to monitor, analyze, and help defend networks in a Security Operations Center (SOC) environment.
-
The three most used endpoint operating systems are Windows, Linux, and Mac. When investigating security incidents, security analysts often encounter these operating systems running on servers or user end hosts. If you are an associate-level cybersecurity analyst who is working in security operation centers, this course will help you understand basic Windows operations principles. By the end of the course, you will be able to: •By the end of the course, you will be able to: • Describe the history of the Windows operating system and vulnerabilities. • Describe the Windows OS architecture and components. • Describe Windows processes, threads, and handles. • Describe virtual memory allocation in the Windows OS.• Describe Windows services and how they are used. • Describe the functionality of Windows NTFS. • Describe the Windows NTFS structure. • Describe Windows domains and local user accounts. • Describe the Windows graphical user interface and its use. • Describe how to perform tasks in Windows which may require administrator privileges.• Describe the Windows command line interface use and features. • Describe the features of the Windows PowerShell. • Describe how the net command is used for Windows administration and maintenance. •Describe how to control Windows startup services and execute a system shutdown. • Describe how to control Windows services and processes that are operating on a host. • Describe how to monitor Windows system resources with the use of Windows Task Manager. • Describe the Windows boot process, starting services, and registry entries. • Describe how to configure Windows networking properties. •Use the netstat command to view running networking functions. •Access Windows network resources and perform remote functions. •Describe the use of the Windows registry. •Describe how the Windows Event Viewer is used to browse and manage event logs. • Use the Windows Management Instrumentation to manage data and operations on Windows-based operating systems.• Understand common Windows server functions and features. • Describe commonly used third-party tools to manage to manage Windows operating systems. • Explore the Windows operating system and services. The knowledge and skills that students are expected to have before attending this course are: 1. Skills and knowledge equivalent to those learned in Implementing and Administering Cisco Solutions (CCNA) v1.0 course 2. Familiarity with Ethernet and TCP/IP networking 3. Working knowledge of the Windows and Linux operating systems 4. Familiarity with basics of networking security concepts.
-
Learn the core functions of a Security Operations Center (SOC) and elevate your incident response skills with our comprehensive analyst training program designed for associate-level professionals. This course provides the essential skills to protect organizational assets against sophisticated cyber-attacks by focusing on SIEM integration, incident response workflows, and advanced threat-hunting techniques. Designed for associate-level analysts, the curriculum addresses the challenge of managing high-volume data by teaching you to leverage workflow management systems and automation to reduce incident detection time. You will gain a deep understanding of SOC team roles, the business benefits of centralized monitoring, and the technical strategies required to balance proactive protection with operational agility. To succeed, participants should possess CCNA-level networking knowledge, familiarity with TCP/IP, and foundational experience with Windows and Linux operating systems. By the end of this course, you will be equipped to handle the complexities of modern cybersecurity, effectively mitigating threats while streamlining SOC operations for maximum efficiency in any enterprise landscape.
-
If you are an associate-level cybersecurity analyst who is working in security operation centers, this course will help you understand how threat-centric SOC must prepare for analyzing new and emerging threats by implementing robust security investigation procedures • By the end of the course, you will be able to: • Understand cyber-threat hunting concepts • Describe the five hunting maturity levels (HM0–HM4) • Describe the hunting cycle four-stage loop• Describe the use of the Common Vulnerability Scoring System (CVSS) and list the CVSS v3.0 base metrics• Describe the CVSS v3.0 scoring components (base, temporal, and environmental) • Provide an example of CVSS v3.0 scoring • Describe the use of a hot threat dashboard within a SOC • Provide examples of publicly available threat awareness resources • Provide examples of publicly available external threat intelligence sources and feeds• Describe the use of security intelligence feed • Describe threat analytics systems • Describe online security research tools • Simulate malicious actions to populate the event data on the Security Onion tools for later analysis • Identify resources for hunting cyber threats. To be successful in this course, you should have the following background: 1. Skills and knowledge equivalent to those learned in Implementing and Administering Cisco Solutions (CCNA) v1.0 course 2. Familiarity with Ethernet and TCP/IP networking 3. Working knowledge of the Windows and Linux operating systems 4. Familiarity with basics of networking security concepts.
-
If you are an associate-level cybersecurity analyst who is working in security operation centers, this course will help you understand Incident Analysis in a Threat-Centric SOC. By the end of the course, you will be able to: •Use the classic kill chain model to perform network security incident analysis • Describe the reconnaissance phase of the classic kill chain model • Describe the weaponization phase of the classic kill chain model • Describe the delivery phase of the classic kill chain model • Describe the exploitation phase of the classic kill chain model •Describe the installation phase of the classic kill chain mode l• Describe the command-and-control phase of the classic kill chain model • Describe the actions on objectives phase of the classic kill chain model • Describe how the kill chain model can be applied to detect and prevent ransomware • Describe using the diamond model to perform network security incident analysis • Describe how to apply the diamond model to perform network security incident analysis using a threat intelligence platform, such as ThreatConnect • Describe the MITRE ATTACK framework and its use • Walk-through the classic kill chain model and use various tool capabilities of the Security Onion Linux distribution •Understand the kill chain and the diamond models for incident investigations, and the use of exploit kits by threat actors. To be successful in this course, you should have the following background: 1. Skills and knowledge equivalent to those learned in Implementing and Administering Cisco Solutions (CCNA) v1.0 course 2. Familiarity with Ethernet and TCP/IP networking 3. Working knowledge of the Windows and Linux operating systems 4. Familiarity with basics of networking security concepts.
-
If you are an associate-level cybersecurity analyst who is working in security operation centers, this course will help you understand threat response. By the end of the course, you will be able to: • Explain the purpose of incident response planning • Describe the typical incident response life cycle • Describe the typical elements within an incident response policy • Describe how incidents can be classified. • Describe the different US-CERT incident categories (CAT 0 to CAT 6) • Describe compliance regulations that contain incident response requirements • Describe the different general CSIRT categories • Describe the basic framework that defines a CSIRT• Describe the different CSIRT incident handling services: triage, handling, feedback, and optional announcement • Describe a typical incident response plan and the functions of a typical CSIRT. To be successful in this course, you should have the following background: 1. Skills and knowledge equivalent to those learned in Implementing and Administering Cisco Solutions (CCNA) v1.0 course 2. Familiarity with Ethernet and TCP/IP networking 3. Working knowledge of the Windows and Linux operating systems 4. Familiarity with basics of networking security concepts.
Taught by
Cisco Learning & Certifications