High School BeginnerModule B13Lesson 2 of 7

B13.2 What SOC Analysts Do

Learn how security operations center analysts review alerts, gather evidence, distinguish suspicious activity from normal behavior, document cases, follow playbooks, and escalate incidents.

Lesson Progress

What SOC Analysts Do

High School BeginnerB13: Cybersecurity Careers and Certifications • Lesson 2 of 7

29% complete

Readiness Check

Before You Start

0/3 ready

Professional Hook

SOC Analysts Turn Noisy Alerts Into Defensible Decisions

Security tools may generate thousands of alerts. Analysts must decide which ones are urgent, which need more evidence, which are explained by approved activity, and which should be escalated to incident responders or specialists.

Safety reminder: every alert, ticket, log, user, device, account, and organization in this lesson is fictional. Never request passwords, MFA codes, recovery codes, or private personal data during an investigation.

Learning Objective

Explain alert triage, evidence review, case documentation, playbooks, escalation, and closure.

Learning Objective

Distinguish high-priority evidence from harmless or approved activity.

Learning Objective

Write clear fictional case notes that another analyst could understand and continue.

Why This Matters

Fast but Unsupported Decisions Can Create More Risk

Closing a real incident too early can leave an organization exposed. Escalating every harmless alert wastes time. Strong SOC work depends on evidence, context, clear notes, and appropriate authority.

Visual Diagram

The Beginner SOC Workflow

SOC analysts move from alert intake to evidence review, documented decisions, and appropriate escalation or closure.

1

Receive and prioritize

Review the alert source, severity, asset, user, time, and possible business impact.

2

Gather evidence

Compare approved logs, account activity, device events, tickets, and known context.

3

Decide and document

Record what the evidence supports, what remains uncertain, and which action is justified.

4

Escalate or close

Send important cases to the correct response team or close explained alerts with clear notes.

Analyst rule: alerts are starting points, not final conclusions. Evidence and context drive the decision.

Core Concept

Triage Is Structured Reasoning Under Time Pressure

Analysts review the alert source, affected asset, user, timing, severity, related events, business context, and known changes. They then document what the evidence supports and choose the safest next step.

Key Vocabulary

Terms for Security Operations

Security operations center

A team or function that monitors security events, reviews alerts, investigates evidence, documents findings, and supports incident response.

Alert triage

The first review used to decide an alert's priority, relevance, possible impact, and next action.

False positive

An alert that appears suspicious but is explained by normal, approved, or harmless activity.

Escalation

Passing an alert or incident to a person or team with the authority, expertise, or responsibility to continue the response.

Case notes

Clear documentation of evidence, actions, decisions, timestamps, owners, and unresolved questions.

Playbook

An approved set of response steps for a common alert or incident type.

Professional Decision-Making

SOC Analyst Decision Board

Strong analysts balance speed with accuracy, evidence with context, and independent work with timely escalation.

Priority

Review question

Which asset, user, data, service, or business process could be affected?

Strong analyst action

Prioritize based on evidence, exposure, criticality, scope, and time sensitivity.

Evidence

Review question

Which approved logs, tickets, account events, device alerts, or owner confirmations explain the activity?

Strong analyst action

Gather enough trusted context to support the next decision without altering evidence.

Documentation

Review question

Could another analyst understand what happened and continue the case?

Strong analyst action

Record timestamps, evidence, actions, reasoning, owners, and unanswered questions clearly.

Escalation

Review question

Does the case exceed the analyst's authority, skill, scope, or response playbook?

Strong analyst action

Escalate promptly to the correct team with organized evidence and a clear summary.

Fake SOC Dashboard

Alert Triage Review Panel

This fictional panel compares alerts, evidence, business context, likely explanations, and response decisions.

Fake Data

Unusual login alert

New location, expected user, successful MFA, approved travel

Document the context and decide whether the alert can be safely closed or requires more verification.

Malware warning

Security tool blocks a suspicious file on a managed laptop

Preserve evidence, isolate through approved procedures, and escalate to incident response.

Repeated failed logins

Many attempts against one account from unfamiliar sources

Check account ownership, timing, source pattern, lockout status, and related alerts.

Policy violation

Approved software installed outside the normal maintenance window

Verify the change ticket and avoid treating unusual timing as automatic malicious activity.

Resolved alert

Normal scheduled backup caused high network activity

Close with evidence, owner confirmation, and a clear explanation for future analysts.

Fake Dashboard

Fake SOC Shift Dashboard

Training dashboard using fictional alerts, assets, users, tickets, severity labels, evidence, and case decisions.

Alerts reviewed

38

Fictional identity, endpoint, email, network, cloud, and policy alerts.

Escalated cases

7

Evidence or impact required incident response or specialist review.

Explained alerts

23

Approved changes, normal behavior, scheduled tasks, or duplicate detections.

Fake SOC Alert

Multiple Failed Logins Followed by a Successful MFA Login

Source: Fake Identity Monitoring • Time: 8:42 AM

High Severity
A fictional account receives repeated failed login attempts from unfamiliar sources, followed by a successful login from a new location.
Defensive recommendation: Preserve the authentication evidence, check the user's approved activity through trusted channels, review related alerts, and escalate if the login cannot be verified.

Fake Log Panel

Fake SOC Investigation Log

training-log-viewer.log
08:14:03 ALERT type='failed_logins' user='student_portal_admin'
08:17:28 SOURCE attempts='18' locations='multiple_unfamiliar'
08:22:11 AUTH success='true' mfa='approved' location='new'
08:27:46 USER_CONTEXT travel='not_documented' change_ticket='none'
08:33:19 RELATED_ALERT endpoint='new_device' email='none'
08:38:54 DECISION severity='high' escalation='identity_response'
08:42:06 CASE notes='completed' owner='soc_shift_lead'

Training note: this is fake data for defensive analysis practice only.

Analyze the Evidence

Should This Alert Be Closed or Escalated?

A fictional administrator account receives 18 failed login attempts.
A successful MFA login follows from a new location.
No approved travel or change ticket is documented.
The login uses a previously unseen device.

What is the safest analyst decision?

Common Mistakes

Mistakes That Weaken SOC Work

Closing alerts without documenting the evidence.
Escalating every alert without performing basic triage.
Assuming a high severity label automatically proves a serious incident.
Changing or deleting evidence before authorized review.
Contacting users through unapproved channels or asking for passwords.
Writing vague case notes that another analyst cannot understand.

Safe Career Lab

Triage a Fictional SOC Alert Queue

Fake Alert Queue

Beginner SOC Shift

A fictional analyst reviews unusual login, blocked malware, scheduled backup traffic, after-hours software installation, public-link exposure, and repeated password-reset alerts.

Analyst Review Steps

  • Identify the alert source, asset, user, time, and severity.
  • Review trusted context and related evidence.
  • Separate facts, assumptions, and unanswered questions.
  • Choose close, monitor, investigate, or escalate.
  • Write clear case notes and identify the next owner.
  • Follow approved playbooks and protect all evidence.

Scenario Decision Lab

A High-Severity Alert Has an Approved Explanation

A fictional high-severity network alert occurs during a documented backup test approved by the infrastructure team.

Scenario Decision Lab

A Malware Alert Appears on a Managed Laptop

A fictional endpoint tool blocks a suspicious file and reports that the user attempted to open it.

Defender Habits

SOC Analyst Checklist

Check Your Understanding

B13.2 Mini Quiz: What SOC Analysts Do

Choose your answers first. Explanations appear only after submission.

1. What is alert triage?

2. What is a false positive?

3. Why are case notes important?

4. When should an alert be escalated?

5. What should a SOC analyst never request from a user?

Portfolio Prompt

Portfolio Prompt

Create a one-page fictional SOC case report. Include alert summary, affected asset, user, timeline, severity, evidence, business context, facts, assumptions, unanswered questions, decision, escalation path, and final case notes.

Use fictional users, devices, logs, tickets, alerts, accounts, and organizations only.
Do not include real credentials, private employer data, personal records, or live security logs.
Write so another beginner analyst could understand why the case was closed, monitored, or escalated.

Key Takeaways

What You Should Remember

1.SOC analysts review alerts, gather evidence, document findings, and support incident response.
2.Alert severity is important, but evidence and context determine the decision.
3.False positives should be explained and documented, not silently deleted.
4.Clear case notes and timely escalation are essential professional skills.
5.Analysts must protect evidence and never request account secrets.

Navigation

Continue Module B13