1.0 Fundamentals (20% Weighting)This domain focuses on the foundational rules, operational workflows, and strategic models underpinning modern Security Operations Centers (SOCs), risk management, and cloud infrastructures. Spoto1.1 Incident Response PlaybooksComponent Interpretation: Dissecting the structure of cybersecurity playbooks, including triggers, condition checks, operational steps, communication matrices, and escalation criteria.Tool Selection: Mapping security tools (SIEM, XDR, EDR, packet captures, network logs) to corresponding playbook stages based on threat scenarios.Playbook Application: Step-by-step application of standard incident response playbooks for high-frequency security incidents:Unauthorized elevation of privilege (Privilege Escalation) NWExamDenial of Service (DoS) and Distributed Denial of Service (DDoS)Web-facing infrastructure attacks (Website defacement, SQL injection, XSS) NWExam1.2 Regulatory Compliance & Risk ManagementIndustry Standards Frameworks: Identifying, interpreting, and aligning specific industries and operating boundaries with key compliance baselines: NWExamPCI-DSS: Credit card data and transaction processing environments.FISMA / FedRAMP: Federal information systems, agencies, and cloud service providers handling government data.SOC (SOC 1, SOC 2, SOC 3): Operational security, availability, processing integrity, confidentiality, and privacy controls for service organizations.SOX: Financial reporting compliance and internal data controls for publicly traded companies. NWExamGDPR
What you'll learn
Understand the foundational concepts of cybersecurity and Security Operations Centers
Analyze incident response playbooks and their components
Select appropriate security tools for different cyber threat scenarios
Apply incident response strategies to common cybersecurity incidents
Interpret regulatory compliance frameworks like GDPR and PCI-DSS