# SOC job preparation workbook

Use with CymBytes Foundations, Investigation Course or Complete Programme.
This is a learner worksheet, not a certificate or proof of employment.

## 1. Check the vacancy

Company / role / location:
Original posting URL:
Date you checked that applications were open:
Experience, qualifications, location and shift requirements:

For every responsibility, fill one row. Use demonstrated / practised with help /
not yet demonstrated / outside my course. Do not turn a completion badge into
proof of a skill you cannot explain. Check vacancy status again before applying.

| Requirement from posting | Relevant included lab | My evidence and assistance used | Gap / next action |
| --- | --- | --- | --- |
| SIEM searches and log analysis | Splunk First Steps; SPL Detective | | |
| Windows investigation | Reading Windows Logs; Insider Threat Investigation | | |
| Malicious execution | Malicious File Execution (Investigation + Complete) | | |
| Phishing-related C2 | Phishing C2 Detection (Investigation + Complete) | | |
| Team investigation and briefing | Operation Loki (Complete only) | | |
| Other requirements from this posting | | | |

Separately check networking, Linux, EDR, SIEM products other than Splunk,
ServiceNow, operational SOPs, credentials and required employment experience.
Loki is not included in the six-lab Investigation Course. C2 investigation is
not equivalent to complete phishing mailbox triage or email-product training.

## 2. Capture one investigation

Lab / date / attempt reference:
Assistance: guided / independent / mixed. Specify instructor, tutor or other help.

### Investigation question
What were you asked to establish? What evidence would support or refute it?

### Searches and evidence
For each search: SPL, index/source, time range and timezone, relevant fields,
selected result/event reference, why you ran it, what it does and does not prove.
Capture lab evidence before the session closes. Remove secrets and personal data.

### Timeline
Timestamp and timezone | host/user | event/source | significance | confidence

### Findings and limitations
What is established? Which users/hosts are affected? Which benign explanation
did you test? What is uncertain? A missing event is not proof an action did not occur.

### Escalation handoff
Summary / affected assets / proposed priority and why / key evidence /
recommended next action / evidence still needed / receiving analyst or team.
State recommendations separately from actions you actually performed.

### Interview walkthrough
In two minutes: question → evidence → decision → limitations → next action.
Then answer: Why this query? What would change your conclusion? What would you
check next? What did you do yourself, and where did you need help?

Save these sections in https://portal.cymbytes.com/portfolio under the matching
lab. Paid learners can save and submit for instructor feedback. Download your
saved evidence pack; sharing it publicly is optional.

## 3. Follow-up assessment

After finishing the included labs, request one changed investigation question
from your instructor in class or through portfolio feedback. It uses an included
lab and the normal monthly launch allowance; arrange it before launching.
The instructor checks that the question is supported by that lab's telemetry.

Assigned question / lab / event window / assignment date:
Expected submission date agreed with instructor:
Start/end time / assistance actually used:

Attempt without a walkthrough, tutor or generated answer. You may use product
reference documentation; disclose it. If you need help, ask and label the work
mixed rather than concealing assistance. Independence is self-declared unless
an instructor observed it; this is not proctored.

Append clearly labelled “Follow-up assessment” sections to the same case study
without deleting the original report. Include your new question, queries,
evidence, timeline, competing explanations and escalation decision. If the
original was guided and the follow-up independent, mark the overall entry mixed
and describe both. Save, then submit for instructor feedback.

Feedback checks: evidence accuracy / investigation method / alternative
explanations and limits / escalation and communication. It is separate from
platform scoring and does not change certificate eligibility. Review each
comment, revise and rehearse again. There is no employment-readiness pass mark.

## 4. Application evidence

CV section: Practical projects — SOC lab investigations

“Investigated [scenario] in a simulated enterprise lab using Splunk. Used
[queries/events] to establish [finding], documented [scope/timeline] and
recommended [next action]. Evidence: [optional portfolio link].”

Replace every placeholder with your own completed work. Do not list the course
as employment, an internship or years of professional experience. Apply according
to each employer's criteria; do not wait for a course if a suitable vacancy closes
sooner. Training does not guarantee an interview, selection or placement.
