Course Description
30 Hours | 5 Days | Instructor-Led Certification Bootcamp
Cybersecurity operations analysts protect organizations by identifying threats, investigating suspicious activity, assessing vulnerabilities and recommending countermeasures. The Certified Cybersecurity Operations Analyst™ course develops the practical knowledge and technical skills needed to work across networking, endpoints, applications, cloud environments and security-monitoring platforms.
Aligned with the ISACA CCOA exam domains, this instructor-led bootcamp combines cybersecurity concepts with hands-on analysis and performance-based practice. Students explore technology essentials, cybersecurity principles and risk, adversarial tactics, incident detection and response, and asset protection. The course emphasizes the use of logs, network traffic, threat intelligence, vulnerability data and common defensive tools to investigate and respond to realistic security events while preparing for the CCOA certification exam.
SEC980 is taken as part of the Isaca Professional Certificate. To complete the certificate students will also enroll in one of the following courses SEC800, SEC930,, SEC940 or SEC960. Click on each course link for more details and to add to cart.
Course Outline
- Module 1: Technology Essentials
- Computer and cloud networking, devices, ports and protocols
- Network access, segmentation, topology and diagnostic tools
- Windows and Linux systems, command-line utilities and endpoints
- Databases, middleware, virtualization and containers
- APIs, cloud applications, scripting and automated deployment
- Module 2: Cybersecurity Principles and Risk
- Security governance, objectives, roles and responsibilities
- Risk-management concepts and cybersecurity models
- Application, cloud, data, network, endpoint and supply-chain risk
- Compliance and communication with business stakeholders
- Module 3: Adversarial Tactics, Techniques and Procedures
- Threat actors, motives, attack vectors and intelligence sources
- Common attack types and stages of a cyberattack
- Exploitation techniques and attacker behaviors
- Penetration-testing concepts and defensive interpretation
- Module 4: Incident Detection
- Logging, alerts, dashboards and monitoring technologies
- Indicators of compromise and indicators of attack
- Detection use cases, rule sets and data analytics
- Network and endpoint event analysis
- Threat hunting and escalation decisions
- Module 5: Incident Response and Analysis
- Incident preparation, triage, containment and handling
- Forensic, malware, threat and network-traffic analysis
- Packet analysis and evidence preservation
- Communication, documentation and lessons learned
- Module 6: Securing Assets and Vulnerability Management
- Preventive, detective and corrective controls
- Identity and access management
- Security frameworks, standards and guidance
- Vulnerability identification, assessment, remediation and tracking
- Contingency planning and continuous improvement
- Module 7: CCOA Exam Preparation and Performance Practice
- Review of the five CCOA exam domains
- Hands-on practice using representative security tools
- Multiple-choice and performance-based question strategies
- Knowledge checks and targeted review
Learner Outcomes
Upon successful completion of this course, students will be able to:
- Analyze networking, systems, cloud and application information relevant to cybersecurity operations.
- Apply cybersecurity governance and risk principles when prioritizing operational security work.
- Recognize adversarial tactics, techniques, procedures, attack vectors and indicators.
- Use logs, alerts, traffic and threat intelligence to detect and investigate incidents.
- Perform incident triage, containment and analysis using common cybersecurity tools.
- Identify, assess, remediate and track vulnerabilities affecting organizational assets.
- Recommend appropriate controls and countermeasures and prepare for the CCOA exam.
Additional Information
SLU's Course Kit: (included in the course fee):
All included ISACA materials and resources, including the certification exam voucher, are accessible or valid for 6 months.
- ISACA CCOA Official Review Manual (digital edition)
- CCOA Questions, Answers & Explanations (QAE) Database with a 200+ question pool
- Thirteen hands-on CCOA practice labs
- Instructor-led presentation materials and performance-based exam preparation
- One CCOA certification exam attempt
About the Test:
- Four-hour computer-based certification exam.
- Includes 115 multiple-choice questions and 25 performance-based questions.
- Covers Technology Essentials, Cybersecurity Principles and Risk, Adversarial Tactics, Techniques and Procedures, Incident Detection and Response, and Securing Assets.
- Requires candidates to apply knowledge using operating systems, command-line utilities and security-analysis tools identified by ISACA.
- Administered through ISACA's authorized testing provider at approved testing centers or by remote proctoring where permitted.
- The exam registration is valid for a six-month eligibility period.
Requirements for Certification Exam Testing:
Exam and certification requirements are separate from the prerequisites for attending this course. To earn the certification, candidates must:
- No prior professional certification is required to register for the CCOA exam.
- Register and pay for the CCOA exam through ISACA.
- Schedule and pass the exam within the six-month eligibility period.
- Submit the CCOA certification application and US$50 application fee within five years of passing the exam.
- Agree to ISACA's Code of Professional Ethics.
- Follow ISACA's Continuing Professional Education Policy after becoming certified.
Prerequisites
Students should complete the SLU Workforce Center SEC150 Cybersecurity Foundations and SEC250 Cyber Defense courses or have equivalent cybersecurity knowledge and experience. Students should understand basic TCP/IP networking, Windows and Linux operating systems, cybersecurity terminology, common threats and vulnerabilities, access controls, logs and introductory incident-response concepts. Comfort using a command line and working through technical labs is strongly recommended.
Duration
30 Hours | 5 Days or 10 NightsEnroll Now - Select a section to enroll in
*Academic Unit eligibility to be determined by college/university in which you are enrolled in a degree seeking program.