Assignments
Assignments are short, reviewable exercises that strengthen technical reasoning and communication between larger labs and portfolio projects.
Assignment 1 — SOC capability baseline
Create a table covering networking, Windows logs, Wazuh, incident response, cloud security, Git/GitHub, automation and communication. Score current confidence, identify evidence already available and define the next 90-day action for each area.
Assignment 2 — Alert triage worksheet
Build a reusable triage template containing:
- alert name and source;
- timestamp and affected asset/account;
- observable facts;
- initial hypothesis;
- next evidence to collect;
- severity rationale;
- disposition;
- escalation decision;
- false-positive/tuning note.
Use it on three lab alerts.
Assignment 3 — Investigation writing
Write a one-page investigation summary for a failed-logon scenario. The reader should understand what happened, what evidence supports the conclusion, what remains uncertain and what action is recommended.
Assignment 4 — Detection design
Design two detections from threat hypotheses. Include telemetry, logic, severity, test data, false positives and ATT&CK mapping.
Assignment 5 — Cloud control map
Compare identity, MFA, least privilege, logging, network exposure and monitoring controls in Google Cloud and one additional cloud platform. Explain the SOC-relevant telemetry each control can produce.
Assignment 6 — Communication improvement plan
The assessment identifies communication as an area where additional support would help. Create a practical plan with:
- one written communication exercise per week;
- one short verbal explanation/demo every two weeks;
- mentor feedback notes;
- examples of improved before/after wording;
- one mock incident briefing by Day 60.
Assignment 7 — Career evidence audit
Review CV, LinkedIn and GitHub portfolio. For every claimed security skill, link to evidence or mark it as learning-in-progress. Remove vague claims that cannot be supported.
Submission standard
Each assignment should include references, evidence links, a short self-review and the specific mentor/reviewer feedback that was acted on.