SOC Interview Language Cheat Sheet
Sound credible without overselling yourself. These are not scripts, but patterns of speech commonly used by SOC analysts.
This will open your print dialog. Print as usual, or select "Save as PDF" to download.
SOC Interview Language — Cheat Sheet
First SOC Shift Companion Guide
How to Talk About Alerts
"I responded to a lot of alerts."
"I focused on triaging alerts to separate noise from activity that warranted escalation."
How to Talk About Triage
"We investigated everything."
"We prioritized alerts based on potential impact and available evidence."
How to Talk About False Positives
"Most alerts were false."
"Many alerts were false positives, which required pattern recognition to avoid alert fatigue."
How to Talk About Phishing
"We handled phishing emails."
"We monitored phishing-related alerts and escalated when patterns suggested broader risk."
How to Talk About Malware
"A machine got infected."
"Endpoint activity indicated possible malware, so we isolated the host and tracked IOCs."
How to Talk About Containment
"We fixed the issue."
"We contained the activity to limit spread while investigation continued."
How to Talk About DFIR
"Forensics handled it."
"We engaged DFIR to analyze the incident and provide insights for future prevention."
How to Talk About Evidence
(No equivalent)
"We preserved evidence and supported DFIR efforts by maintaining chain of custody."
How to Talk About Post-Incident Work
"We closed the incident."
"We conducted a post-incident review to identify detection gaps and improve playbooks."
How to Talk About Risk
"Nothing bad happened."
"We assessed exposure and documented residual risk even without confirmed impact."
One Sentence That Signals Readiness
If you remember nothing else, remember this pattern:
"My role focused on monitoring, triage, documentation, and communication to support incident response and continuous improvement."
That sentence sounds like someone who belongs in a SOC.