Back to Companion Guides
    Study Material

    Reader Study Guide

    Solidify your understanding chapter by chapter. Each section focuses on how analysts think, speak, and decide — not just what they do.

    This will open your print dialog. Print as usual, or select "Save as PDF" to download.

    Chapter 1

    First Alert in the Queue

    Core Focus

    • Understanding what alerts are (and are not)
    • Learning how triage works in practice
    • Getting comfortable with uncertainty

    Key Takeaways

    • Most alerts are not incidents
    • Triage is about prioritization, not fixing
    • Asking questions is part of the job

    Language to Be Comfortable With

    Alert vs eventAlert queueTriageFalse positive vs true positiveTicket / case

    Self-Check

    • • Can you explain why an alert might not be a problem?
    • • Can you describe triage without using technical jargon?
    Chapter 2

    When the Noise Isn't Noise

    Core Focus

    • Recognizing patterns across many small signals
    • Understanding alert fatigue
    • Detecting subtle authentication attacks

    Key Takeaways

    • Noise becomes dangerous when patterns are missed
    • Volume can hide real risk
    • Correlation matters more than single alerts

    Language to Be Comfortable With

    Alert fatigueAuthentication logsPassword sprayingCorrelation ruleTime window

    Self-Check

    • • Can you explain why password spraying is hard to detect?
    • • Can you describe alert fatigue in your own words?
    Chapter 3

    A Ticket That Wouldn't Close

    Core Focus

    • How incidents evolve over time
    • Malware response basics
    • Containment vs eradication

    Key Takeaways

    • Tickets stay open when risk remains
    • Containment is not resolution
    • User statements are data, not truth

    Language to Be Comfortable With

    MalwareIndicator of Compromise (IOC)Endpoint logsHost isolationContainment vs eradication

    Self-Check

    • • Can you explain the difference between containment and resolution?
    • • Why might a ticket stay open after initial response?
    Chapter 4

    The Cloud Misstep

    Core Focus

    • Risk without an attacker
    • Misconfiguration as a security issue
    • Thinking in terms of exposure

    Key Takeaways

    • "Nothing happened" does not mean "no risk"
    • Data sensitivity drives impact
    • Logs help confirm absence, not certainty

    Language to Be Comfortable With

    IAMData classificationAudit logRisk assessmentCompensating control

    Self-Check

    • • Can you explain why exposure alone matters?
    • • Can you describe risk without referencing a breach?
    Chapter 5

    Inside the Perimeter

    Core Focus

    • Internal visibility
    • Lateral movement
    • Threat hunting mindset

    Key Takeaways

    • Internal activity can be more dangerous than external noise
    • Trust boundaries matter
    • Proactive searching is part of defense

    Language to Be Comfortable With

    Lateral movementPrivilege escalationNetwork segmentVLANThreat hunting

    Self-Check

    • • Can you explain why internal traffic raises concern?
    • • Can you describe segmentation in plain language?
    Chapter 6

    Evidence Matters

    Core Focus

    • Investigation discipline
    • Evidence preservation
    • Slowing down when stakes are high

    Key Takeaways

    • Speed can destroy evidence
    • Documentation protects credibility
    • Understanding root cause prevents recurrence

    Language to Be Comfortable With

    DFIRChain of custodyForensic imageMemory dumpTimeline analysis

    Self-Check

    • • Can you explain why reimaging is sometimes delayed?
    • • Can you describe DFIR without mentioning tools?
    Chapter 7

    Lessons Logged

    Core Focus

    • Post-incident review
    • Improvement over blame
    • Playbook refinement

    Key Takeaways

    • Incidents teach if teams learn
    • Blame culture blocks growth
    • Improvement requires honesty

    Language to Be Comfortable With

    Post-incident reviewLessons learnedPlaybookSOPDetection gap

    Self-Check

    • • Can you explain why post-incident reviews exist?
    • • Can you describe how detection rules get updated?
    Chapter 8

    The Handover

    Core Focus

    • Shift continuity
    • Operational communication
    • Transition of ownership

    Key Takeaways

    • Dropped context creates risk
    • Clear handover protects people and process
    • Good communication is non-negotiable

    Language to Be Comfortable With

    Shift handoverOn-callRun bookChange windowMonitoring priority

    Self-Check

    • • Can you explain why handovers matter?
    • • Can you describe a good handover in your own words?