CM
The Career Machine
Skip to main content
All roles
Security · Free Practice

SOC Analyst Scenarios

Monitor, detect, and respond to security incidents in real-time.

Scenarios
5
Skills Tested
15
Salary Range
$55k–$110k
Job Demand
very high

Difficulty Distribution

Beginner1
Intermediate2
Advanced2

Skills You'll Practice (15)

Incident triageSIEM analysisEscalationInsider threatDLP investigationPrivacy considerationsRansomware responseContainmentForensicsPhishing analysisUser account securityThreat huntingVulnerability managementPatch managementCommunication

All 5 Scenarios

Click any scenario to practice it. No account required.

beginnerincident

3AM Alert — Brute Force Attack

You are an L1 SOC Analyst on night shift. It's 3:17 AM and your SIEM fires an alert: 547 failed login attempts from IP 185.220.101.45 against your company's VPN gateway in the last 5 minutes. The IP is in Romania. Logins are targeting the 'admin' account. Walk me through exactly what you do.

Incident triageSIEM analysisEscalation
10 min
intermediateincident

Data Exfiltration Alert

Your DLP tool flags unusual activity: an employee just uploaded 4.7GB to personal Google Drive. The employee is in Finance and it's 11:30 PM on a Friday — unusual for their typical 9-5 hours. What do you do? What questions do you ask? Who do you contact?

Insider threatDLP investigationPrivacy considerations
15 min
advancedincident

Ransomware Alert — Encrypted Files Detected

Your EDR fires 47 alerts in 3 minutes: mass file encryption detected on a workstation in Engineering. Files with extensions .doc, .xlsx, .pdf are being renamed with '.locked' extension. The workstation belongs to a senior engineer with domain admin access. Walk me through the first 15 minutes of your response.

Ransomware responseContainmentForensics
15 min
intermediateincident

Phishing Campaign Investigation

You receive 12 reports from employees in one hour about the same phishing email: 'Urgent: Update your Microsoft 365 password.' 3 users clicked the link. 1 user entered credentials. The link goes to microsoft365-verify.co (not microsoft.com). What's your response plan?

Phishing analysisUser account securityThreat hunting
15 min
advancedincident

Zero-Day Vulnerability Disclosed

CISA just published an emergency advisory: a critical zero-day (CVSS 10.0) in the software your company uses for VPN access. Exploitation is actively occurring in the wild. Your CISO wants a status update in 30 minutes. Walk me through your approach.

Vulnerability managementPatch managementCommunication
20 min

Ready to practice like a SOC Analyst?

5 real-world scenarios waiting. Set the timer. Think out loud. Get better.

Start Practicing