My Journey to SOC-200/OSDA Certification
Also have Mandarin Chinese version on https://blog.3lue.tw/
My Journey to SOC-200/OSDA Certification

Also have Mandarin Chinese version on https://blog.3lue.tw/
Overview
I recently passed the OSDA (Security Operations and Defensive Analysis) certification exam. Here’s my journey through the training and examination process.
Training Experience
Thanks to my office’s resources, I had the opportunity to attend DEVCORE & OffSec’s Live Training. The five-day intensive training was one of the most focused learning experiences I’ve had.
Five Days Daily Schedule
- 06:45 Wake up
- 07:35 Drop off kids at school
- 08:45 Arrive at training center
- 18:00 End of training
- 18:30 Family time
- 21:00 Preparation for next day
- 23:00 Sleep
Course Structure
SOC-200 consists of three main components:
1. Training Material
- 19 learning modules
- Focuses on small scenarios and attacker’s perspective
- Recommendation: Quick overview of all modules, deep dive into unfamiliar areas
- Optional for experienced practitioners (I only completed 25.7% ….)
2. Challenge Labs
- Essential to complete all labs
- Document attack flows for each phase
- Write summary reports per phase
- Tip: Check OffSec Discord for hints if stuck over 30 minutes
- Challenges 11–13 are crucial as they closely simulate exam conditions
3. OSA-SOC-200
- Maps Training Material to Challenge Labs
- Includes instructor-led solution videos
- Particularly useful for self-study
The Exam Experience
Setup
- Scheduled for Friday 9 PM
- 20 minutes for initial setup and verification
- Phase 1 started at 21:30
Key Tips
- Pre-exam Preparation
- Import custom dashboards
- Enable all default Kibana rules was very helpful
2. Essential Tools
- Prepare dashboards for quick event type analysis
- Know common Event Sources and Event IDs
- Table your events by diff sources
3. Exam Process
- Completed 10 phases in approximately 7–8 hours
- Take screenshots and document KQL queries
- Track start time for each phase
4. Time Management
- Rest break: 4 AM to 7 AM
- Morning: Review all events
- Afternoon: Final verification and completion by 3 PM
5. Report Writing
- 2–3 hours for attack path documentation
- Phase-wise summary reports, and full phases high-level summary
- Submitted by Sunday midnight
Conclusion
The exam reflects real-world security operations scenarios. Success depends on:
- Ability to analyze large volumes of events
- Confidence in your findings
- Skill in correlating events into a coherent attack story
The main challenge isn’t the technical difficulty but maintaining confidence without immediate validation. Trust your analysis and focus on building a comprehensive attack narrative.
Pro Tips
- Don’t second-guess yourself too much
- Import analysis tools before starting Phase 1
- Create efficient dashboards for quick event analysis
- Document thoroughly as you progress
- Trust your initial findings
메타데이터
- post_id
- a67b8db509ae
- slug
- my-journey-to-soc-200-osda-certification-a67b8db509ae
- url
- https://medium.com/@blue_e/my-journey-to-soc-200-osda-certification-a67b8db509ae
- canonical_url
- https://medium.com/@blue_e/my-journey-to-soc-200-osda-certification-a67b8db509ae
- author_url
- https://medium.com/@blue_e
- status
- ok
- fetched_at
- 2026-06-27 07:40:21