← Back to list

My Journey to SOC-200/OSDA Certification

Also have Mandarin Chinese version on https://blog.3lue.tw/

blue_e · 2024-10-29 03:41 · 1 claps · 1.8 min read
#osda #soc #cybersecurity #offsec #cyberdefender
Open on Medium ↗
Wiki topics: 🔒 · Cybersecurity

My Journey to SOC-200/OSDA Certification

Also have Mandarin Chinese version on https://blog.3lue.tw/

Overview

I recently passed the OSDA (Security Operations and Defensive Analysis) certification exam. Here’s my journey through the training and examination process.

Training Experience

Thanks to my office’s resources, I had the opportunity to attend DEVCORE & OffSec’s Live Training. The five-day intensive training was one of the most focused learning experiences I’ve had.

Five Days Daily Schedule

  • 06:45 Wake up
  • 07:35 Drop off kids at school
  • 08:45 Arrive at training center
  • 18:00 End of training
  • 18:30 Family time
  • 21:00 Preparation for next day
  • 23:00 Sleep

Course Structure

SOC-200 consists of three main components:

1. Training Material

  • 19 learning modules
  • Focuses on small scenarios and attacker’s perspective
  • Recommendation: Quick overview of all modules, deep dive into unfamiliar areas
  • Optional for experienced practitioners (I only completed 25.7% ….)

2. Challenge Labs

  • Essential to complete all labs
  • Document attack flows for each phase
  • Write summary reports per phase
  • Tip: Check OffSec Discord for hints if stuck over 30 minutes
  • Challenges 11–13 are crucial as they closely simulate exam conditions

3. OSA-SOC-200

  • Maps Training Material to Challenge Labs
  • Includes instructor-led solution videos
  • Particularly useful for self-study

The Exam Experience

Setup

  • Scheduled for Friday 9 PM
  • 20 minutes for initial setup and verification
  • Phase 1 started at 21:30

Key Tips

  1. Pre-exam Preparation
  • Import custom dashboards
  • Enable all default Kibana rules was very helpful

2. Essential Tools

  • Prepare dashboards for quick event type analysis
  • Know common Event Sources and Event IDs
  • Table your events by diff sources

3. Exam Process

  • Completed 10 phases in approximately 7–8 hours
  • Take screenshots and document KQL queries
  • Track start time for each phase

4. Time Management

  • Rest break: 4 AM to 7 AM
  • Morning: Review all events
  • Afternoon: Final verification and completion by 3 PM

5. Report Writing

  • 2–3 hours for attack path documentation
  • Phase-wise summary reports, and full phases high-level summary
  • Submitted by Sunday midnight

Conclusion

The exam reflects real-world security operations scenarios. Success depends on:

  1. Ability to analyze large volumes of events
  2. Confidence in your findings
  3. Skill in correlating events into a coherent attack story

The main challenge isn’t the technical difficulty but maintaining confidence without immediate validation. Trust your analysis and focus on building a comprehensive attack narrative.

Pro Tips

  • Don’t second-guess yourself too much
  • Import analysis tools before starting Phase 1
  • Create efficient dashboards for quick event analysis
  • Document thoroughly as you progress
  • Trust your initial findings

메타데이터
post_id
a67b8db509ae
slug
my-journey-to-soc-200-osda-certification-a67b8db509ae
url
https://medium.com/@blue_e/my-journey-to-soc-200-osda-certification-a67b8db509ae
canonical_url
https://medium.com/@blue_e/my-journey-to-soc-200-osda-certification-a67b8db509ae
author_url
https://medium.com/@blue_e
status
ok
fetched_at
2026-06-27 07:40:21