CAI 410 Enterprise Security, Automation, and Response
This course is designed to advance learners from manual triage to automated response. Using Splunk SOAR, they design and execute playbooks that orchestrate tools and
streamline response actions; with Enterprise Security, they tune correlation searches, build dashboards, and apply risk-based alerting for prioritized detections. The capstone synthesizes skills into a portfolio ready SOC project—complete with runbooks, metrics, and an executive briefing—while preparing learners for the Splunk SOAR User certification.
Credits
5
Prerequisite
CSS 400
Corequisite
None