CAI 410 Enterprise Security, Automation, and Response

This course is designed to advance learners from manual triage to automated response. Using Splunk SOAR, they design and execute playbooks that orchestrate tools and
streamline response actions; with Enterprise Security, they tune correlation searches, build dashboards, and apply risk-based alerting for prioritized detections. The capstone synthesizes skills into a portfolio ready SOC project—complete with runbooks, metrics, and an executive briefing—while preparing learners for the Splunk SOAR User certification.

Credits

5

Prerequisite

CSS 400

Corequisite

None