Check every automated verdict.
The analyst's line: triage, investigate, escalate
Learn · Practice · ApplyA ten-week certificate course in Tier 1 security operations, taught on a real SIEM inside Greyfern Security Operations, a fictional managed SOC with two clients: Tamarind Pay, a Lagos fintech, and Brasswick Manufacturing in Denver. Twelve alert classes with runbooks, 60 scripted incidents, the auto-closure sample every shift, the SIEM outage drill, and the ticket that carries what you do not know yet. Every lesson maps to CompTIA Security+ SY0-701 objectives. Two lanes chosen at enrolment: the Lagos SOC market, or the US market for work-authorised residents.
Not sure this course is right for you? Find your training path ↗
Or try a sample exercise—no sign-upTraining for remote work. A certificate does not guarantee employment.

Ten-week certificate course in Tier 1 security operations: alert triage on Wazuh and Elastic, runbooks, evidence chains, escalation, incident drills and the analyst's line, inside a fictional managed SOC with two clients, mapped to CompTIA Security+ SY0-701 objectives, with a two-week practicum.
The analyst's line: triage, investigate, escalate
Learn · Practice · ApplySeverity and priority from the client's matrix
Learn · Practice · ApplyReading firewall, proxy, endpoint and identity logs
Learn · Practice · ApplyMove from reading about attacks to working a SOC shift: triage on a real SIEM, evidence chains, escalation, and the ticket someone else can act on. Select a moment below to look inside the practice.
Order the queue by severity and asset, then run the sample before anything else.
The queue number is not the job; the verdicts are.
Pivot from the user to the sign-in log to the time window, write the chain, escalate to Dorian with a containment request.
Every escalation carries an evidence chain or it bounces.
Reopen it, record why the closure was wrong, escalate with the evidence.
Twenty-six times in the story the platform closed a true positive.
Give the facts, the gaps and a time for the next update. No attribution, no guess.
Promising an outcome or a name is a critical error.
Based on the Academy’s course content and signed-in Playground. Previewing these steps does not create an attempt or save a score.
Try the no-sign-up exercise ↗SchoolRegistry Academy’s Security Operations Tier 1 course is a ten-week online programme for beginners and career changers, taught in two lanes: the Lagos SOC market and the US market for work-authorised residents. First, students learn the analyst’s line, the SOC’s tiers and queue, and security fundamentals as they appear in logs. Second, students practise triage and investigation on Wazuh and Elastic inside Greyfern, a fictional managed SOC with two clients, with twelve runbooks, MITRE ATT&CK mapping, the auto-closure sample, the phishing wave, the SIEM outage drill and the requests that must be refused. Third, tutor-reviewed assignments, six practicum shifts and a capstone with zero critical errors create evidence of applied judgment, and every lesson maps to CompTIA Security+ SY0-701 objectives with a practice exam in Week 8. Certification requires the published completion rules, full tuition coverage and an 80% overall result. The course does not promise employment, income or US placement from Nigeria, teaches defence only, and is not CompTIA certification; the Security+ exam is sat separately at CompTIA’s fee.
Ask academic questions in the lesson player. The assistant uses lesson context but does not answer assignments or grade your work.
Manage personal work and participate in assigned team tasks with columns, dependencies, comments and history.
Use tutor feedback, explain your changes and resubmit while the original and revised evidence remain available for review.
Your assessed portfolio is private by default. Sharing is optional and revocable. Available learning-media formats depend on the lesson; caption and low-bandwidth processing is still being completed across the library.
Build a habit of learning, applying, and improving. Each part of the week gives the next one a purpose.
Explore your ten weeks ↗Work through self-paced lessons and check your understanding with module quizzes.
Apply what you’ve learned through assignments and track-specific practical exercises.
Join your track’s live session and submit your weekly assignment on the cohort schedule.
From the foundations to your final practical assessment, each stage builds on the last.
Module quizzes check understanding before you move forward. The final assessment includes written and practical work, then two practicum weeks on the job simulator.
The SOC, its tiers and its clients; the shift, the queue and the log; the analyst's line; the ticket someone else can act on; the tools of the desk; severity and priority; the two lanes.
The CIA triad; threat actors in outline; attack surfaces; the kill chain and MITRE ATT&CK; phishing, malware, brute force, web attacks, MFA fatigue and cloud misconfigurations as they appear in the logs.
Addresses, ports and DNS; HTTP and TLS in outline; the endpoint agent and the process tree; Windows event ids and Linux auth logs; the identity provider; service accounts; reading, never configuring.
What a SIEM is and is not; Wazuh from the console; searching and pivoting; saved searches; the second client in Elastic; reading a detection rule and its Sigma rule; noise, tuning and the auto-closure sample.
The four verdicts; the runbook in order; evidence and the chain; the phishing wave; the brute force that is a service account; the AI verdict you validate; the ticket; time to triage; escalations that bounce.
Incident response in outline; containment requested, never executed; the ransomware precursor; the manager who wants a ticket closed; the executive who wants a name; the SIEM outage drill; the six-hour miss reported as it is.
Least privilege and your own access; vulnerability findings as tickets and CVSS read not computed; CBN and the NDPA named for the Lagos SOC, CMMC, NIST 800-171 and SOC 2 named for the US client; evidence never leaves the environment; the analyst as a target.
The handover and the weekly report; metrics read honestly; the portfolio of simulator work; Security+ SY0-701 and confirming the live exam code before you book; the two markets honestly; interview questions answered with your own tickets; the capstone.
Timed shifts on Greyfern with alerts arriving at realistic rates on both clients, the auto-closure sample every shift, and every ticket graded on its evidence chain and its open questions.
More shifts including the SIEM outage drill, the six-hour miss reported as it is, the request you must refuse, and a tutor-marked capstone. Passing needs zero critical errors.
Keep the curriculum, fees, start date, and study checklist in one handy course guide.
Start with good judgment. Try this illustrative exercise and see the reasoning behind a useful response.
The platform auto-closed an outbound-connection alert as benign. The evidence shows a beacon to a known bad domain every 60 seconds.
Choose your next response.
Security Operations Tier 1 Certificate
The SchoolRegistry Academy certificate is assessed through knowledge and practical tasks—not simply time spent watching lessons.
Issued by SchoolRegistry Academy. This is not a third-party accreditation or a guarantee of employment.
A computer, headset, reliable internet, and a quiet place to practice will help you participate. Check the live-session schedule before enrolling.
Future US-client work may involve afternoon or evening hours in Nigeria.
Roles this training prepares you to pursue. Start with the work you want to do, then build the skills to demonstrate it.
Triage and investigate alerts on a managed SOC or in-house security team, escalate with evidence, keep the log.
Six practicum shifts on Greyfern with zero critical errors.
Sit inside a bank, fintech or telecom security team and work the queue under a senior.
Runbooks, evidence chains and the auto-closure sample.
Work a US SOC shift where clients require US-resident staff.
Security+ objectives mapped on every lesson and the practice exam.
Employers commonly ask for CompTIA Security+, which is sat separately at CompTIA’s fee, and US clients restrict telemetry access to US-resident, background-checked staff. This course trains skills; it does not confer US work authorisation. Employment is not guaranteed; role titles and hiring requirements vary by employer.
The shared Career Readiness course covers your LinkedIn profile, résumé, interview practice, and getting paid as an international remote contractor. Describe practice honestly as training—not employment.
The SchoolRegistry Academy certificate proves you did the work: the ten weeks, six supervised practicum shifts and a capstone with zero critical errors, verifiable by any employer on our public verification page.
US and Nigerian postings for Tier 1 roles most often name CompTIA Security+. Every lesson in this course carries the SY0-701 objectives it covers, Week 8 includes a timed practice exam scored by domain, and the exam lesson walks you through booking, including confirming the live exam code first.
Together they answer the two questions a hiring manager asks: can you do the work (our certificate, assessed on a real SIEM), and does the industry recognise your knowledge (Security+). CySA+ is the step after.
Security+ is issued and governed by CompTIA, not by SchoolRegistry Academy, and the exam carries a fee CompTIA sets; we prepare you and show you the process, CompTIA awards the credential. We re-check the fee and the live exam code each cohort.
Need help with your course fee? Apply for a Founder's Scholarship before enrolling. You can also invite a family member, employer, or supporter to sponsor all or part of your training.
Scholarship awards depend on review and available budget. Sponsorship does not guarantee admission, certification, or employment.
Choose your payment option. Get a clear view of the commitment before making your decision.
Pay in full or choose two installments at checkout.
Full course fee · or ₦100,000 × 2 installments
Choose your payment plan securely at checkout.
Questions? Book a free advising call ↗Choose an available time with the Academy team. All times are WAT.
No. Week 2 starts with the CIA triad and what attacks look like in logs, and Week 3 teaches enough networks and endpoints to read a firewall line and a process tree. What you need is the discipline to follow a runbook, write things down, and say what you do not know yet.
No. The course teaches defence and detection only. Offensive tools appear only as things you recognise in logs. That is the correct line for a Tier 1 analyst and for the Academy.
Not on its own. Every lesson maps to SY0-701 objectives and Week 8 includes a timed practice exam with a score by domain, so you can judge your readiness. The exam itself is CompTIA's, sat separately, at a fee CompTIA sets ($439 direct at the time of writing, less through resellers). Confirm the live exam code before you book; CompTIA replaces exam versions on its own schedule.
US clients restrict who touches their security telemetry to US-resident, background-checked staff under rules such as CMMC, NIST SP 800-171 and SOC 2, and the course explains why. The Nigeria lane prepares you for the Lagos market: banks, fintechs, telecoms and managed SOCs. The US lane is for work-authorised US residents. This course trains skills; it does not confer US work authorisation.
Yes. A SchoolRegistry Academy certificate with a unique ID and a public verification page is issued when the published completion rules are met, including the final assessment and the practicum with zero critical errors.
October 12, 2026 at 11:00 AM WAT (Nigeria). Each track has one live class a week; the day is confirmed in your enrollment information.
No. The Academy develops and assesses skills. Employment depends on your performance, employer requirements, and available roles.
₦200,000 covers this track. You can pay in full or in two ₦100,000 installments, with the balance due three weeks later. Review the handbook and checkout terms before paying.
Talk through this course, your experience and how to get started. Choose a time from the Academy team’s shared availability.
See available advising times ↗Employers and partners can confirm the current status of a shared SchoolRegistry Academy certificate using its 12-character ID.
Verify a certificate ↗Use these existing SchoolRegistry guides to compare the wider career decision before you enroll.
Security Operations Tier 1 Certificate · SchoolRegistry Academy