Skip to main content
Course

Incident Response Foundations

From first alert to lessons learned: handle a security incident the way real teams do.

Beginner

Level

4

Modules

8

Lessons

4

Graded quizzes

2

Assignments

8 hours

Estimated time

What you will be able to do

  • Tell the difference between a routine event, an alert, and a real security incident.
  • Describe each phase of the NIST SP 800-61 lifecycle and explain why the order matters.
  • Name the core CSIRT roles and say who owns which decision during a live incident.
  • Assemble the preparation basics: an incident response plan, a contact tree, and a first playbook.
  • Declare an incident and run triage: scope it, rate its severity, and open a clean timeline.
  • Choose containment and eradication steps that stop the threat while protecting the evidence.
  • Guide systems back to normal and lead a plain, blameless lessons-learned review.

What is inside

4 modules, 8 lessons. Each module ends in a graded quiz and most carry an assignment.

  1. 01

    Foundations: What Counts as an Incident

    Every good response starts with clear language and a clear map. In this module you will learn what actually turns a security event into a declared incident, then walk the whole National Institute of Standards and Technology (NIST) Special Publication 800-61 lifecycle so you can see where every later task fits. This is the mental model the rest of the course builds on.

    2 lessons · 5 quiz questions

  2. 02

    The Team and the Playbook

    Incidents are handled well by people who prepared long before the alarm sounded. Here you will meet the CSIRT (Computer Security Incident Response Team) and learn who owns which call when the pressure is on. Then you will build the readiness layer that makes a calm response possible: the incident response plan, the playbooks, and the tools a team sets up in advance.

    2 lessons · 5 quiz questions · assignment

  3. 03

    Detection and Triage

    This is the moment an incident becomes real. You will learn where detections come from, how a team decides to formally declare an incident, and how to make sense of what you are seeing. You will practice scoping the damage, rating severity, and keeping the careful timeline that every later step depends on.

    2 lessons · 5 quiz questions

  4. 04

    Containment, Eradication, and Recovery

    Now you act. You will work through containing the threat, removing it for good, and bringing systems safely back to normal, all while protecting the evidence a Digital Forensics and Incident Response (DFIR) analyst may need later. The module closes with the blameless lessons-learned review that turns one hard week into a stronger, better-prepared team.

    2 lessons · 5 quiz questions · assignment