CFS210 · Cyber Defense Fundamentals

Chapter 2 Review: System and Network Architecture in Security Operations

A hands-on review station for SOC operations, logging, Sysmon, operating system security, and modern infrastructure.

Start Here

Five review stations, each a different way to practice Chapter 2. Work through them in any order. Nothing here is graded or stored, so use it as many times as you like before the quiz or lab.

What this chapter asked you to be able to do

  • Explain the SOC analyst workflow and how work divides across Tier 1, Tier 2, and Tier 3.
  • Describe a logging architecture: collection, aggregation, tiered storage, integrity, and time synchronization.
  • Apply operating system security ideas: hardening, file permissions, process monitoring, and Windows event and Sysmon logging.
  • Analyze modern infrastructure: virtualization, cloud shared responsibility, containers, and APIs.
  • Assess device management for endpoints, mobile, and IoT.
Two new station types in this chapter The Guided Terminal lets you run a safe, simulated command sequence for deploying Sysmon and inspecting a Linux host. The Match-Up station uses drag and drop (or keyboard and touch) to pair event IDs and infrastructure terms with their meanings. Neither runs any real commands.

Your progress this session

These counters update as you work each station. They reset when you reload the page.

0/20Terms viewed
0/6Terminal steps done
0/12Match-ups correct
0/11SOC & cloud correct
0/10Quiz correct
How to use each station Make a choice or run a command, then check the feedback and the reasoning behind it. A wrong answer is a chance to reread the logic rather than just the label. Keyboard users can move between tabs with the arrow keys, and every station is fully keyboard operable.