When you enroll in this course, you'll also be enrolled in this Professional Certificate.
Learn new concepts from industry experts
Gain a foundational understanding of a subject or tool
Develop job-relevant skills with hands-on projects
Earn a shareable career certificate from Google
There are 4 modules in this course
This is the sixth course in the Google Cybersecurity Certificate. Learners will focus on incident detection and response. They will learn what defines a security incident and explain the incident response lifecycle, including the roles and responsibilities of incident response teams. Learners will analyze and interpret network communications to detect security incidents using packet sniffing tools to capture network traffic. By assessing and analyzing artifacts, learners will explore the incident investigation and response processes and procedures. Additionally, they will develop a conceptual overview of log data and their role in intrusion detection systems (IDS) and Security Information Event Management (SIEM) tools. Learners who complete this certificate will be equipped to apply for entry-level cybersecurity roles. No previous experience is necessary.
By the end of this course, you will:
- Explain the lifecycle of an incident.
- Describe the tools used in documentation, detection, and management of incidents.
- Analyze packets to interpret network communications.
- Perform artifact investigations to analyze and verify security incidents.
- Identify the steps to contain, eradicate, and recover from an incident.
- Determine how to read and analyze logs during incident investigation.
- Interpret the basic syntax and components of signatures and logs in Intrusion Detection Systems (IDS) and Network Intrusion Detection Systems (NIDS) tools.
- Perform queries in Security Information and Event Management (SIEM) tools to investigate an event.
This module provides an overview of detection and incident response. Learners will explore how security professionals verify and respond to malicious threats. Learners will also become familiar with the steps involved in incident response. This overview will be the foundation for the next module.
What's included
12 videos7 readings6 assignments1 plugin
Show info about module content
12 videos•Total 30 minutes
Introduction to Course 6 •2 minutes
Dave: Grow your cybersecurity career with mentors•3 minutes
Welcome to module 1 •2 minutes
Introduction to the incident response lifecycle •4 minutes
Incident response teams •3 minutes
Fatima: The importance of communication during incident response•3 minutes
Incident response plans•2 minutes
Incident response tools •2 minutes
The value of documentation •3 minutes
Intrusion detection systems •2 minutes
Alert and event management with SIEM and SOAR tools•4 minutes
Wrap-up •1 minute
7 readings•Total 44 minutes
Course 6 overview•4 minutes
Helpful resources and tips•4 minutes
Portfolio Activity Exemplar: Document an incident with an incident handler's journal•4 minutes
Roles in response •8 minutes
Overview of detection tools •8 minutes
Overview of SIEM technology •12 minutes
Glossary terms from module 1•4 minutes
6 assignments•Total 114 minutes
Test your knowledge: The incident response lifecycle•8 minutes
Test your knowledge: Incident response operations•8 minutes
Test your knowledge: Detection and documentation tools •8 minutes
Test your knowledge: Management tools•20 minutes
Portfolio Activity: Document an incident with an incident handler's journal•20 minutes
Module 1 challenge•50 minutes
1 plugin•Total 10 minutes
Explore: Apply the NIST lifecycle to a vishing scenario•10 minutes
Network monitoring and analysis
Module 2•5 hours to complete
Module details
In this module, learners will be provided with an overview of network analysis tools more commonly referred to as “packet sniffers”. In particular, learners will sniff the network and analyze packets for malicious threats. Learners will also craft common filtering commands in both tcpdump and Wireshark to analyze the contents of packet capture.
What's included
9 videos10 readings5 assignments4 app items
Show info about module content
9 videos•Total 23 minutes
Welcome to module 2•1 minute
Casey: Apply soft skills in cybersecurity•2 minutes
The importance of network traffic flows•3 minutes
Data exfiltration attacks•4 minutes
Packets and packet captures•3 minutes
Interpret network communications with packets•2 minutes
Reexamine the fields of a packet header•4 minutes
Packet captures with tcpdump•4 minutes
Wrap-up•1 minute
10 readings•Total 64 minutes
Maintain awareness with network monitoring •8 minutes
Learn more about packet captures •8 minutes
Investigate packet details•8 minutes
Resources for completing labs•4 minutes
Lab tips and troubleshooting steps•4 minutes
Exemplar: Analyze your first packet•8 minutes
Overview of tcpdump •8 minutes
Exemplar: Capture your first packet•8 minutes
Activity Exemplar: Research network protocol analyzers•4 minutes
Glossary terms from module 2•4 minutes
5 assignments•Total 104 minutes
Test your knowledge: Understand network traffic•8 minutes
Test your knowledge: Capture and view network traffic•8 minutes
Test your knowledge: Packet inspection•8 minutes
Activity: Research network protocol analyzers•30 minutes
Module 2 challenge•50 minutes
4 app items•Total 80 minutes
Activity: Analyze your first packet•30 minutes
Optional Exemplar: Analyze your first packet•10 minutes
Activity: Capture your first packet•30 minutes
Optional Exemplar: Capture your first packet•10 minutes
Incident investigation and response
Module 3•4 hours to complete
Module details
In this module, Learners will explore the various processes and procedures in the stages of incident detection, investigation, analysis, and response as framed by NIST. They will utilize VirusTotal as an investigative tool to analyze the details of suspicious file hashes. Learners will recognize the importance of documentation and evidence collection during the detection and response stages. Finally, learners will approximate an incident’s chronology by mapping artifacts to reconstruct an incident’s timeline.
What's included
11 videos11 readings7 assignments2 plugins
Show info about module content
11 videos•Total 27 minutes
Welcome to module 3 •1 minute
The detection and analysis phase of the lifecycle •2 minutes
MK: Changes in the cybersecurity industry•3 minutes
The benefits of documentation •2 minutes
Document evidence with chain of custody forms •4 minutes
The value of cybersecurity playbooks •3 minutes
The role of triage in incident response •3 minutes
Robin: Foster cross-team collaboration•3 minutes
The containment, eradication, and recovery phase of the lifecycle•2 minutes
The post-incident activity phase of the lifecycle •2 minutes
Analyze indicators of compromise with investigative tools•8 minutes
Activity Exemplar: Investigate a suspicious file hash•4 minutes
Best practices for effective documentation •8 minutes
Activity Exemplar: Use a playbook to respond to a phishing incident•4 minutes
The triage process •8 minutes
Business continuity considerations•8 minutes
Post-incident review •8 minutes
Glossary terms from module 3•4 minutes
7 assignments•Total 144 minutes
Activity: Investigate a suspicious file hash•20 minutes
Test your knowledge: Incident detection and verification•8 minutes
Activity: Use a playbook to respond to a phishing incident•30 minutes
Test your knowledge: Response and recovery•8 minutes
Activity: Review a final report•20 minutes
Test your knowledge: Post-incident actions •8 minutes
Module 3 challenge•50 minutes
2 plugins•Total 20 minutes
Identify: Indicators of compromise•10 minutes
Identify: Explore an incident event timeline•10 minutes
Network traffic and logs using IDS and SIEM tools
Module 4•6 hours to complete
Module details
In this module, learners will be provided with a conceptual overview of logs and their role in intrusion detection systems (IDSs) and Security Information and Event Management tools (SIEMs). The module will discuss the general concept of an IDS and how it works to detect attacks before highlighting specific IDS and SIEM products, such as Suricata, Splunk, Google SecOps (Chronicle), and Wazuh, respectively. Learners will then develop an understanding of how to access and navigate within Suricata and how basic rules are set up to provide alerts, events, and logs for malicious network traffic. This module will conclude with an introduction to Splunk, Google SecOps (Chronicle), and Wazuh, and will showcase some of their features, including common commands for search queries.
Grow with Google is an initiative that draws on Google's decades-long history of building products, platforms, and services that help people and businesses grow. We aim to help everyone – those who make up the workforce of today and the students who will drive the workforce of tomorrow – access the best of Google’s training and tools to grow their skills, careers, and businesses.
"To be able to take courses at my own pace and rhythm has been an amazing experience. I can learn whenever it fits my schedule and mood."
Jennifer J.
Learner since 2020
"I directly applied the concepts and skills I learned from my courses to an exciting new project at work."
Larry W.
Learner since 2021
"When I need courses on topics that my university doesn't offer, Coursera is one of the best places to go."
Chaitanya A.
"Learning isn't just about being better at your job: it's so much more than that. Coursera allows me to learn without limits."
Learner reviews
4.8
3,373 reviews
5 stars
84.17%
4 stars
11.49%
3 stars
2.84%
2 stars
0.71%
1 star
0.77%
Showing 3 of 3373
S
SE
4·
Reviewed on Jul 11, 2024
I loved this coursed and learned so much. The only thing I would have liked to see is if the all of the SIEM tools were integrated into a lab like many of the other labs are directly in the courses.
N
ND
4·
Reviewed on May 8, 2025
The professor’s teaching is excellent, making complex topics easy to understand. The study material provided is also awesome and very helpful for learning. Highly recommended!
U
US
5·
Reviewed on Oct 16, 2023
Learnt a lot about SIEM tools and much more that are all ready to be applied in the job. Thanks a lot to Google and Coursera for such a wonderful session.
When will I have access to the lectures and assignments?
To access the course materials, assignments and to earn a Certificate, you will need to purchase the Certificate experience when you enroll in a course. You can try a Free Trial instead, or apply for Financial Aid. The course may offer 'Full Course, No Certificate' instead. This option lets you see all course materials, submit required assessments, and get a final grade. This also means that you will not be able to purchase a Certificate experience.
What will I get if I subscribe to this Certificate?
When you enroll in the course, you get access to all of the courses in the Certificate, and you earn a certificate when you complete the work. Your electronic Certificate will be added to your Accomplishments page - from there, you can print your Certificate or add it to your LinkedIn profile.