MIVA STUDY PACK — Cybersecurity Technician (SOC Analyst) (English) Downloaded 2026-09-29. Free to pass on. Cybersecurity Technician (SOC Analyst) — Lesson 1: What Is Cybersecurity and Why It Matters 10 minutes read OBJECTIVE: By the end of this lesson you can explain what cybersecurity is and identify common real-life examples of its importance in West Africa. Have you ever heard stories of someone losing their entire month's salary to a scammer? Or seen warnings about fake messages from MTN or AirtelTigo? These are real-life examples of why cybersecurity is so important, right here in West Africa. Cybersecurity is all about protecting computers, networks, and all the information stored on them from bad actors like thieves, hackers, and even simple accidents. It's like having a strong lock on your shop door, but for the digital world. WHY CYBERSECURITY MATTERS IN OUR DAILY LIVES In Accra, Lagos, Lomé, and every busy market stall, mobile money has become a lifeline. It lets people pay for goods, send money to family, and manage their business without needing a bank. But this convenience also creates opportunities for fraudsters. In Ghana and Nigeria, one of the biggest threats is mobile money fraud. Scammers send fake SMS messages, pretending to be from your network provider. They might say there’s an issue with your account or that you’ve won a prize. Their goal? To trick you into giving away your PIN or transferring money to them. - Your bank account details: Protecting your savings from online theft. - Your mobile money PIN: Preventing scammers from emptying your wallet. - Your personal photos and messages: Keeping your private life private. - Business secrets: Ensuring a company's plans and customer lists are safe from competitors. As a cybersecurity technician, your job is to build and maintain these digital locks. You are the one who helps stop these attacks. You prevent the fraudster from stealing that month's salary. You protect people's privacy and their trust in digital services. Think about it: every business that uses computers—banks, hospitals, schools, your favourite phone repair shop, or even the small business selling clothes online—needs someone who understands how to keep their systems and data safe. [More Than Just Hacking] Cybersecurity isn't just about stopping master hackers. It's also about protecting against common mistakes. For example, accidentally deleting important files, or a power surge from a generator damaging computer systems. It's about making sure data is always available when needed and accurate. The digital world is growing fast in West Africa. More and more people are using smartphones, mobile apps, and online services. This means the demand for skilled cybersecurity professionals is exploding. Learning cybersecurity means you're not just getting a job; you're stepping into a career that protects communities, supports businesses, and makes the digital future safer for everyone. You'll be a digital guardian, and that’s a powerful role to play. PRACTICE QUESTIONS 1. What is one of the biggest cybersecurity threats in Ghana and Nigeria? A) Computer viruses from space B) Mobile money fraud through fake SMS messages C) Phones overheating from too many apps D) Slow internet connections Answer: B — Mobile money fraud is a major and common cyber threat in West Africa. Scammers often pretend to be staff from mobile network operators like MTN or AirtelTigo via SMS or phone calls to trick people into giving up their PINs or transferring money. Protecting these transactions is a huge and growing part of cybersecurity work in our region. 2. Which of these is NOT a reason why cybersecurity matters? A) To protect people's mobile money savings from fraudsters. B) To ensure businesses can operate without data theft. C) To make mobile phones lighter and easier to carry. D) To keep personal information, like photos and messages, private. Answer: C — Cybersecurity focuses on protecting digital information and systems from harm. Making phones lighter is a hardware design issue, not related to cybersecurity. ---------------------------------------- Cybersecurity Technician (SOC Analyst) — Lesson 2: Understanding Networks and IP Addresses 12 minutes read OBJECTIVE: By the end of this lesson you can describe how computer networks function and explain the purpose of an IP address in identifying devices. Have you ever wondered how your phone sends a message to your friend across town, or how you stream music from a server far away? It all happens because of computer networks. A computer network is simply a group of connected devices, like computers, phones, or even smart TVs, that can share information with each other. Think of it like a bustling market stall. Different vendors (devices) are all connected, buying and selling goods (data). YOUR DEVICE'S STREET ADDRESS: THE IP ADDRESS Every device connected to a network needs a unique way to be identified. This is where an IP address comes in. An IP address is like the street address for your phone or computer on the internet. Just as the postman needs your house number to deliver mail, the internet needs your device's IP address to send data directly to it. You'll often see IP addresses looking like a series of numbers separated by dots, for example, 192.168.1.1. This is called an IPv4 address. Imagine you’re at a busy cybercafe in Lagos. Each computer there has its own unique IP address so that when you ask for a website, the internet knows exactly which computer to send that website's information back to. Without it, everything would be chaos! - Local Area Networks (LANs): These are smaller networks, like the one in your home, office, or an internet cafe. All the devices are usually in one building or a small area. - Wide Area Networks (WANs): The biggest example of a WAN is the internet itself! It connects LANs and individual devices across huge distances, even across countries like connecting Accra to Lomé. - Wireless Networks (Wi-Fi): This uses radio waves to connect devices without cables. When you connect to 'Miva_Guest' Wi-Fi, you're joining a wireless network. When you send information, like a message, across a network, that data doesn't just magically appear at its destination. It travels in small packets. Devices called 'routers' act like intelligent postmen. They read the IP address on each data packet and decide the best path for it to travel to reach its destination. They forward the data from one network to the next until it arrives at the correct IP address. [Public vs. Private Networks] Networks can be public, like the internet where anyone can access many things, or private, like your home Wi-Fi network or your school's network. Private networks are usually protected. A 'firewall' is like a security guard at the entrance to a private network, checking everyone and everything that tries to come in or go out. It protects your private network from threats on the public internet, just like a gatekeeper for a generator room in a busy market keeps it safe. PRACTICE QUESTIONS 1. What is an IP address? A) A password for logging into a website B) A unique address that identifies a device on a network C) A type of computer virus D) A method for encrypting data Answer: B — An IP address is like a house number on a street. Without it, the postman cannot deliver your mail, and the internet cannot send data to your phone or computer. Every device connected to a network gets one — your phone, your laptop, even some smart TVs. It’s how devices find each other. 2. What is the main role of a router in a computer network? A) To create new IP addresses for devices B) To act as a security guard, blocking unwanted visitors C) To direct data packets to their correct destination based on IP addresses D) To store all the data that passes through the network Answer: C — Think of a router as a traffic controller or a postman for your data. When you send a message, the router looks at the destination IP address and figures out the best path for that data packet to travel, sending it along to the next part of the network until it reaches its goal. ---------------------------------------- Cybersecurity Technician (SOC Analyst) — Lesson 3: Types of Cyber Attacks 12 minutes read OBJECTIVE: By the end of this lesson you can identify and describe five common types of cyber attacks that target digital systems and data. Imagine your mobile money account. It holds your hard-earned cash, right? Now imagine someone trying to sneak in and steal it. That's what cyber attacks are like for computers and networks. They are attempts to damage, disrupt, or gain unauthorised access to digital systems. As a future Cybersecurity Analyst, understanding these attacks is your first line of defense. You need to know how they work so you can stop them. Let's look at five common types you will definitely encounter. FIVE COMMON CYBER ATTACK TYPES - Phishing: This is like a scam artist sending you a fake text or email that looks real. It might pretend to be from your bank, MTN, or even a government office. Their goal? To trick you into giving up private info like your password, PIN, or even your mobile money OTP. - Malware: Think of malware as unwanted software that sneaks onto your phone or computer. It could be a virus, a worm, or ransomware. Once it's in, it might steal your data, spy on you, or even lock your device until you pay a 'ransom' — like those hackers who target businesses in Lagos. - Man-in-the-Middle (MitM) Attack: Imagine you are talking to a friend, but someone secretly listens to every word and can even change your messages without you knowing. That's a MitM attack. The attacker secretly intercepts communication between two parties, often on public Wi-Fi networks. - Brute Force Attack: This is a tireless attacker who tries every possible password combination until they guess yours. It's like trying every key on a huge keychain until one opens the lock. They use special programs that can try thousands of passwords in seconds. - Distributed Denial of Service (DDoS) Attack: Picture a busy market in Accra, suddenly flooded with so many people that no one can buy or sell anything. A DDoS attack does the same to a website or server. It overwhelms it with so many fake requests that the real users can't access it, causing it to crash. [Local Example: Smishing is Everywhere] In West Africa, you probably see phishing a lot, especially through SMS. We call this 'smishing'. You might get a message saying, 'Your account has been suspended. Click here to verify' with a link. That link leads to a fake website designed to steal your login details. Recognising these patterns is a key skill for any SOC (Security Operations Centre) Analyst. Always verify through official channels before you click! These attacks are always evolving, just like how criminals find new ways to break into houses. Your job will be to stay one step ahead. Learning these basics is your foundation. In the next lessons, we'll dive deeper into how to protect systems from these threats. PRACTICE QUESTIONS 1. What is 'phishing'? A) A type of computer game B) Fake messages pretending to be from a trusted source to steal information C) A method for fixing broken networks D) A way to speed up internet connections Answer: B — Phishing is like a scammer wearing a bank uniform and standing outside a real bank — they look official, but they are fake. The goal is to trick you into handing over your PIN, password, or OTP. Always verify through official channels before responding to urgent account messages. 2. Which type of cyber attack involves overwhelming a website or server with so many fake requests that it crashes, preventing real users from accessing it? A) Malware attack B) Brute Force attack C) Distributed Denial of Service (DDoS) attack D) Man-in-the-Middle (MitM) attack Answer: C — A DDoS attack is like a massive crowd blocking the entrance to a shop, making it impossible for real customers to get in. It floods the target with traffic, causing it to become unavailable. ---------------------------------------- Cybersecurity Technician (SOC Analyst) — Lesson 4: Passwords and Authentication 10 minutes read OBJECTIVE: By the end of this lesson you can describe the characteristics of a strong password and explain authentication methods for account protection. Imagine your valuable belongings – your mobile phone, your cash, your important papers – locked safely inside a room. The lock on that door is like your password online. If the lock is weak, anyone can get in. But if it's strong, your things are protected. In cybersecurity, your password is often the very first line of defense against online thieves trying to get into your accounts. CRAFTING STRONG PASSWORDS So, what makes a password strong? It's not just about making it hard to remember for you. It's about making it nearly impossible for a computer program to guess. A strong password has at least 12 characters. It mixes uppercase letters (like 'A', 'B'), lowercase letters (like 'a', 'b'), numbers (like '1', '2'), and symbols (like '!', '@', '#'). An example of a decent password might be 'KofiAma1988!'. Something like 'password123' is very weak and easily guessed. [Pro Tip: Passphrases] The best approach for a truly strong and memorable password is a passphrase. This is usually four or more random words connected together. Think 'correct-horse-battery-staple' or 'market-orange-mountain-table'. Humans can remember these because they tell a tiny story. But for a computer trying to guess, finding four random words in the right order is incredibly difficult. Long and memorable beats short and complicated every time! Even the strongest password can sometimes be stolen, maybe through a tricky email called 'phishing'. This is where Two-Factor Authentication, or 2FA, comes in. Think of it as a second lock on your door. Even if a thief has your key (your password), they still need a special code to get in. This code usually comes to your mobile phone. - You enter your password as usual. - The service then sends a unique, one-time code to your registered phone number, often via SMS or a special app. - You enter this code to complete your login. Many services you use every day, especially financial ones, now require 2FA. In Ghana, for example, many banks and mobile money services like MTN Mobile Money or Vodafone Cash already use 2FA to protect your funds. This extra step might feel like a hassle sometimes, but it's a huge boost to your security. As a cybersecurity technician, you will help businesses set up 2FA for their staff and teach them why it's so important. Education is a big part of cybersecurity – most breaches happen because someone made a simple mistake, not because a hacker was a genius. PRACTICE QUESTIONS 1. What makes a passphrase stronger than a regular password? A) It is shorter and easier to type B) It uses four random words that are easy to remember but hard to guess C) It contains only numbers D) It never expires Answer: B — A passphrase like 'market-orange-mountain-table' is long and complex enough to be very hard for a computer to guess (it has 27 characters in this example!). But for a human, it's much easier to remember than 'Kq!8$pZf@tY#'. Passphrases combine length, complexity, and memorability into one powerful security tool. 2. Why is Two-Factor Authentication (2FA) considered an important security measure? A) It makes your password shorter and easier to remember. B) It eliminates the need for any password at all. C) It adds a second layer of verification, making it harder for unauthorized access even if a password is stolen. D) It only works with very old mobile phones. Answer: C — 2FA acts like a second lock. Even if someone gets your password (the first lock), they still need that unique code sent to your phone (the second lock) to get into your account. This significantly increases security against unauthorized access. ---------------------------------------- Cybersecurity Technician (SOC Analyst) — Lesson 5: Introduction to Security Operations Center (SOC) 10 minutes read OBJECTIVE: By the end of this lesson you can define what a Security Operations Center (SOC) is and describe its main role in protecting digital systems. WHAT IS A SOC? Imagine a busy market in Accra or Lagos. There are many stalls, lots of people, and goods being moved around. Now, imagine a special security team dedicated to watching over this market 24 hours a day, 7 days a week. Their job is to keep everything safe and spot trouble before it becomes a big problem. That’s exactly what a Security Operations Center, or SOC, does for computer systems and networks. A SOC is a dedicated team of security analysts. They are the eyes and ears of an organisation's digital world. Their main goal is to protect all the computer systems, servers, websites, and data from cyber threats. They work together, sharing information and skills, to ensure nothing dangerous slips through. YOUR ROLE AS AN ENTRY-LEVEL SOC ANALYST As an entry-level SOC analyst, you are like the front-line security guard. Your main tasks will involve monitoring security alerts, investigating them to understand what's happening, and then escalating (passing on) any real threats to more experienced team members. You are crucial because you’re the first to spot potential danger. Think of a SOC like a neighborhood watch. There are many security cameras (these are the monitoring tools) installed all over the neighborhood, constantly recording everything. If motion is detected at 2 AM at a shop that should be closed, an alert immediately pops up on your screen. You, the analyst, check the camera feed — is it a thief trying to break in, or just a stray cat? Most alerts are like those stray cats (what we call 'false positives'). Your job is to quickly sort through these, identify the real thieves (actual threats), and immediately call for help from your senior colleagues. [What is SIEM?] To do their job, SOC teams use powerful tools. One of the most important is a SIEM, which stands for Security Information and Event Management platform. Think of it as a central dashboard that collects information (logs) from every computer, server, and network device. When something looks suspicious – like someone trying to log into an account many times from a strange location – the SIEM will flag it immediately with an alert. It’s like a smart alarm system for the entire digital infrastructure. - Monitor alerts generated by security tools like SIEM. - Investigate suspicious activities to determine if they are real threats or false alarms. - Document your findings clearly and accurately. - Escalate genuine security incidents to senior SOC analysts or incident responders. - Participate in improving security processes and tools. PRACTICE QUESTIONS 1. What does a SIEM platform do? A) Sells antivirus software to customers B) Collects security logs and alerts when suspicious activity is detected C) Manages employee salaries and benefits D) Creates marketing campaigns for businesses Answer: B — SIEM is like a central alarm system for a whole building. Instead of each door having its own alarm that nobody watches, SIEM collects all alarms and events from across the network into one screen. When suspicious activity, like someone trying to log in too many times, occurs, the SIEM flashes a red alert for the analyst to investigate. It helps SOC teams see and react to potential threats quickly. 2. As an entry-level SOC analyst, what is your primary responsibility when an alert comes in? A) Immediately delete the alert to reduce clutter. B) Investigate the alert to determine if it is a real threat or a false alarm. C) Send a general email to all employees warning them about the alert. D) Turn off the system that generated the alert to prevent further issues. Answer: B — Your main job as a junior SOC analyst is to act as the first line of defense. When an alert pops up, you need to investigate it to understand what's happening. Is it a harmless event (a false positive) or a genuine security threat? This careful investigation helps the team decide the next steps, protecting the organization's digital assets without causing unnecessary panic. ---------------------------------------- Cybersecurity Technician (SOC Analyst) — Lesson 6: Mobile Money Security Threats 12 minutes read OBJECTIVE: By the end of this lesson you can identify common mobile money security threats and describe how fraudsters operate in West Africa. Mobile money has changed how we live and work across West Africa. Sending money to family in another city, paying for goods at a market stall in Accra, or settling bills in Lagos – it's all so much easier. But with this convenience comes risk. Fraudsters are always looking for new ways to steal your hard-earned money. As a future cybersecurity technician, understanding these threats is your first step to fighting them. COMMON MOBILE MONEY FRAUDS Mobile money fraud in places like Ghana and Nigeria takes many forms. Fraudsters are cunning and constantly adapt their tricks. You need to know their methods to stop them: - Fake Transfer Confirmations: A fraudster sends a fake SMS that looks exactly like a real mobile money receipt. It shows money was sent to you, but no actual transaction happened. They might use this to trick market vendors or small business owners into releasing goods without payment. - PIN Harvesting (Phishing): Fraudsters call you, pretending to be a customer service agent from your bank or mobile money provider. They will tell you there’s a 'problem' with your account and ask you to 'verify' your Personal Identification Number (PIN) or other sensitive details. They are trying to 'harvest' your PIN – steal it – so they can access your account. - SIM Swap Fraud: This is a very dangerous trick. Fraudsters convince your mobile network provider (like MTN, Vodafone, or AirtelTigo) to transfer your phone number to a new SIM card that they own. Once your number is on their SIM, all your calls, SMS, and crucial One-Time Passwords (OTPs) for logging into your mobile money or bank accounts go straight to them. They can then drain your accounts. [Always Be Suspicious] Your mobile money provider will NEVER ask for your PIN, passwords, or full card details over the phone or by SMS. If someone asks, they are a fraudster. Hang up immediately and report the number. As a cybersecurity technician working for a fintech company or a bank, you will be on the front lines of this battle. You'll investigate these fraud patterns, identify how they happen, and build robust systems to detect them automatically. You’ll also play a key role in educating customers on how to protect themselves. Understanding how fraudsters think is essential for good security. The best security professionals can 'think like an attacker.' This means anticipating what tricks the next scammer will try, how they might exploit a weakness, and what steps you can take to stop them before they succeed. It’s like a game of chess, always thinking several moves ahead to protect users and their money. PRACTICE QUESTIONS 1. What is SIM swap fraud? A) Stealing someone's physical phone B) Transferring someone's phone number to a new SIM to intercept their OTPs C) Damaging someone's SIM card D) Copying someone's contacts list Answer: B — SIM swap is dangerous because the fraudster does not need your physical phone. They trick your mobile network provider into activating a new SIM with your existing number. This reroutes all your calls, SMS, and critical One-Time Passwords (OTPs) to them, allowing them to access your accounts. It's like someone redirecting all your mail to their address without you knowing, but with your digital identity. 2. You receive an SMS that looks like a mobile money alert, showing a large sum transferred to you. A few minutes later, someone calls claiming to be from your network provider and asks for your PIN to 'confirm' the transfer. What is the most likely threat here? A) SIM swap fraud B) Fake transfer confirmation combined with PIN harvesting C) A genuine customer service call D) An attempted password reset Answer: B — This scenario describes a classic two-pronged attack: first, a fake SMS is sent to trick you into believing a real transaction occurred (fake transfer confirmation). Then, the fraudster calls, pretending to be a legitimate representative and asks for your PIN under false pretenses (PIN harvesting). Your network provider will never ask for your PIN. ---------------------------------------- Cybersecurity Technician (SOC Analyst) — Lesson 7: Incident Response Basics 10 minutes read OBJECTIVE: By the end of this lesson you can define a security incident and explain the basic steps involved in responding to such an event. Imagine running your own small business, maybe a mobile phone repair shop in Accra, or a provision store in Lagos. One day, your digital payment system stops working. Or maybe your computer, used for tracking inventory, starts acting strangely. It’s like discovering your generator won’t start when there’s a power cut. Something is wrong, and it needs fixing fast. In the world of cybersecurity, we call this a security incident or a breach. It’s when someone unauthorized gets into your systems, or when something goes wrong that threatens your data. Knowing how to react quickly and effectively is crucial. It can save you a lot of money, protect your customers, and keep your business running. THE INCIDENT RESPONSE PLAYBOOK When a security breach happens, following a clear set of steps helps you manage the chaos. Think of it like a recipe. You don't just guess what to do next. You follow the steps to get the best result. In cybersecurity, we use an 'Incident Response Plan'. Here are the key steps: - Detect: This is when you first notice something is wrong. Maybe your security system (called a SIEM) alerts you, or a user reports strange activity, like their computer slowing down or unusual pop-ups. - Contain: This is about stopping the problem from getting worse. You isolate the affected system to prevent the attack from spreading to other parts of your network. Think of it like shutting the door on a thief. - Eradicate: Once contained, you remove the threat. This means cleaning out any malware, closing the vulnerability (the weak spot) that allowed the attack, or deleting malicious accounts. - Recover: After cleaning, you bring your systems back online. This often involves restoring data from clean backups and making sure everything is working correctly and securely. - Document: Finally, you write a report. What happened? How did you fix it? What can you do to prevent it from happening again? This helps you learn and improve. [Why Containment is Key] The most important step, especially early on, is containment. If you discover a compromised computer on a network – meaning an attacker has control of it – you must disconnect it immediately. Pull the ethernet cable, disable the WiFi, or block its network access. This is like seeing a thief in one room of your house and locking that door. You don’t chase the thief into other rooms first; you make sure they cannot move to other parts of the house. This prevents the attacker from moving to other computers or stealing more data. This structured approach helps you calmly handle what can be a very stressful situation. Each step builds on the last, ensuring you don't miss critical actions that could prevent future attacks. Just like how a good mechanic follows steps to fix an engine, an incident responder follows steps to fix a security problem. PRACTICE QUESTIONS 1. What is the FIRST thing you should do when you detect a compromised computer on a network? A) Delete all files on the computer B) Call the police C) Disconnect it from the network to contain the threat D) Turn off all computers in the building Answer: C — Containment is the immediate priority. Think of a burst water pipe in your compound. You don't start mopping the floor while water is still spraying everywhere. You shut off the main valve first. Disconnecting the compromised computer stops the attacker from spreading to other machines or stealing more information. It's like putting a stop to the 'bleeding' before you start cleaning up. 2. Which step in incident response involves restoring systems from backups and ensuring they are clean? A) Detect B) Eradicate C) Recover D) Document Answer: C — The 'Recover' step is all about bringing your systems back to a normal, safe state after an attack. This includes restoring from trusted backups, reconfiguring systems, and verifying that everything is clean and secure before full operation resumes. Eradication focuses on removing the threat, but recovery is about getting back to normal business. ---------------------------------------- Cybersecurity Technician (SOC Analyst) — Lesson 8: Getting Your CompTIA Security+ Certification 10 minutes read OBJECTIVE: By the end of this lesson you can identify the CompTIA Security+ certification and explain its importance for entry-level cybersecurity roles. Hello, future cybersecurity professional! You've learned about different cybersecurity roles and the skills you need. Now, let's talk about a big step: getting certified. A certification proves you have certain skills. For many entry-level cybersecurity jobs, the CompTIA Security+ certification is what employers look for. It's like having a special badge that says, 'I know my stuff!' WHAT IS COMPTIA SECURITY+? CompTIA Security+ is a global certification. It covers the core knowledge you need for any cybersecurity role. Think of it as your foundation. This certification shows you understand how to keep computer systems and data safe. It covers important topics like spotting cyber threats, securing networks, managing user identities, and knowing what to do when an incident happens. These are skills you'll use every day in a job like a Security Operations Centre (SOC) analyst. - Threats, Attacks, and Vulnerabilities: Learning about different types of cyber attacks and how to protect against them. Imagine guarding a mobile money agent's kiosk from thieves. - Architecture and Design: Understanding how to build secure networks and systems. Like designing a strong lock for your shop. - Implementation: Setting up and configuring security controls. This is like installing a security camera and making sure it works. - Operations and Incident Response: Knowing what to do when an attack happens and how to recover. If a generator breaks down, you know how to fix it fast. - Governance, Risk, and Compliance: Following rules and laws to keep data safe. This means understanding privacy laws like those protecting bank customer data. [Why is Security+ Important for West Africa?] In countries like Ghana, Nigeria, and Togo, digital services are growing fast. Mobile banking, e-commerce, and government services all rely on strong cybersecurity. Companies like MTN, Access Bank, and Ecobank often look for Security+ when hiring for their cybersecurity teams. It shows you have the foundational skills they need to protect their customers and operations. The exam for Security+ has about 90 multiple-choice and performance-based questions. Performance-based questions are hands-on scenarios where you show what you'd do. You get 90 minutes to complete it. The exam costs around $370 USD, which is a significant investment. But it’s an investment in your future career. You can prepare for the exam in different ways. Many free resources are available online, like Professor Messer's YouTube course. He explains everything clearly. There are also paid courses on platforms like Udemy, which might offer more structured learning. A good study strategy is to spend about three months learning all the material, then one month focusing on practice exams. This helps you get used to the question style and manage your time. After this, you should be ready to take the test and earn your certification. PRACTICE QUESTIONS 1. What is the passing score for the CompTIA Security+ exam? A) 500 out of 900 B) 600 out of 900 C) 750 out of 900 D) 900 out of 900 Answer: C — The passing score is 750 out of 900 (about 83%). This means you can miss some questions and still pass. Focus on understanding concepts, not memorizing facts — the exam tests whether you can think through security scenarios, not just repeat definitions. Don't be scared if you don't get every single question right! 2. Which of these companies in West Africa is likely to list CompTIA Security+ as a requirement for cybersecurity roles? A) A small market stall vendor in Lagos B) MTN, a large telecommunications company C) A local tailor in Lome D) A farmer selling yams in Accra Answer: B — Large tech and financial companies like MTN handle vast amounts of sensitive data and have complex IT infrastructures. They require certified professionals to protect their systems from cyber threats, making CompTIA Security+ a valuable and often required certification for their cybersecurity teams. Small businesses or individuals like market vendors, tailors, or farmers typically do not have the same level of cybersecurity needs or formal hiring processes for such certifications. ---------------------------------------- Cybersecurity Technician (SOC Analyst) — Lesson 9: Ethical Hacking and Legal Boundaries 8 minutes read STAYING ON THE RIGHT SIDE OF THE LAW When you learn cybersecurity skills, you learn how systems work and how they break. You learn how attackers scan networks, find weak passwords, and exploit software. These skills are powerful. Used correctly, they help protect small businesses, banks, and mobile money systems in places like Accra, Lagos, and Lomé. Used wrongly, they can destroy livelihoods and land you in prison. In cybersecurity, the boundary between legal work and criminal activity comes down to one clear word: authorization. If you have explicit, written permission from the owner of a computer network to test it, you are conducting authorized security testing. If you do not have written permission, scanning or logging into that system is illegal cybercrime, regardless of your intention. [Critical Warning on Authorization] Never attempt to scan, probe, or test any network, website, or mobile money app that you do not own or do not have written legal authorization to test. Even scanning a local business website out of curiosity can trigger security alerts and lead to police investigation or prosecution under national cybercrime laws. WHITE HAT VS. BLACK HAT CYBERSECURITY In the technology industry, security practitioners are often described using hat colors: - White Hat: Ethical security professionals who use their skills to protect organizations. They always work with legal authorization and follow strict rules. - Black Hat: Cybercriminals who breach systems without permission to steal money, lock files for ransom, or cause damage. - Grey Hat: Individuals who look for security flaws without permission, then try to contact the owner to report the flaw. Even if grey hats mean well, their actions are illegal in most countries. UNDERSTANDING SCOPE AND RULES OF ENGAGEMENT When a company hires an ethical hacker or security auditor, they sign a contract containing a document called the Scope. The Scope defines exactly which servers, IP addresses, or applications you are allowed to touch. It also lists off-limits systems. For example, a contract might allow you to test a company's public website (example.com), but forbid you from touching their payment portal or internal HR server. If you test a server outside the agreed Scope, you have broken the law and your contract. PRACTICING LEGALLY ON SAFE PLATFORMS You do not need to risk breaking the law to gain real hands-on practice. There are legal platforms built specifically for learning and testing skills: - TryHackMe and Hack The Box: Online virtual labs designed for beginners and advanced learners to attack and defend fake networks legally. - Bug Bounty Platforms: Websites like HackerOne and Bugcrowd list companies (like Google, Uber, or banks) that invite security researchers to find bugs legally in exchange for cash rewards or recognition. - Home Virtual Labs: Setting up your own virtual machines on your laptop using free software like VirtualBox. [Try This Today] Create a free account on TryHackMe or Hack The Box using your email. Complete your first beginner room (such as 'Intro to Cybersecurity' or 'Linux Fundamentals') to practice legal hands-on security skills without breaking any laws. PRACTICE QUESTIONS 1. What makes cybersecurity testing legal versus illegal? A) Whether you use specialized software like Linux or Windows. B) Having explicit, written permission from the system owner before testing. C) Whether you fix the problem after finding it. D) Testing systems during late night hours when traffic is low. Answer: B — Explicit, written permission (authorization) is what separates legal ethical hacking from illegal cybercrime. Without permission, any testing is illegal. 2. In ethical hacking contracts, what does the term 'Scope' refer to? A) The total amount of money the hacker gets paid. B) The brand of laptop used to complete the job. C) The list of specific systems and IP addresses you are legally allowed to test. D) The number of hours you spend sleeping during a test. Answer: C — Scope defines the boundaries of security testing. It lists exactly which targets are permitted and which ones are strictly off-limits. ---------------------------------------- Cybersecurity Technician (SOC Analyst) — Lesson 10: Building a Cybersecurity Portfolio on a Budget 8 minutes read WHY PROOF OF SKILL MATTERS Many people think you must spend thousands of dollars or Naira on certifications before you can get hired in cybersecurity. While certifications help, hiring managers in tech hubs like Lagos, Accra, or remote companies care most about one thing: Can you actually do the work? A portfolio is a public collection of your hands-on work. It proves that you know how to analyze network logs, set up firewalls, or write basic security scripts. You can build a strong, professional portfolio completely for free using simple tools on a basic laptop. BUILDING YOUR FREE HOME LAB A home lab is a isolated environment created on your personal computer where you can simulate real corporate networks. You do not need expensive server equipment. You only need a standard laptop with at least 8GB of RAM. - VirtualBox: Free software that lets you run multiple operating systems inside your computer. - Ubuntu Linux or Kali Linux: Free Linux operating systems used widely by security professionals. - Wireshark: Free network analyzer tool used to inspect traffic moving across a network. - pfSense or Security Onion: Free open-source security and firewall software. THREE FREE PROJECTS FOR YOUR PORTFOLIO Here are three simple, practical projects you can build and document to show employers: - Network Traffic Analysis: Capture network traffic using Wireshark on your home network, identify unencrypted passwords or suspicious DNS requests, and write a summary report. - SIEM Log Analysis Setup: Install free software like Splunk Free or Elastic Stack, send sample server logs to it, and build a simple dashboard that flags failed login attempts. - TryHackMe Room Write-ups: Solve a room on TryHackMe, explain your methodology step-by-step in your own words, and show how you found and patched vulnerabilities. [Protect Sensitive Information] When publishing portfolio write-ups or screenshots online, never reveal private IP addresses, personal passwords, or real company data. Always blur out sensitive details before posting publicly. WHERE TO PUBLISH YOUR WORK Once you complete a project, store and present it where employers can find it: - GitHub: Create a free GitHub profile to upload your code, setup scripts, or written reports in Markdown format. - Medium or Hashnode: Write short, clear blog posts explaining what you built, problems you faced, and how you solved them. - LinkedIn Articles: Share short summary posts of your home lab builds with screenshots to attract recruiters. [Try This Today] Download VirtualBox (free) on your computer. Download a free Linux ISO image (like Ubuntu Desktop). Install Ubuntu inside VirtualBox to start building your personal home security lab. PRACTICE QUESTIONS 1. What is the main purpose of a cybersecurity portfolio for an entry-level job seeker? A) To show how many expensive laptops you own. B) To provide concrete proof of your practical hands-on skills to employers. C) To hide your work from hiring managers until you get hired. D) To replace the need for speaking English during job interviews. Answer: B — A portfolio demonstrates practical skills. It gives hiring managers physical evidence that you can perform real security tasks. 2. Which free tool allows you to run multiple virtual computers on a single personal laptop? A) VirtualBox B) WhatsApp C) Google Docs D) Canva Answer: A — VirtualBox is free virtualization software that lets you run operating systems like Linux inside your existing computer. ---------------------------------------- Cybersecurity Technician (SOC Analyst) — Lesson 11: Finding Cybersecurity Jobs and Avoiding Scams 8 minutes read NAVIGATING THE ENTRY-LEVEL JOB MARKET Finding your first job or internship in cybersecurity requires active networking, especially in competitive markets across West Africa and remote international spaces. Waiting passively on job boards is rarely enough. You need a clear plan to connect with local tech professionals. OPTIMIZING LINKEDIN BASIC FOR FREE You do not need to pay for LinkedIn Premium to land an entry-level role. A clean LinkedIn Basic profile works well if set up properly: - About Section: Summarize your interest in cybersecurity, what you are building in your home lab, and what skills you are actively practicing. - Featured Section: Pin links to your GitHub projects, TryHackMe achievements, or blog posts. - Connect with Purpose: Send personalized connection requests to IT managers, SOC leads, and recruiters in towns like Lagos, Accra, or Toronto. Include a polite short message explaining you are an aspiring analyst interested in their career path. LEVERAGING LOCAL TECH COMMUNITIES AND WHATSAPP GROUPS In West Africa, many entry-level opportunities, paid internships, and contract gigs are shared inside tech communities before they reach public job boards. - WhatsApp & Telegram Groups: Join local tech hubs (like Cybersecurity Nigeria, DevCongress Ghana, or regional developer groups). Members frequently share junior job leads. - Local Meetups: Attend free tech meetups or virtual webinars hosted by local ISACA or OWASP chapters. - Volunteer Work: Offer to help local small businesses or non-profits check their office router settings or staff password policies for free to gain reference contacts. AVOIDING JOB SCAMS AND FAKE RECRUITMENT Cybersecurity job seekers are frequently targeted by scammers who take advantage of people looking for employment. You must learn to spot fake job offers. - Upfront Fee Scams: Anyone asking you to pay money for 'application processing', 'training materials', or 'background checks' is a scammer. - Equipment Cheque Scams: Fake employers who send you a fake cheque to buy laptop equipment from a 'specific vendor' online. - Unprofessional Communication: Job offers sent via WhatsApp or Telegram without an official interview or company domain email (e.g., using @gmail.com instead of @company.com). [Golden Rule of Job Hunting] A legitimate employer will NEVER ask you to pay money to secure a job or internship. If an recruiter demands 5,000 Naira, 100 Cedis, or 5,000 CFA for processing fees, stop talking to them immediately. [Try This Today] Search LinkedIn for 'Cybersecurity Accra' or 'Cybersecurity Lagos'. Find two local professionals working as SOC Analysts or IT Security Specialists, and send them a polite connection request asking one thoughtful question about how they got started. PRACTICE QUESTIONS 1. What is a major red flag that indicates a job offer is a fake scam? A) The employer conducts a technical interview on Zoom. B) The company asks you to pay money upfront for registration or training fees. C) The hiring manager asks to see your GitHub portfolio. D) The position requires working in shift rotations. Answer: B — Legitimate companies pay you for work; they never require job seekers to pay application or processing fees. 2. How can you effectively use LinkedIn Basic without paying for a subscription? A) By adding false work history to make your profile look senior. B) By optimizing your headline, feature links to your real lab projects, and connecting politely with local industry leads. C) By sending automated spam messages to 500 people every day. D) By posting non-technical viral memes to get maximum likes. Answer: B — A clean profile showcasing real lab projects and thoughtful networking with local leads is effective and completely free. ---------------------------------------- Cybersecurity Technician (SOC Analyst) — Lesson 12: First Month as a Junior SOC Analyst 8 minutes read STEPPING INTO YOUR FIRST ROLE Landing your first job as a Security Operations Center (SOC) analyst or IT security assistant is a massive achievement. However, the first month can feel overwhelming. You will face strange software dashboards, hundreds of daily alert notifications, and team terminology you have never heard before. Success in your first 30 days is not about knowing every answer immediately. It is about building strong professional habits, communicating clearly, and being dependable. UNDERSTANDING ALERT TRIAGE AND TICKETS In a SOC, security alerts are generated automatically by monitoring systems when something unusual happens. Your job as a Tier 1 analyst is to investigate these alerts, known as 'alert triage'. - True Positive: A real security incident (for example, malware detected on an employee's laptop). - False Positive: A harmless event that triggered a security alert (for example, an employee logging in while traveling on vacation in Kumasi or Abuja). - Documentation: Every alert you investigate must have notes attached explaining why you closed it or why you escalated it. THE 15-MINUTE RULE FOR PROBLEM SOLVING When you encounter a technical problem or log alert you do not understand, follow the 15-minute rule before asking senior team members: - 1. Try to research the error code or IP address yourself for 15 minutes using internal documentation or search engines. - 2. Write down what steps you took, what tools you used, and what you discovered. - 3. If you are still stuck after 15 minutes, ask a senior colleague. Show them your notes so they see you tried first. [Never Cover Up a Security Mistake] If you accidentally click a malicious link during testing, close a critical alert by mistake, or misconfigure a firewall rule, inform your manager immediately. In cybersecurity, hiding an error causes massive breaches. Admitting a mistake early allows the team to fix it safely. CORE HABITS FOR FIRST-MONTH SUCCESS Adopt these practical habits to build trust quickly with your supervisor: - Take Detailed Notes: Keep a private digital notebook (like Obsidian or OneNote) recording daily commands, internal IP ranges, and team procedures. - Master Shift Handovers: When ending your shift, write clear summary notes for the incoming analyst so no unresolved alerts drop through the cracks. - Stay Calm Under Pressure: High alert volumes are normal. Focus on quality analysis for one ticket at a time rather than rushing through blindly. [Try This Today] Practice writing a clear, professional ticket note. Imagine a user failed their login password 5 times because their keyboard caps lock was on. Draft a 3-sentence summary note explaining the event, your investigation, and why you closed the ticket as a false positive. PRACTICE QUESTIONS 1. What should a junior SOC analyst do immediately if they accidentally make a mistake that affects network security? A) Delete all log records so no one notices. B) Inform their team lead or manager immediately so it can be mitigated. C) Turn off their computer and leave the office. D) Blame another teammate during the next shift. Answer: B — Honesty and fast communication are essential. Reporting errors immediately allows the team to secure the network before damage occurs. 2. What is a 'False Positive' in security operations? A) A serious hacker attack that destroys all backup servers. B) A harmless, normal event that mistakenly triggered a security alert. C) A password that contains numbers and special symbols. D) An alert that is automatically sent to the police. Answer: B — A false positive occurs when legitimate activity (like an employee logging in while on business travel) triggers an automated security warning. ---------------------------------------- Cybersecurity Technician (SOC Analyst) — Lesson 13: Build Your Professional Profile 10 min read OBJECTIVE: Set up a simple, honest professional presence online so employers and customers can find and trust you. Before someone hires you or buys from you, they often look you up. A professional profile is simply a clean, honest page that answers three questions: who are you, what can you do, and how can someone reach you? You do not need to be famous or have a computer. A phone and one good photo are enough to start. START WITH WHAT IS FREE - WhatsApp Business — free app. Add your trade, working hours, location and a short catalogue of your work or services. Many customers in West Africa will find you here first. - Google Business Profile — free. If you have a shop, workshop or stall, this puts you on Google Maps so people nearby can find you. - LinkedIn (free Basic account) — useful if you want office, NGO or company work. Add a clear photo, your trade or skill, and two or three lines about what you have done. - Local job and trade groups — Facebook and WhatsApp groups for your town or trade are where many real opportunities are shared first. You do not need all four on day one. Pick the one where your customers or employers actually are. A tailor or caterer may get more from WhatsApp Business and local groups; an IT support learner may need LinkedIn first. Add the others over time. WHAT MAKES A PROFILE TRUSTWORTHY - A real photo of you — face visible, plain background, neat clothing. No sunglasses, no filters. - Your real name, written the same way everywhere. - One honest sentence about what you do: 'I install and repair solar home systems in Hohoe.' - Proof: photos of finished work, a certificate, or a short quote from a happy customer. - A phone number or WhatsApp link that actually works. [Protect yourself] Never pay anyone who promises to 'verify' your profile or guarantee you a job for a fee. Real platforms like LinkedIn, WhatsApp Business and Google Business Profile are free to set up. Anyone asking for money to list you is likely a scammer. [Try this today] Write your one honest sentence — who you are and what you do — and save it in your notes. You will reuse it in every profile, CV and introduction from now on. PRACTICE QUESTIONS 1. Which of these is free to set up and puts your workshop on Google Maps? A) A paid business directory B) Google Business Profile C) A printed flyer D) A website you pay a developer for Answer: B — Google Business Profile is free and places your business on Google Maps and Search, so people nearby can find you. You only need a phone and your business details. 2. What is the most important quality of a professional profile photo? A) It was taken by a professional photographer B) It uses an attractive filter C) Your face is clearly visible and you look neat D) It shows you with expensive items Answer: C — Employers and customers want to see a real, trustworthy person. A clear, neat photo with a plain background builds more trust than any filter or expensive backdrop. ---------------------------------------- Cybersecurity Technician (SOC Analyst) — Lesson 14: Write Your Goals and Plan for Obstacles 10 min read OBJECTIVE: Turn a wish into a written goal, review it weekly, and use if-then plans to handle the obstacles that usually stop you. A goal that stays in your head is a wish. A goal written down, with a date and a next step, is a plan. Research on how people actually change their behaviour keeps finding the same thing: people who write their goals down, check them regularly, and decide in advance what to do when things go wrong are far more likely to finish what they start. WRITE IT DOWN, THE PRACTICAL WAY - One goal at a time. 'Finish the solar course by 30 November' beats five vague wishes. - Make it checkable. You should be able to say 'done' or 'not done' — not 'I tried my best'. - Give it a date. A goal without a date quietly becomes 'someday'. - Write the very next small step. Not 'get a job' but 'message two hardware shops on Saturday morning'. - Keep it where you will see it — a notebook, a note on your phone, or paper on the wall. THE WEEKLY REVIEW — 15 MINUTES THAT CHANGE EVERYTHING Pick one fixed moment each week — Sunday evening works well for many people. Ask yourself three questions: What did I finish this week? What got in my way? What is my next step for the coming week? Write the answers down. This small habit catches problems while they are still small, and it reminds you that you are moving, even when progress feels slow. IF-THEN PLANS: DECIDE BEFORE THE OBSTACLE ARRIVES Most plans fail at the same predictable moments: the data bundle runs out, a friend invites you out on study night, rain cancels the job you planned. An if-then plan is a decision you make now, so a hard moment does not require willpower later. The format is simple: 'IF [obstacle happens], THEN I will [specific action].' - IF my data finishes, THEN I will study from my downloaded offline lessons instead. - IF it rains on the day I planned to visit shops, THEN I will call them instead and visit the next day. - IF I feel too tired to study at night, THEN I will do just 10 minutes — starting is the hard part. - IF a customer delays payment, THEN I will send one polite reminder after three days, not argue. [A note on visualisation] Imagining your goal can help — but picture the steps, not just the reward. Instead of only dreaming about the certificate on your wall, picture yourself opening the lesson, answering the quiz, and messaging the customer. Picturing the process prepares you; picturing only the prize can actually relax you into doing nothing. [Try this today] Write one goal with a date, then write two if-then plans for the obstacles most likely to stop you. Keep them somewhere you will see this week. PRACTICE QUESTIONS 1. What makes a goal 'checkable'? A) It is written in English B) You can clearly say whether it is done or not done C) Other people approve of it D) It is ambitious enough to impress people Answer: B — A checkable goal has a clear finish line: 'finish 8 lessons by Friday' can be marked done or not done. 'Do my best' cannot — and vague goals are easy to quietly abandon. 2. Your study night arrives and your data bundle has run out. What does a good if-then plan do? A) It forces you to buy more data immediately B) It tells you to skip studying until next week C) It gives you a decision you made in advance, like switching to your downloaded offline lessons D) It punishes you for not planning better Answer: C — An if-then plan removes the need for willpower in the moment: you decided earlier that IF data runs out, THEN you study offline. The decision is already made, so you just follow it. ---------------------------------------- Cybersecurity Technician (SOC Analyst) — Lesson 15: Introduce Yourself in 30 Seconds 8 min read OBJECTIVE: Prepare and practise a short, confident self-introduction you can use with employers, customers and new contacts. Many capable people miss opportunities because they freeze when someone asks 'So, what do you do?' A self-introduction is a short, prepared answer — about 30 seconds — that you have practised until it feels natural. It is not showing off. It is simply making it easy for people to understand how you can help them. THE THREE-PART SCRIPT - Who you are: your name and your trade or skill. 'My name is Amina. I am a trained pharmacy assistant.' - What you can do: one or two concrete things, with proof if you have it. 'I have completed training in dispensing support and stock management, and I helped in a busy pharmacy for three months.' - What you are looking for: say it clearly. 'I am looking for a position in a pharmacy or clinic in this area.' or 'I take catering orders for events of up to 100 people.' Put together, it sounds like this: 'Good morning, my name is Kofi. I am a solar technician — I have finished certified training in home solar installation, and I have already installed systems for three families in this town. I am looking for more customers, and I also do repairs and maintenance. Here is my number.' Thirty seconds, and the listener knows exactly what you offer. MAKE IT YOURS - Adjust the ending for the listener: a customer hears what you sell; an employer hears what job you want; a contact hears how they can help you. - Practise out loud, not in your head — say it to a friend, a mirror, or your phone's voice recorder, five times. - Keep it honest. A small true claim beats a big exaggerated one that falls apart at the first question. - End with a way to reach you: your number, your WhatsApp, or where your shop is. [For shy learners] Feeling nervous is normal and does not mean you are bad at this. Preparation is the cure: a practised script means you never have to invent sentences while nervous. Start by using it in low-pressure moments — with a neighbour, then a shopkeeper — before the big interview or the important customer. [Try this today] Write your three-part introduction in your notes, then say it out loud three times. Use it once this week with a real person. PRACTICE QUESTIONS 1. What are the three parts of a good 30-second introduction? A) Your family background, your education, your hobbies B) Who you are, what you can do, what you are looking for C) Your salary expectation, your location, your age D) Your problems, your needs, your complaints Answer: B — The script answers the three questions every listener has: who is this person, what can they do for me, and what do they want? Keep it short, honest and practised. 2. What is the best way to prepare your introduction? A) Memorise a long speech about your whole life B) Wait for inspiration in the moment C) Practise a short script out loud several times before you need it D) Copy someone else's introduction word for word Answer: C — Saying it out loud — to a friend, mirror or voice recorder — is what makes it feel natural under pressure. A short, honest, practised script beats both improvisation and a long memorised speech. ---------------------------------------- Get the full app: https://miva-skillsnav.lovable.app