Skip to content
Practical SOC Analyst Professional (PSAP) — A Detailed Review on SOC 201 Course and Its Exam

Practical SOC Analyst Professional (PSAP) — A Detailed Review on SOC 201 Course and Its Exam

April 2026TCM SecurityPassed
Certification
PSAP
Provider
TCM Security
Difficulty
Intermediate
Rating
★★★★½4.5/5.0
Introduction

Hello everyone, it's me Chicken0248 again. In this blog, I'll be sharing my review, experience, and tips for the Practical SOC Analyst Professional (PSAP) exam from TCM Security, as well as the SOC 201 course that serves as the associated training.

PSAP certification badge
Figure 1

First of all, I already passed PSAA in 2025 and didn't write a review, as I thought it had enough coverage already. But the course and its instructor, Andrew Prince, left a strong impression, so when SOC 201 and PSAP were announced, I wanted to take it right away. At the time of release, though, I already had a backlog of certifications, so I postponed it until April 2026.

PSAA badge
Figure 2

I purchased the exam with a military veteran discount, as in 2024, I was drafted and had to serve in the Royal Thai Navy as a seaman for a year. So after I was discharged, I asked for a veteran discount to use on Practical Malware Research Professional (PMRP) but didn't use it until April 2026, when I tried to use it on PSAP instead, but the discount code is now invalid because TCM Security was acquired by Educate360, so they had to migrate their courses to learn.educate360.com which made my code invalid.

To be honest with you, if the support hadn't been fast enough, I would not have taken the exam this early: my original plan was late 2026, since I'm saving up for my first GIAC cert. But hey, hats off to them for having such a great support team.

TCM Security support response
Figure 3

So with the price of $499, what did we get?

  • 12 months access to the SOC 201 course, which includes 25 hours of on-demand training, more on that in the course review section
  • 1 Exam Attempt and 1 retake
  • 24/7/365 course support
PSAP bundle pricing and contents
Figure 4
PSAP certification learning path overview
Figure 5

And after you purchase it, you will be enrolled in the Practical SOC Analyst Professional (PSAP) Certification Learning Path, and there are 2 courses available for you in this path.

The first course is Practical SOC Analyst Professional (PSAP) Certification Information; it is not exactly the course but a place to let you know what you need to know about the PSAP exam, such as the certification process, the exam format, what you should expect in the actual (not technical) exam, and information about the exam retake.

The second course is the main course that the exam is based on, the Security Operations (SOC) 201 course.

SOC 201 course page on Educate360
Figure 6

Even though it is stated that we will have 12 months of access to the course, when we actually enter the course inside learn.educate360.com/courses/security-operations-soc-201, it is explicitly stated here that we have "6-month access." To be honest, I'm not entirely sure which one is correct either.

Course access duration discrepancy on Educate360
Figure 7

About the exam voucher, it is explicitly stated on this page that it is valid for 12 months, so after purchasing it, you will need to take the exam within 12 months, which I think is far more generous than most providers. Besides that, if you fail your initial attempt, they will provide feedback and give you one free retake, which is valid for a lifetime.

So if you find yourself unable to sit the exam within 12 months of purchase, one practical workaround is to start your first attempt, explore the environment as much as you can to get familiar with it, and submit whatever you have. You still have a lifetime retake available, and that initial exposure can be invaluable when you go again.

And that's quite an introduction! Let's jump into the course review in the next section.

Course Review & Experience

To be completely transparent with you all, I only watched a few of the videos before taking the exam, so take this as a grain of salt with my perspective after already having taken an exam.

SOC 201 course content overview
Figure 8

First of all, the course is quite long and somewhat dense for beginners, which is expected for something aiming at the professional level. Since the main focus is SOC, you'll work through the incident response process from theory to practical application, much as a SOC Analyst would on the job.

Here is a general course outline covered in the course:

  • Course Introduction
  • Lab Setup
  • Introduction to Incident Response
  • Introduction to Threat Hunting
  • Data Transformation
  • Understanding Anomalies
  • Dissecting Threat Reports
  • Threat Hunting Lab
  • Collection at Scale
  • PowerShell 101
  • PowerShell for Incident Response
SOC 201 course modules list
Figure 9

This course does not come with online lab access like courses from CyberDefenders, HackTheBox, and Centri. The course has its own lab setup section to let you install a Hypervisor, Ubuntu VM, Windows VM, and even set up Splunk, but the required resources can be quite intensive, so I skipped that. The pro of this approach is you have full access to the lab at the cost of your own infrastructure.

Lab setup section in SOC 201
Figure 10

The fundamental of this course is incident response and threat hunting, so after finishing this, you are expected to know how to respond to threats effectively at scale in the incident response process manner and be able to conduct threat hunting in the enterprise environment with not just Splunk but the core methodology on how to do it regardless of the SIEM tool.

Andrew still makes sure you understand everything, even though the course is marketed for "professionals": he walks through almost everything on screen and explains his thought process, which will be genuinely helpful if you're newer to the field.

Overall, the course is solid, not overly technical, but it covers everything you need to carry out real IR and threat hunting work.

Exam Experience
You'll be dropped directly into a corporate network under investigation for potential intrusion by a sophisticated adversary group. You will need to proactively hunt for signs of compromise, reconstruct the attacker's activity, and propose actionable containment, eradication, and recovery measures, all based on realistic attack techniques and campaigns observed in similar organizations.

This is the description they provided on their main page to let you know what to expect and tell your potential employer what you are capable of once you've passed the exam.

PSAP exam portal — exam details and timer
Figure 11

After purchasing the bundle, you will be granted access to the course on Educate360 and the exam at exams.tcmsecurity.com, and you will see the same screen shown above, confirming that you have 3 full days to complete the assessment and another 2 days to write and submit your report.

PSAP exam details page with start button
Figure 12

Once you click the "Details" button, you're taken to a page with a green start button. The other buttons are greyed out, but they become active once the exam begins.

I started the exam on 4th April 2026, which is Saturday, and I wanted to finish my exam in 2–3 days if possible because 6th April is a holiday in Thailand but I have to work on 7th and 8th April.

Exam start confirmation window
Figure 13

I woke up at around 8–9 AM that day and after eating breakfast, I logged into the exam website to start. The confirmation window appeared as a final checkpoint, one last chance to back out before committing. Since I had already planned my weekend around it, I clicked "Agree."

Exam environment initialized — countdown and VPN download
Figure 14

It takes a while for the exam environment to finish initializing, but once it's ready, the countdown begins. From here you can download the OpenVPN configuration file using the key button on the bottom left, and the Rules of Engagement from the document button.

You will need to connect via OpenVPN to access the exam environment. You will not be allowed to pull artifacts down to your own machine (this is to preserve exam integrity), but the good news is that most of the investigation can be done entirely within the Splunk instance they provide.

If you're concerned about a Digital Forensics component, don't be. The exam's focus is threat hunting across an enterprise environment. The Rules of Engagement include a threat actor profile that you can use to build your hunting hypotheses.

Once I started the exam and accessed Splunk, I felt somewhat underwhelmed: there were noticeably few events ingested into the SIEM. The data came from many hosts, but I expected more volume for a "Professional"-level certification.

You might think that fewer events would make things easier, and in terms of raw complexity, that's fair. But the core focus of both the course and exam is IR and threat hunting, and that's where my concern lies. I spent only 1–2 hours reviewing all the logs in the SIEM and was able to piece together the full attack chain without needing to apply any formal threat hunting methodology.

That said, once I had a rough picture of what had happened from reading through the logs, I started working on my report that same day, but then I hit a snag.

I noticed that the report template included in the Rules of Engagement was the PSAA report template, not the PSAP one, so I contacted support about it and they replied with this.

TCM Security support reply about report template
Figure 15

"Unfortunately, we do not have a specific template for PSAP exam." That threw me off: I was about to just use the PSAA template when I remembered that a friend of mine had taken the PSAP beta, so I reached out to him to check.

Surprisingly, he sent me a PSAP template link he'd found in his own Rules of Engagement, and it looked legitimate, so I downloaded it and got to work on my report. As for what the TCM support team's reply actually meant, I still have no idea. 😄

PSAP report template
Figure 16

I found it hard to stay motivated and kept putting the report off, so I finally submitted on Monday, 6th April 2026, as planned, then took the rest of the day to recover. Submissions must be a single PDF file under 200 MB.

Exam submission — PDF under 200MB requirement
Figure 17

Once you submit, whatever time you had left on the exam disappears immediately. The page switches to an "Awaiting Review" status and the OpenVPN connection stops working, so it's a waiting game from there. Based on my previous PSAA exam being graded in 6 days, I expected a similar turnaround of 1–2 weeks.

FYI, the maximum score is 100 points and you need at least 70 to pass. As for how they weight each section of the report, no idea, but I went in feeling optimistic.

Exam status changed to Awaiting Review
Figure 18

After 10 days of waiting, on 16th April 2026 (the day after Thailand's Songkran holiday), I received two emails from TCM Security. The first notified me of a status change on the exam website.

Email notification — exam status change
Figure 19
Email — certificate and badge on Accredible
Figure 20

The other contained my certificate and badge link on Accredible, where you can download both the PDF certificate and the PNG badge.

Exam portal — status updated to Passed
Figure 21

On the exam portal, you'll see the status updated to "Passed," as shown above.

Exam details — congratulations message and Discord role instructions
Figure 22

Clicking "Details" brings up the congratulations message, and from there you can find instructions to email TCM Security's support team to have the PSAP role added to your profile in their Discord server.

PSAP Discord role added within 2 minutes
Figure 23

I was genuinely surprised by how fast they responded: after emailing support to request the PSAP Discord role, a new role was added and I was let into the exclusive PSAP-certified channel within 2 minutes.

That's it for this section. Let's head into the final review.

Final Review

The course is video-based and does a great job teaching the core ideas behind incident response and threat hunting without getting lost in technical minutiae. Andrew makes sure you understand what's happening throughout: he consistently shares his thought process on screen, which makes the material genuinely approachable.

For the exam, I came away with mixed feelings. You have 5 days in total (3 for the engagement and 2 to polish your report), and most of your time will be spent in the SIEM, where you're expected to apply the threat hunting methodology covered in the course. That said, the volume of events is on the lighter side; it's possible to work through all of them within a few hours and piece together the attack chain without formally applying a hypothesis-driven approach.

On a separate note, a PSAP report template does appear to exist, though the support team I contacted was unaware of it: if in doubt, check with someone who has taken the exam before or follow up with support.

If you're looking for a certification that requires you to use a SIEM to correlate events across multiple hosts and produce a structured report, and the words "SOC Analyst" and "Professional" in the name matter to you, then this is worth considering.

Exam Tips & Key Takeaways
  • Before taking this exam, make yourself comfortable with investigating multiple hosts at once.
  • Familiarize yourself with Splunk and get comfortable working with logs spanning at least 4 different hosts (as a bare minimum) while conducting threat hunting.
  • Refer to The DFIR Report when writing your report: TCM Security uses it as an example of what a good IR report looks like.
  • Do not forget IOCs.
  • Do not forget the Timeline.
  • Write the report as you go. Use the last 2 days given for report writing as a polishing time, because you might need to revisit the exam environment just to take a good screenshot for your report.
  • Recommendation and Response measures are also a grading criterion: study some to put in your report.
  • The exam has no rabbit holes; everything is straightforward.
  • The course is a good fit for beginners and SOC L1 analysts who want to upskill toward L2 or potentially L3, though it doesn't go too deep into specific techniques.
  • In the course, there are parts where Andrew will walk through his methodology: study that to know what he expects from students.