Skip to main content

Module 3 Overview

Module 3 of 3
SOC Investigation
Review Incidents, Response History, and Workflow Previews
โฑ ~30 minutes๐Ÿข Enterprise Tenant (Read-Only)๐Ÿ‘ค Persona: PriyaLab 9
๐Ÿ”„

Confirm Tenant Switch
Return to the Enterprise Tenant (Tenant 1). In your assigned CloudShare environment, open Credentials โ†’ SDC Credentials and use the Admin Username and Password to sign in at sdc.zslogin.net. Do not use the Module 2 Student Admin credentials. This module is read-only: do not send notifications, change incident state, escalate, or configure workflows.

After Alex's policy work and Kevin's tests, Priya explores a separate, pre-populated incident queue in Zscaler Workflow Automation (ZWA). Review incident evidence, existing user notifications and state changes, available actions, and a workflow template preview. The Lab 9 example is an Inline incident for an attachment/post at dlptest.com under CC SSN HIPAA Block โ€” not the student's Lab 6 or 7 document or DP Project Code policy. Allow 20 minutes for Lab 9 and 10 minutes for the knowledge check.

Module Objectivesโ€‹

QuestionCapability
How does Priya find and review incidents?ZWA Incident Dashboard
How does she assess evidence and trigger data?Incident Details & Violation Content
What status, priority, and prior actions are recorded?Incident Metadata & State Changes
What notifications have already been sent, and what response is recorded?User Notifications History
Which response options are available, without executing them?Actions Menu Exploration
How could notification and escalation be automated?Workflow Template Preview

Lab in This Moduleโ€‹

๐ŸŽ“
Lab Assistant
Zenith Live 2026 ยท Dataparity
Module 3 Overview
Browse all topics