Your tools now summarise, triage and recommend before you have read a single log line. SAN-101 teaches working cybersecurity analysts the discipline the industry skipped: how to use AI without being used by it — calibrated trust, bias resistance, durable tradecraft and accountable, auditable AI-assisted decisions.
Overview
SAN-101 is a practitioner course, not an awareness seminar. It assumes you already do the work — and that AI has already changed how the work reaches you.
You triage AI-enriched alerts, work from AI-generated summaries, and are measured on speed. You need verification protocols that hold under time pressure.
You use AI for recon, reporting and exploit research — and face AI-enabled adversaries. You need to know where AI accelerates you and where it quietly misleads you.
You are preparing for CPSA/CRT examinations or maintaining certified status, and want human-factors practice that reflects the AI-shaped environment you actually work in.
Working experience in a security operations, incident response or testing role. Familiarity with common analyst tooling (SIEM, EDR, ticketing). No programming or data-science background required — this course is about judgement, not model building.
A laptop with a modern browser. The free online edition runs entirely in your browser — no account password, no install. Use your own tools for the practice prompts if you wish.
Learning Outcomes
On completion, and evidenced through assessment, you will be able to:
Curriculum
Every module pairs the technical reality of AI in security with the human factors science that determines whether it helps or harms. Roughly 40% of contact time is hands-on.
CREST Alignment Map
SAN-101 complements — never replaces — CREST examinations. The table below shows the working alignment used in course design. It does not confer CPD credits or formal accreditation.
| SAN-101 Component | CREST Syllabus Domain | Benefit |
|---|---|---|
| Module 1 — AI-shaped threat landscape | CPSA & CRT: threat awareness, reconnaissance methodology | Current-knowledge grounding for examination scenario questions and real engagements |
| Module 2 — AI tooling & failure modes | CPSA: core technical skills; CRT: tooling & technique | Competent, sceptical use of the AI tooling now embedded in analyst platforms |
| Module 3 — Calibrated trust | CRT: methodology, quality assurance of findings | Fewer false positives escalated; fewer true positives missed; defensible triage |
| Module 4 — Skill maintenance | CREST practitioner → registered → certified career ladder | Sustained examination readiness; protection against skill decay between assessments |
| Module 5 — Governance & capstone | CRT: reporting & client communication; CREST code of conduct | Auditable reporting practice aligned to member-company quality expectations |
Assessment
The free online edition includes a short knowledge check for learning feedback. It is not a formal certification exam and does not award CPD or (ISC)² credits.
Five modules with practice prompts you complete in your own time. Progress is saved in your browser on the free online edition.
A short scenario quiz at the end of the free course for learning feedback — not an accredited exam.
This edition is free learning content. It is not CPD-accredited and not (ISC)² accredited. Do not claim formal credits from it.
Try It Now
Four real questions from the SAN-101 item bank. Answer to see the marking logic.
Q1.An AI copilot summarises an inbound alert and concludes “no further action required.” Your queue is long. The calibrated response is to:
Calibrated trust is not blanket rejection or blanket acceptance. Silent omission is the highest-consequence, lowest-visibility failure mode of AI triage — closure recommendations earn the same structured verification as escalations, using second-channel and provenance checks. (Module 3)
Q2.Which failure mode is most likely when an LLM is asked to enrich an unfamiliar indicator of compromise?
Confabulation is the default failure on low-knowledge queries: the model fills gaps with plausible fabrication, delivered with undiminished confidence. Sycophancy is real but second-order here. This is why provenance checks are mandatory on enrichment output. (Module 2)
Q3.After six months of AI-first drafting, your manual log-analysis speed has measurably dropped. The human factors term and correct countermeasure are:
Deskilling is the predictable cost of never drafting the first pass. The countermeasure is structured: manual-first work on a schedule, then a diff against the model’s version. “Trusting less” is not a trainable behaviour; practice regimes are. (Module 4)
Q4.Under ISO/IEC 42001 and the NIST AI RMF, an AI-assisted incident conclusion is auditable when:
Accountability attaches to people and records, not policies or vendors. An auditable conclusion names the AI contribution, the human verification applied, the deltas, and the accountable owner. (Module 5)
FAQs
No — and deliberately so. SAN-101 complements the CREST pathway rather than teaching to an exam. Content is mapped to CPSA and CRT syllabus domains for orientation, but this free edition awards no CPD and is not an exam-prep product.
No. The curriculum is mapped to CREST syllabus domains for orientation only. SAN-101 is not currently presented as a CREST-accredited course product, and this free online edition makes no accreditation claim.
No. The free online edition runs in your browser. The protocols taught — verification, provenance checking, AI-shadow drills — are tool-agnostic.
Yes — private cohorts for teams of 8–16 are the most common booking. Team delivery adds a shared vocabulary for trust calibration and produces a team-level AI-use SOP as a course artefact.
The online edition is free for now. Request a personal access link and start immediately. Instructor-led team delivery can be quoted separately by email.
Vendor training teaches you to operate their tool well. SAN-101 teaches you to catch any tool when it is wrong — including the days when the confident, fluent, well-formatted answer is fabricated. Those are different skills, and only one of them protects you.
Get a personal access link, work through five modules, and take the knowledge check — no password and no payment. Bookmark your link to return later.
Get free access link →Want instructor-led delivery for a team? Email ibrahim.mukherjee@icloud.com.