If you’re new, how are you practicing incident response and monitoring security events, not just memorizing terms? In my SOC we run a 45-minute phishing tabletop every Tuesday and a 30-minute daily review of the last 24 hours of auth logs in Elastic for anomalous MFA failures; I can share a lightweight playbook and alert-triage checklist you can adapt to a home lab — what constraints are you working with?