CDSA Exam Prep & Study Resources

Hack The Box certification · 2 products

HTB Certified Defensive Security Analyst

Study materials for CDSA

Frequently asked questions

What is HTB CDSA?

CDSA (Certified Defensive Security Analyst) is Hack The Box's blue team certification, based on the HTB Academy SOC Analyst learning path. It validates practical skills in log analysis, SIEM usage, threat hunting, and incident response, the core competencies of a security operations center analyst. Like HTB's offensive certifications, CDSA uses a hands-on practical exam format rather than multiple-choice questions, distinguishing it from most defensive certifications on the market and providing a more credible demonstration of real SOC skills.

Who should take CDSA?

CDSA is designed for SOC analysts (Tier 1 and Tier 2), threat hunters, and incident responders who want a structured, practical certification validating their detection and investigation skills. It is particularly valuable for professionals who are self-taught in defensive security and want formal credentials to demonstrate competency to employers. Security engineers who design detection rules, blue teamers who hunt for threats in enterprise environments, and professionals transitioning from IT operations into security operations roles will all find CDSA directly applicable to their career goals.

How hard is CDSA?

CDSA is moderately challenging. The exam requires analyzing realistic attack scenarios from logs and network captures, identifying attacker actions, and reconstructing a complete attack chain under exam conditions. Candidates who have completed the HTB Academy SOC Analyst path thoroughly and have hands-on experience with a SIEM platform will find the difficulty manageable. Those with only theoretical knowledge of incident response without practical log analysis experience may find the time pressure and the volume of data to analyze more demanding than expected.

What topics does CDSA cover?

CDSA covers the full breadth of security operations analyst skills. Topics include SIEM platform usage and query development, Windows Event Log analysis (logon events, process creation, PowerShell logging, WMI activity), Linux system log analysis, network traffic and packet capture analysis using Wireshark and similar tools, phishing email investigation, malware triage and behavioral analysis, detecting lateral movement and privilege escalation in log data, and structured incident response workflows aligned with industry frameworks such as NIST and PICERL.

Is CDSA worth it?

Yes. CDSA is one of the most practically validated blue team certifications available, backed by HTB's credibility in the security community. Most defensive certifications on the market rely on multiple-choice exams that test knowledge rather than skill, making CDSA stand out as a hands-on credential. It is increasingly recognized by employers for SOC analyst, threat hunter, and incident responder positions. For defensive security professionals who want to demonstrate real-world detection and investigation capabilities rather than just certification knowledge, CDSA is a strong investment.

Prerequisites for CDSA?

No formal prerequisites are required for CDSA. Candidates should have basic networking knowledge, familiarity with Windows Event Logs and Linux syslog format, and completion of the HTB Academy SOC Analyst learning path is strongly recommended as the primary preparation resource. Experience with any SIEM platform, whether Splunk, Elastic, Microsoft Sentinel, or another tool, is beneficial, as it builds the query and investigation intuition that the exam tests. Candidates with prior help desk or IT operations experience will find the transition to SOC analysis concepts easier.

Related

All Hack The Box certifications · Browse cheatsheets