Cyber Defense Certified Analyst (CDCA)
Awarded to Tate Pannam on July 22, 2026
Description
The Cyber Defense Certified Analyst (CDCA) is a fully practical SOC analyst certification covering Tier 1 into Tier 2 work.
There is no multiple choice.
Candidates triage a live alert queue in a virtual SOC across four investigations (network traffic analysis, phishing analysis, live host triage, and SIEM log hunting), then write a full incident report with documented IOCs, an executive summary, a technical analysis mapped to MITRE ATT&CK, and actionable remediations.
The report is manually reviewed by an instructor for accuracy, competency, and context.
A CDCA holder has demonstrated they can step onto a security operations team at the Tier 1 to 2 level and contribute from day one.
The CDCA is the fourth credential in the SOC Analyst Path and the first of the two instructor-certified credentials, following the CDT, CDA, and CDR badges and before the CDCP.
Criteria
Triaged a live alert queue in a virtual SOC across four investigations:
- Reconstructed malicious activity from packet capture, separating attacker traffic from legitimate background noise
- Dissected phishing emails through header analysis, authentication results (SPF, DKIM, DMARC), and encoded content to separate true from false positives
- Performed live triage of a compromised Windows host to identify masquerading malware, its persistence, and its command and control
- Traced process trees and decoded obfuscated commands in a SIEM (ELK) to find the origin of an attack
Report Criteria
Wrote a complete incident report:
- Documented IOCs
- An executive summary for leadership
- A technical analysis mapped to MITRE ATT&CK
- Prioritized remediations
Report was manually reviewed by an Instructor to validate skill and competency.