Verified credential
Cyber Defense Analyst (CDA)
Awarded to Warawut Manosong on July 31, 2026
Description
The Cyber Defense Analyst (CDA) validates foundational security analysis skill at the SOC Tier 1 level: malware triage, phishing email analysis, log and event analysis in a SIEM, cryptography, risk fundamentals, and cyber threat intelligence with MITRE ATT&CK.
Holders passed a timed, scenario-based exam built on realistic evidence, including malware artifacts, email headers, log entries, and threat intelligence reports. The exam is vendor agnostic and requires a score of 80% to pass.
The CDA is the second badge in the SOC Analyst Path, following the CDT and ahead of the CDR and the instructor-certified CDCA and CDCP.
Criteria
- Pass the CDA Exam with a score of 80% or higher (64 of 80)
- 80 scenario-based questions covering cybersecurity fundamentals, GRC, cryptography, Windows triage and malware analysis, email security, log and event analysis, and cyber threat intelligence
- Completed within a 100-minute time limit
Domains Covered:
- Cybersecurity Fundamentals (CIA Triad, security controls, threat actors, threat vectors, defense in depth)
- Governance, Risk & Compliance (risk checkpoint, vulnerability management, CIS benchmarks, asset management)
- Cryptography (hashing, encoding, symmetric/asymmetric encryption, digital signatures, certificates)
- Windows Triage & Malware Analysis (process analysis, persistence mechanisms, registry artifacts, network indicators)
- Email Security (header analysis, SMTP authentication, phishing identification, URL inspection)
- Log & Event Analysis (Windows/Linux logs, ELK queries, event correlation, YARA basics)
- Cyber Threat Intelligence (MITRE ATT&CK, Kill Chain, Diamond Model, IOC analysis, threat actor TTPs)