Skip to main content

Study Schedule & Exam Readiness

Updated today

Welcome to your Study Schedule, your roadmap to get the most from your CyberDefenders course and ace your exam.

Over the next 12 weeks, leading up to your first attempt, scheduled three months after enrollment, this plan outlines weekly study goals and helps you track your progress through your Exam Readiness score.

Follow the weekly goals, complete the investigations, and watch your readiness score grow.


How the Study Plan Works

Both courses are organized into modules spread across 11 weeks, with the 12th week reserved for review. The total time commitment is approximately 60 hours for CCDL1 and 75 hours for CCDL2. Expect to dedicate 6–9 hours per week, depending on your experience and familiarity with the content.

Your weeks are calculated in 7-day intervals from your enrollment date. For example, if you start on a Sunday, each new week begins on Sunday. This schedule ensures you maintain steady progress while balancing your learning with other responsibilities.


Understanding Your Exam Readiness Score

Regardless of which course you're taking, the Exam Readiness score on your dashboard shows how prepared you are for the exam. It is weighted as follows:

  • Investigations contribute 45%

  • Labs contribute 35%

  • Lessons and quizzes contribute 20%

This weighting emphasizes hands-on, practical learning, with investigations having the greatest impact because they best reflect the skills and scenarios you will encounter in the exam.

Your readiness score updates automatically as you complete content, and you can monitor your progress through your dashboard and Study Schedule.

Why Investigations Matter

Module Investigations are capstone exercises that bring together everything you've learned. They mirror the final exam's structure and challenge, making them the most effective way to prepare.

Our metrics show a 30% improvement in exam performance among students who complete all capstone investigations.


Weekly Goals

Each week comes with a target Exam Readiness score, representing the progress you should achieve to stay on track.

Your dashboard widget uses colors to show your status:

  • Green: On track or ahead of your weekly goal

  • Yellow: 1–2 weeks behind

  • Red: More than 2 weeks behind

Weeks behind means your current score is below the goal for recent weeks. Staying green ensures you are on track, and if you fall behind, it's a signal to focus on catching up before moving on to new content.


Taking the Exam Early

You don't need to wait the full three months. If you finish the course early and feel confident, you can attempt the exam at any time.

For full access periods and attempt policies, see the Course and Certification Access Policy.


CCDL1 — Week-by-Week Breakdown

Week

Topics

Goal

1

Module 1: SOC & Threat Intelligence Foundations
Topic 1.1: Threat Intelligence Essentials
Topic 1.2: Threat Landscape & Actors
Investigation Lab 1: OpenCTI & OSINT

12%

2

Module 2: Network & Endpoint Essentials
Topic 2.1: Endpoint Monitoring & Hardening
Topic 2.2: Network Fundamentals and Threat Detection

18%

3

Module 2: Network & Endpoint Essentials
Topic 2.3: Active Directory Security & Monitoring
Investigation Lab 2: Network & AD Basics

29%

4

Module 3: SIEM Basics - Splunk & Sentinel
Topic 3.1: SIEM Fundamentals
Topic 3.2: Splunk Essentials

37%

5

Module 3: SIEM Basics - Splunk & Sentinel
Topic 3.3: Microsoft Sentinel Essentials
Topic 3.4: Alert Triage & Investigation
Investigation Lab 3: SIEM Basics

49%

6

Module 4: Phishing & Email Security
Topic 4.1: Building Blocks of Email Security
Topic 4.2: Common Email Attacks & How They Work
Topic 4.3: Email Threat Detection Tactics

54%

7

Module 4: Phishing & Email Security
Topic 4.4: Responding to Email Attacks
Investigation Lab 4: Phishing & Email Security

Module 5: Digital Forensics & Incident Response
Topic 5.1: DFIR Foundations & Evidence Handling

67%

8

Module 5: Digital Forensics & Incident Response
Topic 5.2: Windows Host Forensics & Analysis
Topic 5.3: Linux Host Forensics & Investigation

75%

9

Module 5: Digital Forensics & Incident Response
Topic 5.4: Live Response & Digital Evidence Collection
Investigation Lab 5: DFIR

85%

10

Module 6: Cloud Security & AI
Topic 6.1: Cloud Security Fundamentals
Topic 6.2: Cloud Threats & Defense

89%

11

Module 6: Cloud Security & AI
Topic 6.3: Forensics & Incident Response in the Cloud
Topic 6.4: AI-Enhanced Security Operations
Investigation Lab 6: Cloud Security

100%

12

Review Week
• Consolidate and organize your notes
• Review topics you found challenging
• Rest up before your exam


CCDL2 — Week-by-Week Breakdown

Week

Topics

Goal

1

Module 1: Network Forensics
Introduction to Network Forensics
Understanding Network Data Types
Understanding Network Data Sources
Preparing Network Captures for Analysis
Extracting IoCs & Objects
Network Forensics: Use Cases

2%

2

Module 1: Network Forensics
Lab - Network Forensics 1
Lab - Network Forensics 2

8%

3

Module 1: Network Forensics
Lab - Network Forensics Module Investigation

19%

4

Module 2: Forensics Evidence Collection
What is Digital Forensics?
Memory Acquisition
Disk Acquisition: Write-Blocking
Mounting Forensic Images: Analysis Tools & Techniques

Module 3: Disk Forensics
Windows Forensics
Profiling Windows Systems
Collecting Network Connections and Devices
Exploring User Information
Collecting File and Folder Activity
Linking User Actions to Files/Folders

28%

5

Module 3: Disk Forensics
Detecting USB Device Intrusions (includes USB Forensics Lab)
Analyzing Installed Applications
Analyzing Execution Activities
Lab - Disk Forensics

38%

6

Module 3: Disk Forensics
Lab - Disk Forensics Module Investigation

50%

7

Module 4: Memory Forensics
Windows Memory Forensics
Volatility 2
Collecting OS Info
Understanding Windows Processes
Network Connections Analysis
Detecting Persistence Techniques
Collecting Files Artifacts
Lab - Memory Forensics

56%

8

Module 4: Memory Forensics
Lab - Memory Forensics Module Investigation

68%

9

Module 5: Threat Hunting
Threat Hunting Essentials
Methodology-Based Hunting
Elastic SIEM

73%

10

Module 5: Threat Hunting

Endpoint Threat Hunting (includes Endpoint TH Labs 1 & 2)
Network Threat Hunting (includes Network TH Labs 1 & 2)

86%

11

Module 5: Threat Hunting
Lab - Threat Hunting Module Investigation

100%

12

Review Week
• Consolidate and organize your notes and cheat sheets
• Review topics you found challenging
• Rest up before your exam

__

Did this answer your question?