Version 1.0 · May 2026
This guide explains the structure of the CCDL1 certification exam, including the skills assessed, exam format, domain weights, and the knowledge areas covered.
About CCDL1
The Certified CyberDefenders Level 1 (CCDL1) is the foundational certification for SOC Tier-1 analysts in the CyberDefenders ecosystem. CCDL1 validates a candidate's practical ability to triage security alerts, investigate incidents, analyze logs, and operate real SOC tools within a live, scenario-driven environment.
Targeted Professional Domains
The CCDL1 exam covers a broad spectrum of core competencies required for modern Tier-1 SOC analysis. Successful candidates must demonstrate technical proficiency across four primary domains:
Domain 1: Network & Endpoint Essentials
Domain 2: SIEM Basics (Splunk)
Domain 3: Phishing & Email Security
Domain 4: Digital Forensics and Incident Response
Domain 5: Cloud Security
Experience Requirements
There are no formal educational or professional experience prerequisites for the CCDL1 examination. This certification is designed to be objective for individuals beginning their careers in a Security Operations Center (SOC) environment or for professionals transitioning into a Tier-1 analyst role.
Job Task Analysis (JTA)
To ensure the CCDL1 credential remains a highly relevant and valid measure of professional competence, CyberDefenders utilizes a formal Job Task Analysis (JTA) process.
The JTA is a methodical study used to define the actual tasks, knowledge, and skills performed by active security professionals in the field.
[Industry-Wide JTA Survey] ➔ [SME Panel Review & Validation] ➔ [Exam Weights]
Research & Surveying: A comprehensive survey was conducted with actively practicing SOC L1 analysts across the industry.
SME Panel Validation: The survey data was analyzed to generate an occupational report, which was subsequently reviewed, refined, and validated by an independent Subject Matter Expert (SME) panel.
Exam Alignment: The outcomes of this process directly established the domain weights and specific topic areas assessed on the examination.
This development process ensures that candidates are evaluated solely on objective skills directly relevant to the real-world responsibilities of today's practicing SOC Tier-1 analysts.
CCDL1 Examination Specifications
The CCDL1 examination combines a live, practical lab environment with objective, scenario-based questions to measure technical troubleshooting and analytical capabilities.
Exam Characteristic | Specification |
Exam Duration | 6 hours |
Number of items | 48 Questions |
Item format | Multiple Choice (Each item contains between 4 and 8 choices with a single correct answer) |
Testing environment | Live virtual machine accessible via browser throughout the exam session |
Passing Score | 70% |
Attempts included | 2 attempts |
CCDL1 Examination Weights
Domain | Weight |
1. Network & Endpoint Essentials | 26.09% |
2. SIEM Basics (Splunk) | 33.33% |
3. Phishing & Email Security | 10.14% |
4. DFIR | 20.29% |
5. Cloud Security | 10.14% |
Total | 100% |
Detailed Domain Descriptions
Domain 1: Network & Endpoint Essentials
Covers Windows host artifact analysis, process chain investigation, network traffic analysis, and alert validation using endpoint and network-based evidence within a Tier-1 SOC investigation context.
Domain 2: SIEM Basics (Splunk)
Covers SIEM log sources, event searching and filtering, authentication and service event interpretation, lateral movement indicators, and alert enrichment using log-based evidence in Splunk.
Domain 3: Phishing & Email Security
Covers email header analysis, sender validation techniques, attachment and URL analysis, payload extraction, and attacker infrastructure identification.
Domain 4: Digital Forensics and Incident Response (DFIR)
Covers disk, memory, registry, MFT, and prefetch artifact analysis, process chain reconstruction, and scoped forensic investigation relevant to Tier-1 SOC incident response activities.
Domain 5: Cloud Security
Covers cloud provider log structures, cloud IAM concepts, object storage API activity, and cloud-based incident indicators relevant to Tier-1 SOC investigations.
