Skip to main content

CCDL1 Exam Outline

Review the CCDL1 exam format, duration, questions, passing score, domain weights, assessed skills, and experience requirements.


Version 1.0 · May 2026
This guide explains the structure of the CCDL1 certification exam, including the skills assessed, exam format, domain weights, and the knowledge areas covered.

About CCDL1

The Certified CyberDefenders Level 1 (CCDL1) is the foundational certification for SOC Tier-1 analysts in the CyberDefenders ecosystem. CCDL1 validates a candidate's practical ability to triage security alerts, investigate incidents, analyze logs, and operate real SOC tools within a live, scenario-driven environment.


Targeted Professional Domains

The CCDL1 exam covers a broad spectrum of core competencies required for modern Tier-1 SOC analysis. Successful candidates must demonstrate technical proficiency across four primary domains:

  • Domain 1: Network & Endpoint Essentials

  • Domain 2: SIEM Basics (Splunk)

  • Domain 3: Phishing & Email Security

  • Domain 4: Digital Forensics and Incident Response

  • Domain 5: Cloud Security


Experience Requirements

There are no formal educational or professional experience prerequisites for the CCDL1 examination. This certification is designed to be objective for individuals beginning their careers in a Security Operations Center (SOC) environment or for professionals transitioning into a Tier-1 analyst role.


Job Task Analysis (JTA)

To ensure the CCDL1 credential remains a highly relevant and valid measure of professional competence, CyberDefenders utilizes a formal Job Task Analysis (JTA) process.

The JTA is a methodical study used to define the actual tasks, knowledge, and skills performed by active security professionals in the field.

[Industry-Wide JTA Survey] ➔ [SME Panel Review & Validation] ➔ [Exam Weights]

  1. Research & Surveying: A comprehensive survey was conducted with actively practicing SOC L1 analysts across the industry.

  2. SME Panel Validation: The survey data was analyzed to generate an occupational report, which was subsequently reviewed, refined, and validated by an independent Subject Matter Expert (SME) panel.

  3. Exam Alignment: The outcomes of this process directly established the domain weights and specific topic areas assessed on the examination.

This development process ensures that candidates are evaluated solely on objective skills directly relevant to the real-world responsibilities of today's practicing SOC Tier-1 analysts.


CCDL1 Examination Specifications

The CCDL1 examination combines a live, practical lab environment with objective, scenario-based questions to measure technical troubleshooting and analytical capabilities.

Exam Characteristic

Specification

Exam Duration

6 hours

Number of items

48 Questions

Item format

Multiple Choice (Each item contains between 4 and 8 choices with a single correct answer)

Testing environment

Live virtual machine accessible via browser throughout the exam session

Passing Score

70%

Attempts included

2 attempts


CCDL1 Examination Weights

Domain

Weight

1. Network & Endpoint Essentials

26.09%

2. SIEM Basics (Splunk)

33.33%

3. Phishing & Email Security

10.14%

4. DFIR

20.29%

5. Cloud Security

10.14%

Total

100%


Detailed Domain Descriptions

Domain 1: Network & Endpoint Essentials
Covers Windows host artifact analysis, process chain investigation, network traffic analysis, and alert validation using endpoint and network-based evidence within a Tier-1 SOC investigation context.


Domain 2: SIEM Basics (Splunk)
Covers SIEM log sources, event searching and filtering, authentication and service event interpretation, lateral movement indicators, and alert enrichment using log-based evidence in Splunk.


Domain 3: Phishing & Email Security
Covers email header analysis, sender validation techniques, attachment and URL analysis, payload extraction, and attacker infrastructure identification.


Domain 4: Digital Forensics and Incident Response (DFIR)
Covers disk, memory, registry, MFT, and prefetch artifact analysis, process chain reconstruction, and scoped forensic investigation relevant to Tier-1 SOC incident response activities.


Domain 5: Cloud Security
Covers cloud provider log structures, cloud IAM concepts, object storage API activity, and cloud-based incident indicators relevant to Tier-1 SOC investigations.


Did this answer your question?