Splunk Cybersecurity Defense Analyst Study Guide
Free interactive prep for the Splunk Certified Cybersecurity Defense Analyst (CDA) exam — master threat triage, SOC operations, and Splunk ES.
About the SPLK-CDA Certification
The Splunk Certified Cybersecurity Defense Analyst (CDA) is a modern SOC-focused certification validating your ability to detect, analyze, and respond to cyber threats using Splunk Enterprise Security. It is the ideal certification for Tier 1 and Tier 2 SOC analysts.
This free study guide covers SOC fundamentals, MITRE ATT&CK, SPL for security, Notable Event triage, and threat hunting — all with interactive lessons and a full practice exam.
📋 Exam Details
📚 What's on the SPLK-CDA Exam
1. Security Fundamentals & Frameworks
CIA Triad, MITRE ATT&CK, Cyber Kill Chain, threat actor categories (APT, insider threat), common attack techniques (phishing, LotL, Golden Ticket).
2. Splunk Enterprise Security (ES)
Notable Events, Incident Review dashboard, Security Posture, Risk-Based Alerting (RBA), risk objects and modifiers, urgency calculation.
3. SPL for Security Analysis
Security-focused SPL: tstats, rex, transaction, makeresults, lookup for threat intel enrichment, subsearches.
4. Threat Hunting
Hypothesis-driven hunting, distinguishing IOCs from TTPs, proactive search techniques, hunting queries in Splunk.
5. Incident Response Fundamentals
IR lifecycle phases, triage process, containment vs eradication, post-incident review, MTTR and MTTD metrics.
🎯 Sample SPLK-CDA Practice Questions
Preview 2 questions from our 60+ question bank:
💡 Study Tips for SPLK-CDA
- Master tstats — it appears heavily in the exam and is fundamental to ES performance.
- Understand the difference between risk objects and risk modifiers in RBA.
- Know the MITRE ATT&CK tactics in order: Reconnaissance → Initial Access → Execution → Persistence → Privilege Escalation → Defense Evasion → Credential Access → Discovery → Lateral Movement → Collection → Exfiltration → Impact.
- Practice the SPL pipeline: search → filter → transform → present.
🏰 Course Curriculum
Our Splunk Certified Cybersecurity Defense Analyst course covers all exam topics across 6 dungeon floors:
❓ Frequently Asked Questions
What does the CDA certification validate?
The CDA validates your ability to perform the day-to-day responsibilities of a SOC Analyst: monitoring alerts, triaging notable events, investigating threats, and using Splunk ES effectively.
How is CDA different from SPLK-1001?
SPLK-1001 tests general Splunk search and navigation skills. The CDA tests security-specific use of Splunk: threat detection, ES dashboards, MITRE ATT&CK mapping, and incident response workflows.