SPLK-CDA · Splunk Certified Cybersecurity Defense Analyst

Splunk Cybersecurity Defense Analyst Study Guide

Free interactive prep for the Splunk Certified Cybersecurity Defense Analyst (CDA) exam — master threat triage, SOC operations, and Splunk ES.

Start Free Course📝 Practice Exam (60+ questions)
🏰
6
Floors
📖
18
Lessons
📝
60+
Practice Qs
🎉
FREE
Price

About the SPLK-CDA Certification

The Splunk Certified Cybersecurity Defense Analyst (CDA) is a modern SOC-focused certification validating your ability to detect, analyze, and respond to cyber threats using Splunk Enterprise Security. It is the ideal certification for Tier 1 and Tier 2 SOC analysts.

This free study guide covers SOC fundamentals, MITRE ATT&CK, SPL for security, Notable Event triage, and threat hunting — all with interactive lessons and a full practice exam.

📋 Exam Details

question CountApproximately 57 questions
duration57 minutes
passing Score70%
formatMultiple choice, scenario-based
cost$130 USD
prerequisitesSPLK-1001 Core Certified User recommended
🎓 View Official Exam Page on Splunk.com →

📚 What's on the SPLK-CDA Exam

1. Security Fundamentals & Frameworks

CIA Triad, MITRE ATT&CK, Cyber Kill Chain, threat actor categories (APT, insider threat), common attack techniques (phishing, LotL, Golden Ticket).

2. Splunk Enterprise Security (ES)

Notable Events, Incident Review dashboard, Security Posture, Risk-Based Alerting (RBA), risk objects and modifiers, urgency calculation.

3. SPL for Security Analysis

Security-focused SPL: tstats, rex, transaction, makeresults, lookup for threat intel enrichment, subsearches.

4. Threat Hunting

Hypothesis-driven hunting, distinguishing IOCs from TTPs, proactive search techniques, hunting queries in Splunk.

5. Incident Response Fundamentals

IR lifecycle phases, triage process, containment vs eradication, post-incident review, MTTR and MTTD metrics.

🎯 Sample SPLK-CDA Practice Questions

Preview 2 questions from our 60+ question bank:

Q1. What is the primary purpose of Risk-Based Alerting (RBA) in Splunk ES?
AAlert on every suspicious event
BAccumulate risk scores against entities and alert only when a threshold is exceeded✓ Correct
CCalculate financial risk
DAutomatically patch systems
Explanation: RBA reduces alert fatigue by grouping low-fidelity events into a risk score, creating one high-fidelity alert when the entity's score threshold is crossed.
Q2. Which SPL command is fastest for querying data across accelerated Data Models?
Asearch
Bstats
Ctstats✓ Correct
Djoin
Explanation: tstats queries TSIDX index metadata rather than raw events, making it orders of magnitude faster on large, CIM-compliant datasets.
Take the Full Practice Exam →

💡 Study Tips for SPLK-CDA

  1. Master tstats — it appears heavily in the exam and is fundamental to ES performance.
  2. Understand the difference between risk objects and risk modifiers in RBA.
  3. Know the MITRE ATT&CK tactics in order: Reconnaissance → Initial Access → Execution → Persistence → Privilege Escalation → Defense Evasion → Credential Access → Discovery → Lateral Movement → Collection → Exfiltration → Impact.
  4. Practice the SPL pipeline: search → filter → transform → present.

🏰 Course Curriculum

Our Splunk Certified Cybersecurity Defense Analyst course covers all exam topics across 6 dungeon floors:

🛡️
Floor 1: Cyber Landscape
Frameworks & Standards · 3 lessons
Beginner
🦠
Floor 2: Attack Tactics
Threat Intel & Attack Vectors · 3 lessons
Beginner
🔌
Floor 3: SIEM Operations
Data Sources & The CIM · 3 lessons
Intermediate
🔎
Floor 4: Investigation & ES
Event Handling & Risk-Based Alerting · 3 lessons
Intermediate
💻
Floor 5: Security SPL
Advanced Search & Analysis · 3 lessons
Intermediate
🏹
Floor 6: Threat Hunting
Proactive Analysis & Response · 3 lessons
Advanced

❓ Frequently Asked Questions

What does the CDA certification validate?

The CDA validates your ability to perform the day-to-day responsibilities of a SOC Analyst: monitoring alerts, triaging notable events, investigating threats, and using Splunk ES effectively.

How is CDA different from SPLK-1001?

SPLK-1001 tests general Splunk search and navigation skills. The CDA tests security-specific use of Splunk: threat detection, ES dashboards, MITRE ATT&CK mapping, and incident response workflows.

📗 Other Study Guides

SPLK-1001
Splunk Core Certified User
Everything you need to pass the Splunk Core Certified User exam — 100% free.
SPLK-1002
Splunk Core Certified Power User
Master advanced SPL and pass the Splunk Core Certified Power User exam.
SPLK-1004
Splunk Core Certified Advanced Power User
Conquer the most advanced core Splunk certification with expert-level SPL mastery.