HTB Certified Defensive Security Analyst (CDSA) Exam - Review
HTB Certified Defensive Security Analyst (CDSA) Exam - Review
A super fun, data-heavy exam that rewards solid methodology and regular practice. It’s highly rewarding once you hit the end, though the sheer volume of data can feel like drowning if you aren’t prepared.
Here is a breakdown of the experience, what to expect, and how to survive the data deluge.
The Experience
- 100% Useful Content: Absolutely everything covered in the HTB Academy job role path is practical and applicable.
- Massive Scope: Expect a wide, immersive playground with loads of elements to explore and get lost in.
- The Adversaries: You will be tracking sophisticated, nation-state style attackers across two distinct scenarios. They are highly capable, but absolutely trackable if your fundamentals are solid.
- The Lab Structure: The questions themselves act as a guide, offering subtle hints on where to look next. While this prevents painful rabbit holes, it does make it feel slightly less “real-world” accurate—but it keeps the exam flowing beautifully.
Survival Tips & Strategy
- Master the Attacker Mindset: Your best weapon isn’t a complex query; it’s asking yourself: “What would an attacker do next?” Having offensive security experience helps immensely here. If you don’t have an offensive background, consider building a small home lab, executing basic attacks (downloading tools, running standard discovery commands), and watching how those alerts flow into your SIEM.
- Trust Your Methodology, Not Just the Tools: Start with standard attacker behaviour queries to find a thread, then pull on it backward and forward.
- Spot the Anomalies: Know what normal looks like so you can use an eagle eye to spot the anomalies in the calls. Zoom in on the right spot rather than firing off blind searches.
- Filter out the Noise: There is non-exam-related background noise in the environment. Be careful not to traverse too far back into irrelevant data.
- Take Breaks: The mountain of logs can cause serious fatigue. Step away when stuck.
- Save Your Queries: Keep a scratchpad of your successful queries so you can quickly jump back to a known good spot if a tangent leads to a dead end.
- Documentation is Lifesaving: Keep your notes clean and structured in real-time. Whether you use an Obsidian table or a spreadsheet, log every confirmed attacker action as you find it. Backtracking through millions of events because you forgot to write down a timestamp is an absolute nightmare.
The Incident Report
- For many, writing a formal incident report is the hardest part of the exam—especially if you come from a technical or offensive background and haven’t written one before.
- The Gold Standard: Use The DFIR Report as a structural blueprint. It is an excellent real-world guide on how to lay out an investigation.
- Expect Repetition: The report might feel slightly repetitive as you fill out different sections, but this is standard for professional compliance.
- Pre-Study the Sections: Understand the exact purpose of each section (Executive Summary, Timeline, Technical Analysis) before the exam starts so you don’t waste precious time figuring out layout logic on the clock.
Final Verdict
An excellent, comprehensive exam that truly tests your defensive capabilities. It is challenging but entirely fair. Keep your head above the data, document as you go, and enjoy the hunt.
Good luck, and have fun!
This post is licensed under CC BY 4.0 by the author.
