100+ Free CCDL2 Practice Questions
Certified CyberDefender Level 2 (CCDL2, formerly CCD) practice questions are available now; exam metadata is being verified.
In Elastic Security, a detection engineer wants to write a Sigma rule that converts to a KQL query. Which Sigma field represents the process image name (equivalent to process.name in Elastic ECS)?
Explore More CyberDefenders Certifications
Continue into nearby exams from the same family. Each card keeps practice questions, study guides, flashcards, videos, and articles in one place.
Key Facts: CCDL2 Exam
48 hours
Exam Duration
CyberDefenders
4 domains
Exam Domains
CyberDefenders
~£600
Exam Cost
CyberDefenders
1 retake
Free Retake Included
CyberDefenders
4 months
Course Access
CyberDefenders
25+
Hands-on Labs
CyberDefenders
The CCDL2 (formerly CCD) is CyberDefenders' flagship DFIR certification. The 48-hour practical exam requires investigating real-world incidents in a browser-based lab with a dedicated Elastic SIEM instance. Graders evaluate both correct answers and investigative methodology, with partial credit available. Course access (4 months, 25+ labs) and one free retake are included. The exam covers four domains: Threat Hunting, Disk Forensics, Memory Forensics, and Network Forensics.
Sample CCDL2 Practice Questions
Try these sample questions to test your CCDL2 exam readiness. Each question includes a detailed explanation. Start the interactive quiz above for the full 100+ question experience with AI tutoring.