100+ Free HTB CDSA Practice Questions
Prepare for the HTB Certified Defensive Security Analyst exam with instant access — no signup required.
Loading practice questions...
Explore More Hack The Box Certifications
Continue into nearby exams from the same family. Each card keeps practice questions, study guides, flashcards, videos, and articles in one place.
Key Facts: HTB CDSA Exam
7 days
Practical Exam Window
Hack The Box
15 modules
SOC Analyst Path
HTB Academy
~$210
Exam Voucher
Hack The Box
Intermediate
Difficulty Level
Hack The Box
150-250 hrs
Avg. Study Time
Community estimate
2 incidents
Exam Scenarios
CDSA review reports
The HTB CDSA (Certified Defensive Security Analyst) certifies intermediate SOC analyst skills through a 7-day practical lab and incident report. Domains include SIEM operations (Elastic/Splunk), network traffic analysis (Wireshark/tcpdump), Windows event log analysis, YARA and Sigma rule writing, threat hunting, Windows/AD attack detection, and incident reporting. The exam voucher costs ~$210 or is included in an HTB Academy Silver subscription (~$490/year). This 100-question practice exam covers the knowledge domains of the 15-module HTB SOC Analyst path.
Sample HTB CDSA Practice Questions
Try these sample questions to test your HTB CDSA exam readiness. Each question includes a detailed explanation. Start the interactive quiz above for the full 100+ question experience with AI tutoring.
1In the NIST incident handling lifecycle, which phase immediately follows the Detection and Analysis phase?
2A SOC analyst sees 50 failed Windows logon events (Event ID 4625) in 10 minutes from a single source IP targeting one account. Which attack type does this most likely indicate?
3Which Sysmon Event ID records the creation of a new process and is most useful for detecting execution of malicious binaries?
4In Elastic/KQL, which query correctly searches for all Windows Security events with Event ID 4688 (process creation)?
5A Wireshark capture shows repeated TCP SYN packets sent to ports 21, 22, 23, 25, 80, and 443 on a target host with no SYN-ACK responses. What does this traffic pattern indicate?
6In Splunk SPL, which search correctly identifies authentication failures for the Windows Security log?
7Which MITRE ATT&CK tactic describes actions taken by an adversary to maintain access to a compromised system across restarts?
8A YARA rule contains the condition `all of them`. What does this mean?
9In a Sigma rule, which field specifies the log source category (e.g., process_creation)?
10Windows Event ID 4624 logon type 3 indicates which type of authentication?
About the HTB CDSA Exam
The HTB Certified Defensive Security Analyst (CDSA) is a hands-on SOC-focused certification by Hack The Box. Candidates spend 7 days working through a realistic SOC lab environment covering two incidents, then submit a professional incident report graded by HTB staff. This practice exam prepares candidates by testing knowledge of Elastic, Splunk, Wireshark, Windows event logs, YARA, Sigma, MITRE ATT&CK, and incident handling.
Assessment
Performance-based assessment
Time Limit
7 days (lab) + incident report
Passing Score
Not published
Exam Fee
~$210 voucher (Hack The Box)
HTB CDSA Exam Content Outline
Security Analysis & SIEM Operations
Elastic KQL/EQL, Splunk SPL, Winlogbeat/Filebeat, detection rules, alert triage, and Kibana threat hunting workflows
Windows Event Logs & Endpoint Detection
Critical Windows Security and System Event IDs, Sysmon event types, PowerShell logging, and detecting credential theft, persistence, and lateral movement
Network Traffic Analysis & IDS
Wireshark display filters, tcpdump BPF syntax, Snort/Suricata rules, protocol analysis, C2 beaconing, DNS tunneling, and ARP attacks
YARA & Sigma Detection Engineering
YARA rule structure (strings, conditions, PE module, imphash), Sigma rule structure (logsource, detection, modifiers, level), and sigmac conversion
Incident Handling & Reporting
NIST SP 800-61 lifecycle, containment strategies, evidence collection, IOC documentation, and professional incident report writing
How to Pass the HTB CDSA Exam
What You Need to Know
- Passing score: Not published
- Assessment: Performance-based assessment
- Time limit: 7 days (lab) + incident report
- Exam fee: ~$210 voucher
Keys to Passing
- Work through all 100 available questions
- Review every answer and explanation
- Track weak areas and revisit them
- Use our AI tutor for tough concepts
HTB CDSA Study Tips from Top Performers
Frequently Asked Questions
What is the HTB CDSA exam format?
The HTB CDSA is a 7-day practical exam in a browser-based SOC lab environment. Candidates analyze multiple real-world security incidents using SIEM platforms (Elastic and Splunk), network traffic analysis tools, and Windows event logs. After completing the lab, candidates must submit a professional-grade security incident report. Results take up to 20 business days and are evaluated by HTB staff.
What modules are in the HTB CDSA SOC Analyst path?
The 15-module path includes: Incident Handling Process; Security Monitoring & SIEM Fundamentals; Windows Event Logs & Finding Evil; Introduction to Threat Hunting & Hunting With Elastic; Understanding Log Sources & Investigating with Splunk; Windows Attacks & Defense; Intro & Intermediate Network Traffic Analysis; Working with IDS/IPS; YARA & Sigma for SOC Analysts; Detecting Windows Attacks with Splunk; JavaScript Deobfuscation; Introduction to Digital Forensics; Introduction to Malware Analysis; and Security Incident Reporting.
How much does the HTB CDSA cost?
The CDSA exam voucher costs approximately $210 USD when purchased standalone. An HTB Academy annual Silver subscription (~$490/year) includes one exam voucher for CDSA, CWES, or CPTS. This makes the Silver subscription economical if you plan to take any of the three HTB certification exams.
How hard is the HTB CDSA?
The CDSA is rated intermediate difficulty. It requires practical hands-on skills in SIEM analysis, Windows event log investigation, network traffic analysis, and incident report writing. Candidates who have completed all 15 modules of the SOC Analyst path and worked through the included labs are best positioned to pass. The 7-day window is generous, but the quality of the incident report is critical.
What jobs does HTB CDSA qualify me for?
HTB CDSA demonstrates practical SOC analyst skills valued in: SOC Analyst Tier 1/2 ($55,000-$85,000), Security Analyst ($70,000-$110,000), Incident Responder ($80,000-$120,000), Threat Hunter ($90,000-$130,000), and Detection Engineer ($95,000-$140,000) roles. It complements vendor certifications (Splunk Core Certified User, Elastic Certified Analyst) and broad certs (CompTIA Security+).
Is this practice exam like the real HTB CDSA?
No — this is a knowledge-based multiple-choice practice exam. The real CDSA is a hands-on practical lab where you analyze actual security incidents in a live environment and write a professional report. This practice exam tests the theoretical knowledge and tool concepts from the 15-module SOC Analyst path. To pass the real exam, you need extensive lab practice with Elastic, Splunk, Wireshark, and Windows event log analysis.