The CYBER 5W Certified Threat Analyst (CCTA) Exam is a comprehensive, hands-on assessment designed to validate your ability to analyze cyber threats, investigate malicious activity, and apply structured threat analysis methodologies based on realistic scenarios.
Participants will be provided with analysis materials, including malware samples, system artifacts, and network indicators, representing scenarios inspired by real-world incidents such as malware infections, suspicious network activity, and system compromise.
The exam encompasses:
-
Threat Identification and Analysis: Identifying attacker objectives, techniques, and indicators of compromise.
-
Malware Analysis: Examining malicious samples to understand behavior using static and dynamic analysis concepts.
-
System and Process Analysis: Investigating processes, persistence mechanisms, and system interactions related to malicious activity.
-
Network Analysis: Analyzing network communications to identify command-and-control activity.
During the exam, candidates are expected to perform the following analysis tasks:
-
Analysis Methodology: Apply appropriate tools and techniques during static and dynamic analysis.
-
Threat Assessment: Identify malicious behavior, attacker techniques, and indicators of compromise.
-
Behavioral Analysis: Interpret observed system, process, and network activity.
-
Technical Findings: Analyze malware behavior, execution flow, and overall impact.
-
-
-
Instructions to Start the Exam
-
Hardware & Software Requirements
-
- Profile threat actors by analyzing tactics, techniques, and procedures (TTPs).
- Map observed malicious behaviors to the MITRE ATT&CK framework.
- Identify, categorize, and analyze indicators of compromise (IOCs).
- Perform basic log, system, and network traffic analysis.
- Leverage open-source threat intelligence platforms during investigations.
- Understand and apply incident response concepts within a threat analysis context.