The HTB Certified Defensive Security Analyst (CDSA) is one of the toughest blue team certifications you can sit, and it does not hand out marks for guessing. There is no multiple choice, no partial credit for a lucky click, and no way to bluff your way past the report. If you want to know how to pass the HTB CDSA exam in 2026, the honest answer is that it takes a proper plan, real hands-on repetition, and a written report good enough to hand a paying client.
This guide gives you that plan. You will get the exact exam mechanics, the points threshold and report rules that trip people up, a realistic week-by-week schedule, and the tools and habits that separate a pass from a resit. Candidates routinely describe the CDSA as "difficult with a capital D", so treat it with respect and you will come out the other side with a certification that actually proves you can run a SOC investigation end to end.
What Is the HTB CDSA and Who Is It For?
The CDSA is Hack The Box's practical certification for defensive security analysts. Where the HTB CPTS proves you can break in, the CDSA proves you can detect, investigate and report on an intrusion the way a real security operations centre would. It sits alongside other hands-on blue team certs like the BTL1 but goes deeper on threat hunting, SIEM analysis and incident handling.
It is aimed at:
- Aspiring and junior SOC analysts who want a certification that mirrors the day job
- Tier 1 and tier 2 analysts looking to prove threat hunting and incident response skill
- Career changers moving from IT support or networking into defensive security
- Red teamers who want to understand how their activity looks from the blue side
The exam validates security analysis, SOC operations, and incident handling across real-world, heterogeneous networks. In plain terms, you are dropped into a messy environment, told an incident has happened, and expected to work out what, when, how and what to do next.
Exam Tip: The CDSA is not a knowledge quiz, it is a simulation of your job. Every hour you spend inside a real SIEM, parsing real logs, is worth more than any amount of passive video watching.
HTB CDSA Exam Format and Pass Requirements
Understanding exactly how the exam is scored is the first step to passing it. The CDSA has two parts, and you must clear both.
| Exam element | Detail |
|---|---|
| Format | Practical lab investigation, no multiple choice |
| Duration | 7 days to complete the lab and upload your report |
| Scenario | Investigate real-world style incidents across multiple hosts and networks |
| Scoring part 1 | Reach the minimum points threshold by answering exam objectives |
| Scoring part 2 | Submit a professional, commercial-grade incident report |
| Attempts | Two attempts per voucher |
| Report format | Unencrypted PDF or ZIP, no password, 20MB maximum |
| Results | Presented within 20 business days |
| Cost | Around 210 US dollars per voucher, or included with an HTB Academy Silver annual subscription |
Here is the part people underestimate. An HTB Academy assessor first checks whether you gathered the minimum required points during the lab. Only if you clear that bar do they then read and grade your report. If your report is weak, you can still fail even after collecting enough points in the lab.
The two-part scoring model
- Points from the lab. As you investigate, you answer exam objectives (the equivalent of flags). Each correct objective adds points. You must reach the undisclosed minimum threshold to move to stage two.
- The incident report. You write up the full investigation as if delivering it to a client or manager: timeline, indicators of compromise, attack narrative, evidence, and remediation advice.
Exam Tip: Treat the report as 50 percent of the exam from day one, not something you throw together on day seven. Successful candidates often submit reports of 60 pages or more, built up as they investigate, not written from memory at the end.
Attempts and retakes
Each voucher includes two attempts. If you fail the first attempt, you must still submit a report to remain eligible for the retake, and you then have 14 days from receiving your feedback to start the second attempt. That feedback is genuinely useful, so read it carefully before you dive back in.
Prerequisites: What You Need to Know Before You Start
The CDSA assumes real foundational knowledge. Attempting it cold is the fastest route to a resit. Before you buy a voucher, you should be comfortable with:
- Windows internals and Active Directory. Most enterprise intrusions live here. Know processes, services, event logs, authentication and lateral movement artefacts.
- Networking fundamentals. You need to read packet captures and network logs without panicking. The CompTIA Network+ level of knowledge is a sensible floor.
- SIEM and log analysis. Splunk in particular. You will live inside search queries.
- The attack lifecycle. Recognise reconnaissance, initial access, persistence, privilege escalation, lateral movement and exfiltration when you see them in logs.
If you are missing the security fundamentals, a solid grounding like CompTIA Security+ or CySA+ first will make the CDSA far less painful. The CDSA is not a beginner's first certification, it is where you go once you already understand the basics of defence.
The Core Prep: HTB Academy SOC Analyst Path and CDSA Track
The single most important preparation is the official HTB Academy content. There are two pieces that matter most.
The SOC Analyst job role path
Finish the SOC Analyst path fully, and make sure you actually understand it rather than just marking modules complete. It covers security monitoring, SIEM fundamentals, Windows and network event analysis, threat hunting and incident handling. This path is the backbone of everything the exam tests.
The CDSA Preparation track
The CDSA Preparation track equips you with real-world defensive expertise through 11 hands-on scenarios, spanning security analysis, SOC operations and incident handling. Work through every scenario, and repeat any where you needed hints. The exam feels like an extension of these labs, so the more fluent you are here, the calmer you will be on exam day.
Exam Tip: Do not rush the Academy modules to reach the exam sooner. Every module you half-learn becomes a gap you pay for during the 7-day lab, when there is no time to go back and study.
Your Week-by-Week HTB CDSA Study Plan
This plan assumes roughly 10 to 15 hours of study per week over 10 weeks. Compress it if you already work in a SOC, or extend it if you are newer to defence. The goal is fluency, not box ticking.
Weeks 1 to 2: Foundations and tooling
- Refresh Windows event log analysis, Sysmon, and Active Directory basics.
- Get comfortable in Splunk. Learn SPL search syntax, fields, stats and timecharts until searching feels natural.
- Practise reading a PCAP in Wireshark and pulling out the story.
Weeks 3 to 5: The SOC Analyst path
- Work through the full HTB Academy SOC Analyst path, module by module.
- Take structured notes in a format you can reuse: what the artefact was, where you found it, and what it proved.
- Redo any lab section that needed a walkthrough until you can do it unaided.
Weeks 6 to 8: The CDSA Preparation track
- Complete all 11 hands-on scenarios in the CDSA Preparation track.
- For each scenario, write a mini incident report. This builds the exact muscle the exam grades.
- Practise the Splunk Boss of the SOC (BOTS) challenges for extra investigation reps.
Week 9: Report craft and dry runs
- Build a reusable report template: executive summary, incident timeline, indicators of compromise, attack narrative, affected hosts, and remediation recommendations.
- Do a full timed dry run on a preparation scenario, producing a complete report from start to finish.
- Get feedback on your report structure from a peer or mentor if you can.
Week 10: Exam readiness
- Rest, review your notes, and confirm your lab environment and note-taking setup work smoothly.
- Book the exam only when you can complete preparation scenarios without hints and write a clean report.
The Incident Report: Where Most People Lose Marks
The report is what makes the CDSA feel like a real job, and it is where under-prepared candidates fail even after collecting enough lab points. Your report must be a commercial-grade document an employer would accept.
A strong CDSA report includes:
- Executive summary. A short, plain-English overview a manager could read.
- Incident timeline. A clear chronological account of the attack, with timestamps.
- Indicators of compromise. Hashes, IP addresses, domains, filenames and account names, presented cleanly.
- Attack narrative. How the adversary got in, what they did, and how they moved.
- Evidence. Screenshots and log extracts that back every claim you make.
- Remediation and recommendations. What the organisation should do to contain, eradicate and prevent recurrence.
Remember the technical rules: upload an unencrypted PDF or ZIP, no password protection, 20MB maximum, in English, within your 7-day window.
Exam Tip: Write the report as you investigate, not at the end. Every time you confirm a finding in the lab, paste the evidence and a sentence of explanation straight into your report draft. By day six you are editing, not scrambling.
Common Mistakes That Cause a Resit
Learn from the candidates who came before you and avoid these traps:
- Skipping the SOC Analyst path. The exam assumes that knowledge. There is no shortcut around it.
- Leaving the report to the last day. A rushed report fails even with enough points.
- Weak note-taking during the lab. If you cannot find your own evidence again, you cannot document it.
- Poor time management across 7 days. Plan investigation days and report days rather than treating it as one long panic.
- Ignoring remediation. Analysts who only describe the attack, and never advise on the fix, lose report marks.
Is the HTB CDSA Worth It in 2026?
For anyone targeting a SOC analyst, threat hunter or incident responder role, the CDSA carries real weight because it proves practical skill rather than memorised theory. Employers increasingly value hands-on certifications they can trust, and a 7-day investigation plus a graded report is hard to fake. If you already hold a knowledge-based cert like CySA+ or Security+, the CDSA is the natural next step that shows you can actually do the work.
If you are still early in your journey, build the fundamentals first, then come back. The CDSA rewards depth, and it will feel far more achievable once the basics are second nature.
Ready to Start Practising?
Passing the HTB CDSA comes down to hands-on repetition and confident recall of core defensive concepts, and that is exactly what structured practice builds. CertCrush helps you drill the SOC, incident response and security fundamentals that underpin the exam, so you walk into your 7-day lab already fluent.
- Create a free CertCrush account and start practising today
- Browse our certification courses to shore up the fundamentals behind the CDSA
- Read more study guides on the CertCrush blog to plan your next certification
Put the plan into action, do the reps, and write a report you would be proud to hand a client. Get that right and you will earn one of the most respected blue team certifications going. Start your preparation with CertCrush now.
