Available Exams

Browse our selection of certification exams and practice tests to validate your knowledge.

Cyber Threat Intelligence 40m

AA23-108 APT28 Router Exploitation Analysis

Research how APT28 used weak SNMP configuration and a known Cisco vulnerability to enumerate routers, deploy Jaguar Tooth, collect network data, and maintain covert access.

Cyber Threat Intelligence 50m

AA23-129A Snake Implant Architecture

Examine the Snake implant's Windows persistence, encrypted artifacts, Queue structure, modular protocol stack, layered encryption, and global peer-to-peer relay design.

Cyber Threat Intelligence 45m

AA23-136A BianLian Intrusion Tradecraft

Research BianLian's access, proxying, privilege escalation, discovery, credential theft, defense evasion, and changing extortion model from the joint advisory.

Cyber Threat Intelligence 40m

AA23-158A MOVEit LEMURLOOT Research

Investigate CL0P's MOVEit Transfer campaign by connecting the exploited SQL injection to LEMURLOOT authentication, database access, privileged-account behavior, and data theft.

Cyber Threat Intelligence 45m

AA23-187A Truebot Toolchain Investigation

Trace Truebot from delivery and environment checks through FlawedGrace execution, in-memory follow-on activity, encoded collection, and Teleport exfiltration.

Cyber Threat Intelligence 35m

AA23-193A Outlook Online Audit Investigation

Use official reporting to distinguish normal Exchange Online access from forged-token activity and choose logging and retention measures that preserve investigative evidence.

Cyber Threat Intelligence 45m

AA23-201A Citrix NetScaler Artifact Analysis

Analyze appliance-side webshell, privilege, staging, persistence, and anti-forensic artifacts from exploitation of Citrix NetScaler ADC and Gateway systems.

Cyber Threat Intelligence 45m

AA23-213A Ivanti EPMM Forensic Hunting

Investigate a vulnerability chain against Ivanti EPMM and use API, log, user-agent, certificate, and webshell evidence to design defensible hunting conclusions.

Cyber Threat Intelligence 40m

AA23-242A QakBot Infrastructure Research

Research QakBot's evolution, tiered command-and-control design, registry persistence, and the operational limits of the 2023 disruption.

Cyber Threat Intelligence 40m

AA23-250A Aeronautical Intrusion Timeline Analysis

Reconstruct two nation-state intrusion paths at an aeronautical organization and connect account, malware, credential, and network evidence to the correct phase of the investigation.

Cyber Threat Intelligence 45m

AA23-263A Snatch Safe-Mode Encryption and Dwell-Time Analysis

Investigate Snatch's RDP entry, bulletproof-hosted command-and-control, long dwell time, service manipulation, Safe Mode boot, shadow-copy removal, filename masquerading, and recovery note.

Cyber Threat Intelligence 50m

AA23-270A BlackTech Router Firmware and Trusted-Pivot Investigation

Analyze BlackTech's subsidiary-to-headquarters pivots, router firmware replacement, ROMMON bypass, unlogged SSH backdoors, EEM output manipulation, and magic-packet activation.

Cyber Threat Intelligence 50m

AA23-278A Active Directory Misconfiguration Exploitation Lab

Use NSA and CISA assessment findings to analyze ADCS relay, name-resolution poisoning, unsigned SMB, weak network-share controls, cleartext credential discovery, and unrestricted code execution.

Cyber Threat Intelligence 45m

AA23-284A AvosLocker Dual-Use Tool and NetMonitor Detection Analysis

Classify AvosLocker remote administration, tunneling, credential theft, exfiltration, scripting, web-shell persistence, and the NetMonitor reverse-proxy behavior captured by the FBI YARA rule.

Cyber Threat Intelligence 45m

AA23-289A Confluence Administrator-Creation and Exfiltration Hunt

Investigate exploitation of Confluence setup state, unauthorized administrator creation, Rclone configuration, observed user agents, product scope, and post-compromise recovery decisions.

Cyber Threat Intelligence 50m

AA23-319A Rhysida Staging, Cloud Transfer, and Encryptor Research

Investigate Rhysida's valid-account access, MFT evidence, Windows staging, remote execution, Azure storage utilities, process injection, cryptographic design, and ransom-note artifact.

Cyber Threat Intelligence 50m

AA23-320A Scattered Spider Helpdesk-to-Cloud Intrusion Analysis

Trace Scattered Spider from helpdesk impersonation and MFA transfer through legitimate remote tools, credential stealers, AWS discovery, Snowflake collection, response monitoring, and ESXi impact.

Cyber Threat Intelligence 50m

AA23-325A Citrix Bleed Session-Theft and LockBit Payload Analysis

Investigate how LockBit affiliates extracted NetScaler session material, bypassed MFA, staged an encoded DLL, required a launch key, and established command-and-control.

Cyber Threat Intelligence 50m

AA23-335A CyberAv3ngers Unitronics PLC Impact Reconstruction

Analyze IRGC-affiliated compromise of Unitronics PLCs, including exposed engineering access, ladder-logic replacement, device renaming, version rollback, port changes, and HMI defacement.

Cyber Threat Intelligence 50m

AA23-339A ColdFusion Web-Shell and Registry-Dump Investigation

Reconstruct two ColdFusion compromises from vulnerable versions and exploit paths through web-shell decoding, credential artifacts, network reconnaissance, and failed exfiltration.

Cyber Threat Intelligence 45m

AA23-341A Star Blizzard Persona-to-Session Spearphishing Analysis

Trace Star Blizzard from open-source persona research and rapport building through Evilginx session theft, personal-email targeting, mailbox collection, and follow-on phishing.

Cyber Threat Intelligence 50m

AA23-347A SVR TeamCity Supply-Chain Foothold Investigation

Examine SVR exploitation of TeamCity, software-build risk, EDRSandBlast defense evasion, GraphicalProton's cloud covert channel, registry collection, and server-log evidence.

Cyber Threat Intelligence 45m

AA23-352A Play Ransomware Windows-to-ESXi Technical Hunt

Compare Play's Windows and ESXi operations, initial-access CVEs, custom discovery tooling, Group Policy distribution, intermittent encryption, and campaign-specific recompilation.

Cyber Threat Intelligence 45m

AA23-353A ALPHV Blackcat Access and Affiliate Tooling Research

Analyze ALPHV Blackcat's social engineering, remote tooling, adversary-in-the-middle credential theft, Kerberos access, defense evasion, exfiltration, and encryptor artifacts.

Cyber Threat Intelligence 45m

AA24-016A Androxgh0st Web Exposure and Cloud-Credential Hunt

Investigate how Androxgh0st finds exposed application secrets, chains PHPUnit and Laravel weaknesses, exploits Apache path traversal, and repurposes stolen cloud credentials.

Cyber Threat Intelligence 45m

AA24-046A Former-Employee Account and LDAP Evidence Investigation

Reconstruct a state-government intrusion from a retained former-employee account through SharePoint credential exposure, LDAP discovery, CIFS access, and cloud scoping.

Cyber Threat Intelligence 45m

AA24-057A SVR Cloud Identity and Session-Persistence Analysis

Assess how SVR operators target service and dormant accounts, reuse tokens, manipulate MFA enrollment, and hide authentication behind residential proxies.

Cyber Threat Intelligence 45m

AA24-060A Phobos Intrusion Command and Exfiltration Research

Trace a Phobos intrusion from exposed RDP and loader behavior through firewall changes, credential access, exfiltration, recovery inhibition, and ransom-note execution.

Cyber Threat Intelligence 45m

AA24-060B Ivanti Appliance Forensics and Integrity-Check Assessment

Evaluate an Ivanti Connect Secure intrusion where web shells, credential exposure, root persistence, and anti-forensic activity challenged normal appliance validation.

Cyber Threat Intelligence 45m

AA24-109A Akira Hypervisor and Credential-Theft Investigation

Investigate Akira's evolving hypervisor targeting, identity tradecraft, defense evasion, and virtual-disk credential theft using the official joint advisory.

Cyber Threat Intelligence 40m

AA24-131A Black Basta Social-Engineering and Encryption Research

Trace Black Basta's email-bombing support scam, RMM deployment, ConnectWise exploitation, masqueraded discovery, EDR disabling, exfiltration, and cryptographic impact.

Cyber Threat Intelligence 45m

AA24-190A APT40 Case-Study Evidence Research

Compare two APT40 incident-response case studies involving a custom web application, service-account compromise, Secure Socket Funnelling, remote-access appliances, MFA artifacts, and session tokens.

Cyber Threat Intelligence 45m

AA24-193A SILENTSHIELD Detection-Evasion Investigation

Use the SILENTSHIELD report to analyze parallel access paths, long dwell time, diversified implants, timestamp tampering, Sysmon visibility, and organizational response failures.

Cyber Threat Intelligence 45m

AA24-207A Andariel Espionage and Malware Research

Investigate the DPRK RGB 3rd Bureau's defense collection requirements, ransomware funding, web-server exploitation, custom RAT inventory, command habits, and packed tooling.

Cyber Threat Intelligence 45m

AA24-241A Iran-Based Access-Broker Tradecraft Investigation

Investigate how an Iran-linked group turns edge-device exploitation into credential capture, durable access, ransomware partnerships, and separate state-aligned collection.

Cyber Threat Intelligence 45m

AA24-242A RansomHub Encryption-Format Investigation

Research RansomHub's affiliate model, exploit set, exfiltration separation, Curve25519 encryption, intermittent block processing, and encrypted-file trailer structure.

Cyber Threat Intelligence 45m

AA24-249A GRU Unit 29155 Infrastructure Investigation

Research Unit 29155's scanning, vulnerability exploitation, IP-camera access, tunneling, post-exploitation tools, and destructive mission using the joint advisory.

Cyber Threat Intelligence 40m

AA24-290A Iranian Credential-Access Investigation

Trace an Iranian access operation from password spraying and MFA registration through Kerberos discovery, living-off-the-land reconnaissance, and probable resale of network access.

Cyber Threat Intelligence 40m

AA24-317A 2023 Exploited-Vulnerability Evidence Research

Use the multinational report to compare zero-day prevalence, exploitation windows, affected products, weakness classes, and exploit consequences among 2023's top vulnerabilities.

Cyber Threat Intelligence 45m

AA24-326A Critical-Infrastructure Red-Team Reconstruction

Reconstruct how a CISA red team moved from a forgotten webshell through Linux credential stores and Kerberos delegation to domain compromise, then evaluate the defender response.

Cyber Threat Intelligence 45m

AA25-022A Ivanti CSA Exploit-Chain Investigation

Trace two Ivanti Cloud Service Appliance exploit chains from access-control bypass through credential theft, command execution, webshell attempts, and lateral movement.

Cyber Threat Intelligence 40m

AA25-050A Ghost Ransomware Intrusion Research

Investigate Ghost's opportunistic exploitation, short dwell time, Cobalt Strike execution, encoded lateral movement, limited exfiltration, and recovery inhibition.

Cyber Threat Intelligence 40m

AA25-071A Medusa Ransomware Operations Investigation

Research Medusa's broker model, discovery ports, PowerShell evasion, lateral movement, encryption artifacts, and extortion process from documented investigations.

Cyber Threat Intelligence 35m

AA25-093A Fast-Flux DNS Infrastructure Investigation

Research fast-flux infrastructure as a CTI collection problem, distinguish single from double flux, and evaluate DNS evidence without misclassifying legitimate CDNs.

Cyber Threat Intelligence 40m

AA25-141B LummaC2 Configuration and Execution Research

Analyze LummaC2's delivery, host checks, command configuration, browser theft, download execution, and memory-resident behavior using the FBI and CISA report.

Cyber Threat Intelligence 45m

AA25-141A GRU Logistics and Camera Targeting Investigation

Trace GRU Unit 26165's credential attacks, vulnerability use, Active Directory collection, logistics intelligence requirements, and IP-camera reconnaissance.

Cyber Threat Intelligence 35m

AA25-163A SimpleHelp Downstream-Exposure Investigation

Investigate how an unpatched remote-management component exposed a software provider's downstream customers and determine the correct discovery and response steps.

Cyber Threat Intelligence 40m

AA25-203A Interlock Ransomware Attack-Chain Research

Reconstruct Interlock's unusual initial access, persistence, credential theft, Azure exfiltration, and virtual-machine encryption from the joint advisory.

Cyber Threat Intelligence 35m

AA25-212A Critical-Infrastructure Hunt Gap Analysis

Use the CISA and U.S. Coast Guard hunt report to decide which observed configuration and logging gaps would prevent defensible incident analysis in an IT/OT environment.

Cyber Threat Intelligence 40m

AA25-239A Network-Device Espionage Investigation

Investigate the joint government report on PRC-linked compromises of telecommunications and edge infrastructure, then distinguish vulnerable-device activity from normal router behavior.

Cyber Threat Intelligence 40m

YARA Rule Technical Investigation

Research official YARA rule syntax to interpret string types, modifiers, hex wildcards and jumps, Boolean conditions, occurrence counts, identifiers, and output behavior for malware-focused collection.

Cyber Threat Intelligence 40m

Sigma Detection Rule Technical Investigation

Research Sigma's official rule format to interpret log sources, detection selections, conditions, field modifiers, status, severity, false positives, and portable rule intent.

Cyber Threat Intelligence 45m

Certificate Transparency RFC Investigation

Research IETF Certificate Transparency v2 to interpret signed certificate timestamps, tree heads, inclusion and consistency proofs, monitor behavior, and the evidentiary limits of public certificate logs.

Cyber Threat Intelligence 45m

RDAP Registration Data Technical Investigation

Research IETF RDAP JSON to interpret domain, network, autonomous-system, entity, event, status, notice, remark, and extension data without overclaiming what registration records prove.

Cyber Threat Intelligence 45m

GitHub Advisory and SBOM Investigation

Research GitHub's official APIs to retrieve security advisories, apply vulnerability filters, export dependency evidence, and interpret SPDX package and relationship data for supply-chain decisions.

Cyber Threat Intelligence 40m

Kubernetes Audit Policy Technical Investigation

Research Kubernetes auditing to identify event stages, select policy levels, understand first-match evaluation, configure the API server, and balance investigative detail with sensitive-data exposure.

Cyber Threat Intelligence 45m

Google Cloud Audit Log Evidence Investigation

Research Google Cloud's official audit-log structure to identify log classes, principals, services, methods, resources, policy denials, and the correct filters for security investigations.

Cyber Threat Intelligence 45m

AWS CloudTrail Event Attribution Investigation

Research AWS CloudTrail's official event schema to attribute API activity, interpret assumed-role sessions, preserve source identity, and distinguish reliable event fields from contextual clues.

Cyber Threat Intelligence 45m

Microsoft Defender XDR Hunting Schema Investigation

Use Microsoft Defender XDR's official advanced-hunting schema to select event tables, interpret process and network fields, correlate unique events, and retrieve trustworthy signing evidence.

Cyber Threat Intelligence 40m

Microsoft Entra Sign-In Evidence Investigation

Research Microsoft Entra and Microsoft Graph documentation to distinguish sign-in types, interpret risk and Conditional Access fields, understand aggregation, and avoid misreading identity evidence.

Cyber Threat Intelligence 45m

CISA Joint Advisory Evidence Hunt: Volt Typhoon

Research CISA joint advisory AA24-038A to extract exact living-off-the-land commands, artifacts, ATT&CK mappings, persistence observations, and investigative implications from reported victim evidence.

Cyber Threat Intelligence 35m

CISA ICS Advisory Technical Investigation

Extract vulnerability, product, impact, weakness, scoring, and affected-version evidence from a specific CISA industrial control systems advisory without substituting assumptions about operational exposure.

Cyber Threat Intelligence 45m

TAXII 2.1 API Technical Investigation

Research the OASIS TAXII 2.1 standard to discover servers, interpret API roots and collection permissions, retrieve manifests, filter STIX objects, and handle protocol pagination correctly.

Cyber Threat Intelligence 45m

STIX 2.1 Object Modeling Investigation

Research the OASIS STIX 2.1 specification to model indicators, observed data, relationships, sightings, bundles, and object properties without confusing transport containers with intelligence assertions.

Cyber Threat Intelligence 40m

MITRE ATT&CK Group and Software Investigation

Investigate a live ATT&CK group record to connect aliases, techniques, procedure evidence, software, commands, vulnerabilities, and infrastructure into a sourced actor profile.

Cyber Threat Intelligence 40m

MITRE ATT&CK Technique Page Investigation

Navigate live MITRE ATT&CK technique pages to identify tactics, platforms, parent-child relationships, procedure evidence, and the difference between behavior categories and observed implementations.

Cyber Threat Intelligence 40m

NVD CVE, CPE, and API Record Investigation

Research NIST's official NVD developer documentation to distinguish CVE publication from NVD enrichment, navigate CVE API responses, and build precise CPE and pagination queries.

CVSS:4.0
Cyber Threat Intelligence 40m

CVSS v4 Vector Technical Research

Navigate FIRST's CVSS v4 specification and data representations to interpret metric groups, vector nomenclature, impact separation, and the role of supplemental context.

Cyber Threat Intelligence 35m

FIRST EPSS Data and API Investigation

Use FIRST's official EPSS documentation, API, and data guidance to retrieve exploitation probabilities, interpret percentiles, choose filters, and avoid treating EPSS as a complete risk score.

Cyber Threat Intelligence 35m

CISA KEV Catalog Technical Investigation

Research the authoritative CISA Known Exploited Vulnerabilities catalog, interpret its machine-readable fields, and turn catalog evidence into defensible vulnerability-prioritization decisions.

Cyber Threat Intelligence 30m

CTI Program Metrics, Governance & Intelligence Value

Test your ability to evaluate and govern a CTI program through outcome metrics, stakeholder value, service levels, source portfolios, quality review, ethical controls, sharing governance, capability maturity, and investment decisions.

Cyber Threat Intelligence 30m

CTI in Incident Response & Campaign Reconstruction

Test your ability to fuse incident evidence with external intelligence, build defensible timelines, separate observations from hypotheses, reconstruct campaign scope, generate intelligence leads, and feed lessons back into response and analysis.

Cyber Threat Intelligence 30m

CTI Phishing Campaigns & Social Engineering Analysis

Test your ability to analyze phishing and social-engineering campaigns through lure themes, delivery chains, sender infrastructure, credential capture, payload staging, audience targeting, campaign clustering, and defensive intelligence.

Cyber Threat Intelligence 30m

CTI Identity Threats & Access Tradecraft

Test your ability to analyze credential theft, session hijacking, MFA abuse, identity-provider compromise, privileged access, credential marketplaces, authentication telemetry, and identity-centered adversary tradecraft.

Cyber Threat Intelligence 30m

CTI Supply Chain & Third-Party Threat Analysis

Test your ability to assess software, service-provider, dependency, and vendor compromise scenarios using relationship mapping, upstream evidence, blast-radius analysis, trust paths, prioritization, and third-party intelligence requirements.

Cyber Threat Intelligence 30m

CTI for Cloud & SaaS Threats

Test your ability to produce threat intelligence for cloud and SaaS environments, including identity-centric intrusion paths, control-plane activity, tenant context, exposed credentials, shared responsibility, cloud-native telemetry, and cross-tenant campaigns.

Cyber Threat Intelligence 30m

CTI Ransomware Ecosystems & Extortion Operations

Test your ability to analyze ransomware ecosystems, distinguish operator and affiliate roles, interpret leak sites and negotiations, assess initial access, track rebrands, and produce decision-relevant extortion intelligence.

Cyber Threat Intelligence 30m

CTI Geopolitical Context & State-Sponsored Threats

Test your ability to assess how geopolitical events shape state-sponsored cyber activity while separating context from evidence, identifying strategic objectives, building indicators, and avoiding deterministic attribution.

Cyber Threat Intelligence 30m

CTI Threat Actor Profiling & Behavioral Analysis

Test your ability to build and maintain defensible threat actor profiles using motivation, intent, capability, constraints, victimology, behavioral patterns, naming discipline, and confidence-aware attribution.

Cyber Threat Intelligence 30m

CTI Strategic Intelligence & Executive Decision Support

Test your ability to turn threat developments into decision-relevant strategic intelligence, including horizon scanning, business impact, scenarios, warning indicators, estimative language, and executive communication.

CYBERSECURITYESSENTIALS 2026Emerging Threats & DefensesZero Trust · AI Security · Quantum Risk · Supply Chain
Cybersecurity 30m

Cybersecurity Essentials 2026: Emerging Threats and Defenses

This comprehensive exam assesses foundational knowledge in cybersecurity as of 2026, covering emerging threats like AI-driven attacks, quantum computing risks, post-quantum cryptography, zero-trust architecture, supply chain security, cloud-native vulnerabilities, and regulatory updates (e.g., NIS2, DORA). It includes 15 multiple-choice and true/false questions designed for professionals seeking to validate their understanding of modern cyber defense strategies.

Cyber Threat Intelligence 30m

CTI Malware Analysis & Campaign Tracking

Test your ability to analyze malware-related intelligence, distinguish families from samples, connect technical evidence to campaigns, evaluate behavioral and code similarities, interpret configuration and infrastructure relationships, track campaign evolution, and communicate confidence without overstating attribution in Cyber Threat Intelligence.

Cyber Threat Intelligence 30m

CTI Adversary Infrastructure & Pivoting

Test your ability to analyze adversary infrastructure, interpret passive DNS and historical registration data, assess infrastructure overlap, account for shared hosting and temporal context, validate investigative pivots, evaluate clustering confidence, and avoid unsupported attribution in Cyber Threat Intelligence.

Cyber Threat Intelligence 30m

CTI Collection & Requirements Management

Test your ability to define and manage Cyber Threat Intelligence requirements, plan collection, select and evaluate sources, identify collection gaps, process incoming information, align reporting with stakeholder needs, and use feedback to improve the intelligence cycle.

Cyber Threat Intelligence 30m

CTI for Detection & Threat Hunting

Test your ability to apply Cyber Threat Intelligence to detection engineering and threat hunting, including hypothesis development, telemetry selection, indicator use, behavioral detection, ATT&CK mapping, detection gaps, hunt prioritization, and translating intelligence into operational security actions.

Cyber Threat Intelligence 35m

Advanced CTI & Structured Intelligence

Test your ability to work with structured Cyber Threat Intelligence concepts, including STIX object types, relationships, indicators, sightings, markings, TAXII API Roots and Collections, and the exchange and modeling of threat intelligence.

Cyber Threat Intelligence 30m

CTI Analysis & Tradecraft

Test your ability to apply Cyber Threat Intelligence analytic tradecraft, including evidence evaluation, assumptions, confidence, alternative hypotheses, source assessment, attribution, collection bias, adversary behavior mapping, and structured analytic reasoning.

Cyber Threat Intelligence 25m

Cyber Threat Intelligence Fundamentals

Test your understanding of foundational Cyber Threat Intelligence concepts, terminology, analytical thinking, threat information sharing, indicators, adversary behavior, and structured intelligence standards.

Computer Science 30m

Introduction to Go Programming

A beginner level exam on the fundamentals of the Go programming language.