- The Certified Cybersecurity Analyst exam from Mile2 has 100 multiple-choice questions, runs about 2 hours, and requires 70% to pass.
- Seven official course modules, unweighted here, cover blue team work, forensics, malware, traffic, defense assessment, SIEM and purple teaming.
- The US Exam Combo is USD $550 and includes preparation components plus two attempts, not an exam-only price.
- Renewal runs on a three-year cycle: 60 documented CEUs or the latest exam, plus the applicable fee.
The Exam at a Glance
The Certified Cybersecurity Analyst credential comes from Mile2 and targets defenders: people who monitor, investigate, hunt and report. This page condenses what you need to hold in your head before test day. For the long-form treatment of any item, follow the links to the deeper guides, starting with the C)CSA study guide.
| Item | Fact |
|---|---|
| Certifying body | Mile2 |
| Current title | Certified Cybersecurity Analyst |
| Format | 100 multiple-choice questions |
| Time | Approximately 2 hours |
| Minimum passing score | 70% |
| Delivery | Online through the Mile2 LMS |
| Technical requirements | Current Chrome and reliable internet |
| US Exam Combo | USD $550, with preparation/simulator components and two attempts |
| Renewal | Three-year cycle |
At 100 questions in roughly two hours, you have a little over a minute per item. That is comfortable for recall questions and tight for scenario-based items where you must read a log excerpt, a packet description or an incident narrative before choosing an answer. If you want to gauge the real-world pressure, the C)CSA difficulty guide breaks down where candidates tend to lose time.
The Seven-Module Map
The seven topic areas below are the official course modules. This site uses them as unweighted categories, so do not assume equal or published exam weighting. Treat them as a coverage checklist. The complete domains guide expands each one.
- Blue Team Principles
- Digital Forensics
- Malware Analysis
- Traffic Analysis
- Assessing the Current State of Defense within an Organization
- Leveraging SIEM for Advances Analytics
- Defeating the Red Team with Purple Team Tactics
One quirk worth noting: the summary list of modules spells the sixth entry "Advances Analytics," while a detailed heading in the course material differs. If you see both spellings in your materials, they refer to the same module on SIEM-driven analytics.
Blue Team Principles and Digital Forensics
Domain 1: Blue Team Principles
This module frames the defender's mindset and the work that surrounds detection and response. Expect questions that ask what an analyst should do, in what order, and why.
- The defender's role relative to monitoring, detection and incident handling
- How defensive operations are organized and what an analyst is accountable for
- Baselines, normal-versus-abnormal behavior and why they matter for detection
- The relationship between prevention, detection and response activities
Domain 2: Digital Forensics
Forensics questions reward procedural discipline. The exam is likely to test whether you handle evidence in a defensible way, not just whether you can name tools.
- Evidence preservation and the reasons order of volatility matters
- Chain of custody and documentation habits
- Working from copies and protecting original evidence from alteration
- Where artifacts live on endpoints and what they can reveal about activity
- How forensic findings feed incident response and reporting
Mile2 suggests prior knowledge of security, forensics, incident handling and testing, though no mandatory course, degree or experience-hour requirement was verified. If forensics is new to you, spend extra time here, because later modules assume the vocabulary. The requirements guide covers the suggested background in more detail.
Malware Analysis and Traffic Analysis
Domain 3: Malware Analysis
The analyst-level view: understand what malicious code does and how to observe it safely, rather than reverse engineer at an expert level.
- Static versus dynamic analysis and what each can and cannot tell you
- Safe handling and isolated analysis environments
- Indicators produced by malware: files, registry changes, processes, network callbacks
- Turning analysis results into detection content and defensive action
Domain 4: Traffic Analysis
Packets and flows are where many attacks become visible. Prepare to interpret descriptions of traffic rather than only recite protocol facts.
- Reading captured traffic to spot scanning, beaconing and exfiltration patterns
- Common protocol behavior and what deviations suggest
- Differences between full packet capture and flow-level summaries
- Correlating network observations with host-level evidence
Assessing the Current State of Defense
Domain 5: Assessing the Current State of Defense within an Organization
This module shifts from investigating incidents to evaluating readiness. Questions tend to be judgment-oriented: given an organization's posture, what gap matters most?
- Reviewing existing controls, coverage and visibility gaps
- Identifying what an organization can and cannot currently detect
- Prioritizing weaknesses by risk rather than by novelty
- Communicating findings in terms decision-makers can act on
Candidates from pure technical backgrounds sometimes underweight this module. The wording of answer choices often distinguishes a technically correct action from the one that best improves the organization's overall posture. Read for the goal of the assessment, not just the mechanism.
SIEM Analytics and Purple Team Tactics
Domain 6: Leveraging SIEM for Advances Analytics
The SIEM module covers using centralized logging for detection and investigation beyond basic alerting.
- Log sources, normalization and why consistent data quality drives detection quality
- Correlation rules, use cases and tuning to reduce false positives
- Searching and pivoting across data during an investigation
- Using analytics to find activity that signature-based alerts miss
Domain 7: Defeating the Red Team with Purple Team Tactics
Purple teaming blends offensive emulation with defensive tuning. The core idea is a feedback loop.
- How red team activity informs new detections and control improvements
- Collaborative exercises where attackers and defenders share findings
- Measuring whether detections actually fire against emulated techniques
- Closing gaps and re-testing rather than treating findings as a one-time report
Key Takeaway
The last two modules are where the credential's analyst identity shows most clearly. Know how a detection gets built, tested against simulated attack behavior, and refined. Questions often ask which step comes next in that loop.
Fees, Delivery and Logistics
The exam is delivered online through the Mile2 LMS, not through a verified third-party testing network. You need a current version of Chrome and a reliable internet connection. A dropped connection mid-exam is a real risk, so test your setup beforehand.
On cost, the US Exam Combo is USD $550. That figure is a bundle: it includes preparation/simulator components and two attempts under the general combo policy. It is not a verified exam-only price, so compare carefully before assuming you are paying for the test alone. The certification cost breakdown walks through what is and is not included.
Scheduling details such as testing windows are covered in the exam dates guide. Note that the current public outline is undated and no 2026 exam version has been confirmed, so check the outline you are studying against Mile2's current materials.
Renewal Cycle Facts
| Renewal Element | Detail |
|---|---|
| Cycle length | Three years |
| Route options | 60 documented CEUs over three years OR the latest exam |
| Additional conditions | Applicable fee and professional-policy agreement |
| Known ambiguity | The course PDF uses wording that implies both routes |
Central policy presents CEUs and re-examination as alternatives, but the course PDF wording conflicts and reads as though both are required. Confirm directly with Mile2 which applies to you before you plan three years of continuing education. Keep records of every CEU activity from day one regardless.
Sequencing Your Review
Order matters more than volume. Start with Blue Team Principles and Digital Forensics, since their vocabulary underpins everything after. Move to Malware Analysis and Traffic Analysis as a pair. Then take the defense-assessment module, and finish with SIEM and purple teaming, which synthesize earlier material.
Foundations
- Blue Team Principles and the analyst's role
- Digital Forensics: evidence handling and artifacts
Technical Analysis
- Malware Analysis: static versus dynamic methods
- Traffic Analysis: spotting beaconing and exfiltration
Assessment and Detection
- Assessing the Current State of Defense
- SIEM analytics and correlation use cases
Synthesis and Practice
- Purple Team Tactics and the detect-test-refine loop
- Timed practice sets on the practice test site
Adjust the pacing to your background. A working SOC analyst may compress the first two weeks, while someone new to forensics should expand them. Timed practice matters because of the roughly 2-hour limit; the pass rate discussion explains why published numbers should be treated cautiously, and why you should prepare as though the exam is demanding.
What Is Not Confirmed
A good cheat sheet is honest about its gaps. These items remain unverified and should be checked with Mile2 before you rely on them:
- Whether the exam is open-book
- Whether a calculator is permitted
- Whether the exam is adaptive
- Proctoring rules and requirements
- Accommodation procedures
- Weighted percentages per topic area (the seven modules here are unweighted categories)
For newcomers still orienting on the basics, the explainers on what the certification is and what the acronym stands for are a good starting point.
FAQ
The exam has 100 multiple-choice questions and runs approximately 2 hours. The minimum passing score is 70%.
Mile2 issues it. The exam is delivered online through the Mile2 LMS rather than a verified third-party testing network, and requires current Chrome and a reliable internet connection.
The US Exam Combo includes preparation/simulator components and two attempts under the general combo policy. It should not be read as an exam-only price.
Prior knowledge of security, forensics, incident handling and testing is suggested, but no mandatory Mile2 course, degree, experience-hour or reference requirement has been verified.
The cycle is three years. Central policy offers 60 documented CEUs over that period or the latest exam, plus the applicable fee and a professional-policy agreement. Because the course PDF wording conflicts, confirm the exact requirement with Mile2.