Selkobase certification index

OffSec Defense Analyst: Complete Certification, Exam and Preparation Guide

Discover what OSDA tests, what it takes, and whether it fits your goals

Validates hands-on security operations skills for detecting, analyzing, contextualizing, and documenting attacker activity using endpoint and SIEM telemetry. Examine the OSDA assessment, preparation demands, pricing, prerequisites, renewal expectations, and skills it can demonstrate. Compare the credential with adjacent options from OffSec before deciding whether it belongs in your professional development plan.

View the OSDA certificationOffSecSearch Certifications by Filters

Credential overview

OffSec Defense Analyst: What the certification covers and who it suits

OffSec Defense Analyst validates hands-on security operations skills for detecting, analyzing, contextualizing, and documenting attacker activity using endpoint and SIEM telemetry.

OffSec Defense Analyst validates hands-on security operations skills using endpoint and SIEM telemetry. Candidates learn to detect, analyze, contextualize, and document attacker activity through an evidence-based workflow that supports clearer operational decisions.

SOC analystThreat detectionSIEMEndpoint securityOffSec

Who should take it

Choose OSDA if you want to work in a SOC or strengthen your detection-and-analysis ability. It is a good fit for technically curious candidates who prefer investigating suspicious behavior and communicating what it means over purely offensive security work.

Best for

OSDA is suited to SOC analysts, security analysts, incident-response trainees, detection engineers, IT professionals moving into blue-team work, and security consultants. It is especially relevant for candidates who enjoy evidence-led investigation and want practical experience beyond a high-level overview of security operations.

Why it matters

OSDA can demonstrate a practical focus on security operations and detection analysis for candidates entering or advancing in blue-team roles. It is valuable when paired with lab investigations, clear writing samples, and an ability to explain how evidence leads to a containment, escalation, or tuning decision.

Requirements

Candidates should understand basic networking, operating systems, common attacker behavior, logs, and security operations concepts. Familiarity with endpoint or SIEM data is helpful but not mandatory. Preparation should build a habit of documenting hypotheses, collecting relevant evidence, and avoiding conclusions that the available telemetry cannot support.

Best fit

Who OffSec Defense Analyst is best suited for

OSDA is suited to SOC analysts, security analysts, incident-response trainees, detection engineers, IT professionals moving into blue-team work, and security consultants. It is especially relevant for candidates who enjoy evidence-led investigation and want practical experience beyond a high-level overview of security operations.

Who should take it

Choose OSDA if you want to work in a SOC or strengthen your detection-and-analysis ability. It is a good fit for technically curious candidates who prefer investigating suspicious behavior and communicating what it means over purely offensive security work.

Best for

OSDA is suited to SOC analysts, security analysts, incident-response trainees, detection engineers, IT professionals moving into blue-team work, and security consultants. It is especially relevant for candidates who enjoy evidence-led investigation and want practical experience beyond a high-level overview of security operations.

Career value

Career value of OffSec Defense Analyst

OSDA supports SOC analyst, cybersecurity analyst, detection analyst, junior incident responder, threat-monitoring, and security consulting roles. It can strengthen a practical blue-team profile, while real investigation experience and the ability to communicate concisely remain important.

OSDA can demonstrate a practical focus on security operations and detection analysis for candidates entering or advancing in blue-team roles. It is valuable when paired with lab investigations, clear writing samples, and an ability to explain how evidence leads to a containment, escalation, or tuning decision.

Learning outcomes

OffSec Defense Analyst: Skills and learning outcomes the certification is designed to validate

OffSec Defense Analyst is intended to provide evidence of specific knowledge and professional capability. Translate each objective into something you should be able to explain, choose, configure, analyse, or troubleshoot, then verify that your practice demonstrates the skill rather than simple recognition.

  • Interpret endpoint and SIEM telemetry during an investigation
  • Detect and contextualize suspicious attacker behavior
  • Develop evidence-led hypotheses and escalation decisions
  • Document findings with clarity and appropriate confidence
  • Use analysis outcomes to improve defensive operations

Tags and keywords

Certification tags and search topics

SOC analystThreat detectionSIEMEndpoint securityOffSecOffSec OSDAOffSec Defense AnalystSOC analyst certificationSIEM and endpoint analysisthreat detection traininghands on blue team

Reference

Quick facts

Provider
OffSec
Code
OSDA
Level
Associate
Credential type
Professional certification
Active exams
1
Known price
$1,749
Study time
180-320h
Last verified
Sep 8, 2026
Official page

Provider

OffSec

Exam details

OffSec Defense Analyst: Exam structure and assessed capability

A useful OffSec Defense Analyst exam plan starts with the official objectives and format. Identify heavily tested themes, note where applied reasoning matters, and use practice work to expose gaps that passive reading can easily hide.

SOC-200

OSDA certification exam

Proctored defensive investigation across ten simulated incident phases

Official exam
Type
Practical
Delivery
Online
Duration
1425 min

Exam sections

01

OSDA

OSDA certification exam examines how candidates understand and apply osda within the wider credential scope. This area connects core concepts to the decisions, dependencies, and consequences practitioners encounter when carrying out the work described by validates hands-on security operations skills for detecting, analyzing, contextualizing, and documenting attacker activity using endpoint and SIEM telemetry.

Question notes

Expect this topic to appear through scenario interpretation, objective questions, or practical tasks consistent with the overall OSDA certification exam format. No separate question count or timing is assigned unless the provider publishes one.

Preparation tips

Build a small practice scenario around osda and complete it without relying on step-by-step prompts. Afterwards, explain why each decision was appropriate and identify the signal that would have changed your approach.

02

SOC

This area concentrates on soc as it appears in realistic tasks and scenarios. Candidates need to recognize the relevant inputs, choose a defensible approach, and understand how the result supports validates hands-on security operations skills for detecting, analyzing, contextualizing, and documenting attacker activity using endpoint and SIEM telemetry.

Question notes

Candidates may encounter soc through comparisons, troubleshooting prompts, configuration choices, analysis, or applied exercises. Exact distribution can change with the active exam form.

Preparation tips

Practise explaining soc to a technical peer without reading definitions. Then validate the explanation by completing representative tasks and checking whether your result satisfies the intended objective.

03

SOC Analyst

SOC Analyst forms a distinct part of the capability assessed in OSDA certification exam. The section brings together terminology, working methods, common constraints, and the judgment needed to deliver validates hands-on security operations skills for detecting, analyzing, contextualizing, and documenting attacker activity using endpoint and SIEM telemetry.

Question notes

Expect this topic to appear through scenario interpretation, objective questions, or practical tasks consistent with the overall OSDA certification exam format. No separate question count or timing is assigned unless the provider publishes one.

Preparation tips

Review a realistic artifact connected to soc analyst—such as a configuration, report, backlog, model, log set, or design—and identify both correct practice and subtle weaknesses that an assessment could probe.

04

Blue Team

Questions or tasks in this area explore blue team from both conceptual and operational perspectives. Strong performance depends on connecting the topic to the broader responsibility of validates hands-on security operations skills for detecting, analyzing, contextualizing, and documenting attacker activity using endpoint and SIEM telemetry.

Question notes

Candidates may encounter blue team through comparisons, troubleshooting prompts, configuration choices, analysis, or applied exercises. Exact distribution can change with the active exam form.

Preparation tips

Use a lab, case study, or worked example to connect blue team to observable outcomes. Deliberately introduce one incorrect assumption, diagnose its effect, and document the correction in your own words.

Study effort

OffSec Defense Analyst: Preparation strategy and expected study effort

Effective OffSec Defense Analyst preparation moves from scope review to active practice. Learn the core concepts, apply them in realistic tasks, test recall and judgment, and reserve enough time to close gaps rather than cramming near the exam date.

Study time

180-320h

Difficulty

Recommended experience

12 months

Practice exam useful
Hands-on lab useful

Exam cost

OffSec Defense Analyst: Exam price and the full cost of earning the certification

Use the structured fee rows for the latest known amount and compare region, tax, voucher, or membership notes before registering.

$1,749

United States

Standard priceTax may vary

Prerequisites

What to know before starting OffSec Defense Analyst

Candidates should understand basic networking, operating systems, common attacker behavior, logs, and security operations concepts. Familiarity with endpoint or SIEM data is helpful but not mandatory. Preparation should build a habit of documenting hypotheses, collecting relevant evidence, and avoiding conclusions that the available telemetry cannot support.

Career fit

Roles and skills connected to this certification

Explore the roles and skills most directly connected to this certification, then use those paths to compare adjacent credentials.

RoleSecurity Operations Analyst

Security operations analysts monitor, triage, investigate, and respond to security alerts and incidents in defensive environments, playing a key role in protecting organizational assets.

44 certificationsExplore
RoleCybersecurity Analyst

Monitors, investigates, and supports the protection of systems, networks, accounts, and security events against cyber threats.

32 certificationsExplore
RoleSIEM Engineer

Designs, implements, tunes, and manages Security Information and Event Management (SIEM) platforms to facilitate real-time security monitoring and incident response.

26 certificationsExplore
RoleSecurity Analyst

Security analysts investigate threats, analyze security alerts and risk signals, and support defensive monitoring and control validation activities.

89 certificationsExplore
SkillSOC Analysis

SOC analysis is the ability to triage, investigate, document, and escalate security signals so a security operations center can respond effectively to real risk.

5 certificationsExplore
SkillInformation Security

Implementing measures to protect digital assets, systems, networks, and sensitive information from unauthorized access, use, disclosure, disruption, modification, or destruction.

104 certificationsExplore
SkillSecurity Engineering

Implementing and validating technical security controls, systems, platforms, and processes to protect information assets.

108 certificationsExplore
SkillIncident Triage

Incident Triage focuses on rapidly classifying and prioritizing incoming issues to ensure that appropriate teams and actions are quickly engaged for resolution.

19 certificationsExplore

Related areas

Related domains and industries

Use these subject and industry paths to understand where this credential fits inside the broader certification index.

Related certifications

Other OffSec certifications to compare

Compare other credentials from OffSec to understand nearby levels, specialties, and alternative certification paths.

OffSec

Professional certification
Featured

OffSec Certified Professional

Validates practical penetration testing through network enumeration, exploitation, privilege escalation, Active Directory attacks, and professional reporting. Explore the exam format, costs, study considerations, prerequisites, renewal expectations, outcomes, and related credentials to judge whether OSCP / OSCP+ matches your experience and intended direction.

Study time
250-450h
Difficulty
Level
Professional

OffSec

Professional certification
Featured

OffSec Experienced Penetration Tester

Validates advanced penetration testing and red-team tradecraft for breaching mature defenses, evading controls, moving laterally, and compromising enterprise environments. Explore the exam format, costs, study considerations, prerequisites, renewal expectations, outcomes, and related credentials to judge whether OSEP matches your experience and intended direction.

Study time
280-500h
Difficulty
Level
Expert

OffSec

Professional certification
Featured

OffSec Exploit Developer

Validates Windows user-mode exploit development, reverse engineering, custom shellcode, and bypassing modern exploit mitigations. Explore the exam format, costs, study considerations, prerequisites, renewal expectations, outcomes, and related credentials to judge whether OSED matches your experience and intended direction.

Study time
300-550h
Difficulty
Level
Expert

OffSec

Professional certification
Featured

OffSec Web Expert

Validates advanced white-box web application security through source-code review, complex vulnerability chains, custom exploit development, and rigorous reporting. Explore the exam format, costs, study considerations, prerequisites, renewal expectations, outcomes, and related credentials to judge whether OSWE matches your experience and intended direction.

Study time
280-500h
Difficulty
Level
Expert

OffSec

Professional certification

Kali Linux Certified Professional

Validates practical knowledge of Kali Linux installation, configuration, package management, command-line operation, security tools, troubleshooting, and customization. Explore the exam format, costs, study considerations, prerequisites, renewal expectations, outcomes, and related credentials to judge whether KLCP matches your experience and intended direction.

Study time
50-100h
Difficulty
Level
Foundational

OffSec

Professional certification

OffSec AI Red Teamer

Validates practical red teaming of AI-enabled systems, including generative AI applications, agents, retrieval pipelines, model infrastructure, and cloud-connected attack surfaces. Explore the exam format, costs, study considerations, prerequisites, renewal expectations, outcomes, and related credentials to judge whether OSAI / OSAI+ matches your experience and intended direction.

Study time
120-240h
Difficulty
Level
Expert
View all provider certifications

Find the path that fits your goals across the OffSec certification catalog

Continue into individual OffSec certifications to compare what each credential covers, how candidates are assessed, and which professional goals it may support. Check the complete credential details before choosing where to invest your preparation time.