Skip to main content
Cybersecurity ops

CCOA: Certified Cybersecurity Operations Analyst

The ISACA hands-on credential for SOC analysts and cyber-defence operators. Five domains covering monitoring, incident response, threat hunting and threat intelligence. Practitioner-level, exam mixes scenarios with multiple-choice.

ISACAPractitioner3 daysLiveSelf-pacedIn-house
  • Practitioner-led, taught by a working CISO
  • Exam & certificate included
Christophe Mazzola

Taught by

Christophe Mazzola

Practicing CISO · Founder of Cyber Academy

See full profile →

Right fit if you are.

  • SOC tier-1 analysts levelling up to tier-2.
  • Incident-response practitioners adding a recognised credential.
  • Threat hunters formalising their methodology.
  • Cyber engineers transitioning into a defence-operations role.

NOT for. When to skip it.

We'd rather you keep your money than buy the wrong path.

  • GRC practitioners without an ops background. CISA or CISM fits better.
  • Aspiring CISOs. Look at CISM.
  • Beginners without any hands-on defensive security experience.

What you'll be able to do

  • 1Operate a security-monitoring stack (SIEM, EDR, network telemetry) at SOC tier-2 level.
  • 2Run a full incident-response cycle from triage to lessons learned, with the documentation auditors expect.
  • 3Conduct hypothesis-driven threat hunts using MITRE ATT&CK as the navigation grid.
  • 4Consume and produce actionable threat intelligence in standard formats (STIX/TAXII).
  • 5Bridge the cyber-ops floor to the broader GRC programme, incidents into risk, controls into telemetry.

Day by day

Day 1Technology Essentials and Cybersecurity Principles and Risks
  • Domain 1: Technology Essentials

    Coverage follows the current official ISACA exam-content outline.

  • Domain 2: Cybersecurity Principles and Risks

    Coverage follows the current official ISACA exam-content outline.

By end of day

  • Apply Technology Essentials concepts to practical and exam-style scenarios.
  • Apply Cybersecurity Principles and Risks concepts to practical and exam-style scenarios.
Day 2Adversarial Tactics, Techniques and Procedures and Incident Detection and Response
  • Domain 3: Adversarial Tactics, Techniques and Procedures

    Coverage follows the current official ISACA exam-content outline.

  • Domain 4: Incident Detection and Response

    Coverage follows the current official ISACA exam-content outline.

By end of day

  • Apply Adversarial Tactics, Techniques and Procedures concepts to practical and exam-style scenarios.
  • Apply Incident Detection and Response concepts to practical and exam-style scenarios.
Day 3Securing Assets
  • Domain 5: Securing Assets

    Coverage follows the current official ISACA exam-content outline.

By end of day

  • Apply Securing Assets concepts to practical and exam-style scenarios.

Upcoming public sessions

Open-enrolment cohorts. Pick a date and book your seat. Want a private cohort for your team instead? Request an in-house quote.

No confirmed live cohort right now. You can still:

Everything inside this certification

The detail behind the headline. Read at your own pace. Each section answers a buyer question we get on discovery calls.

This preparation course covers the current CCOA: Certified Cybersecurity Operations Analyst exam-content outline: Technology Essentials, Cybersecurity Principles and Risks, Adversarial Tactics, Techniques and Procedures, Incident Detection and Response, Securing Assets. It connects the official domains to practical governance, risk, audit, privacy, security, and operations scenarios as applicable.

Training, passing the exam, and satisfying the current ISACA credential requirements are separate steps. Check the official ISACA page before registering.

Official credential and exam-content source: ISACA

Buyers always ask

How does CCOA differ from CISSP-style credentials?+

CCOA is narrower and more operational: it focuses specifically on cyber-defence operations (SOC, IR, threat hunting, threat intel). CISSP is broader (eight domains spanning architecture, engineering, identity, asset security…) and management-leaning. CCOA fits a hands-on operator; CISSP fits a security architect or generalist.

How long is the CCOA exam?+

Three hours, mix of scenario-based items and multiple-choice questions. Computer-based at a PSI testing centre. Same scoring scale as the rest of the ISACA portfolio.

Ready to get certified?

Taught by a practicing CISO. Prices and exam terms shown up front.