Login to profile

CREST Certified Network Intrusion Analyst

 

The Certified Network Intrusion Analyst (CCNIA) examination tests candidates’ knowledge of analysing network traffic and log files for evidence of potential compromise and analysing the potential underlying causes and infection vectors.

The examination is a rigorous assessment of the candidate’s ability to assess a given network for indications of malicious activity including remote control and data ex-filtration.

The exam includes:

  • Data Sources
  • Statistical Analysis
  • Beaconing Systems
  • Encrypted Communications
  • Network Traffic Analysis
  • Networking Protocols
  • Covert Channel Identification
  • Log Analysis

 Examination format
The format is the same as for all other CREST certifications. The candidate will be expected to possess not only the technical ability to find security weaknesses and vulnerabilities, but also the skills to ensure findings are presented in a clear, concise and understandable manner. The examination consists of three tasks:

  • A multiple choice technical examination
  • A long form essay style written paper, testing both technical ability and presentation ability
  • A hands-on practical examination

To pass the exam, the candidate must pass all three sections.

You can download the following documents from the links below:

Syllabus for the Certified Network Intrusion Analyst examination
Notes for Candidates to aid examination preparation

Cost
For costs and availability please refer to individual country booking. The examination is currently delivered at CREST examination centres.

Training Providers
In our mission to support individuals in their examination preparation and professional growth, we collaborate with training providers. Search for a Training Provider using our Training Provider Search.

Recommended Preparation Material
The CREST Assessors panel regularly identifies common themes and consolidates common questions and answers from candidates and from the industry in relation to the CREST certification examinations. Candidates are advised to familiarise themselves with these, although they are free to disregard them if they wish.

CREST recommends that candidates familiarise themselves with the content in our FAQS which has been created specifically for those attempting a practical examination.

The following material and media have been cited as helpful preparation for this examination by previous candidates:

Reading Material:
Practical Malware Analysis
Network Fundamentals:  CCNA Exploration Companion Guide

Websites:
http://www.unixwiz.net/techtips/sql-injection.html
http://opensecuritytraining.info/CISSP-5-C.html
http://overapi.com/

How to Book
This exam is only available in the UK, please complete the booking form below. If you have any problems, please email [email protected]

Examination booking form

Useful Information for Candidates
CREST’s Policy for Candidates requiring special arrangements including additional time to accommodate a medical condition (including examinations delivered via Pearson VUE)
Terms and Conditions for CREST Examinations (includes hard disk drive wiping policy)