Skip to main content
Aegentra
Guide · Updated

Cyber Threat Analyst Certification in Australia: The PECB CCTA Guide

A practical guide to the PECB Certified Cyber Threat Analyst (CCTA) — the 5-day, hands-on threat-hunting and cyber threat analysis certification for security professionals in Australia. This guide covers what the course teaches, the 3-hour exam and its five domains, how proactive hunting complements incident response, real AUD cost, and how to get certified. Written for SOC analysts, incident responders, and blue-team engineers who want to hunt threats before they become breaches.
By Harry Sidhu — ISO 27001 Lead Implementer · Director and Principal Consultant, Aegentra9 min readLast reviewed
Hunting is hypothesis-driven — you form a theory about adversary activity and search the network for it, instead of waiting for an alert to fire.

What is the PECB Certified Cyber Threat Analyst?

The PECB Certified Cyber Threat Analyst (CCTA) is a 5-day, hands-on certification in cyber threat analysis and threat hunting. It gives you the advanced skills to identify, analyse, and mitigate cyber threats before they cause damage — combining threat intelligence, cyber threat and attack frameworks, and threat modelling with practical labs focused on hunting for adversary activity across a network.

The emphasis is proactive, not reactive. Rather than waiting for an alert to fire, you learn to form and validate threat-hunting hypotheses using data-driven approaches, and to run a structured hunt program end to end — prepare, execute, analyse, report, and continually improve. By the end you should be able to search deliberately for threats, design a repeatable hunt program, and write reports that inform risk and response decisions.

APRA CPS 234 expects regulated entities to detect and respond to information-security incidents in a timely way, and the SOCI Act requires critical-infrastructure operators to understand and manage cyber risk to the systems that matter.

Why threat hunting matters in Australia

Australian security teams face a threat environment that no longer rewards a purely reactive posture. Proactive threat hunting complements incident response, and the following considerations can inform whether a recurring hunting capability is appropriate:

  • ASD ACSC threat advisories — the Australian Signals Directorate publishes tactics, techniques, and indicators that hunt teams can turn directly into hypotheses to search for in their own environment.
  • The ASD Essential Eight — mitigation maturity is stronger when paired with active hunting that verifies controls are working and looks for what slipped past them.
  • APRA CPS 234 — regulated entities are expected to detect and respond to information-security incidents in a timely way, with capability matched to its threats and vulnerabilities. Threat hunting can support that capability; this is not a universal requirement for a particular course or hunting programme.
  • The SOCI Act — applicable critical-infrastructure duties depend on the asset and entity. Threat hunting can support risk management, but does not by itself establish compliance or detect every adversary.

Recognised frameworks such as MITRE ATT&CK and the cyber kill chain give hunters a shared language for adversary behaviour, so a hunt in Melbourne maps to the same tactics and techniques a partner in Sydney or an ACSC advisory describes. That common vocabulary is what makes hunting programs auditable and repeatable.

Who should take this course

  • Cybersecurity professionals such as incident responders and SOC analysts moving into proactive hunting
  • IT professionals involved in managing and securing IT infrastructure
  • Security managers and directors responsible for an organisation’s security strategy
  • Penetration testers and ethical hackers wanting insight into the latest threats and defensive techniques
  • Individuals responsible for risk management, compliance, and governance
  • Aspiring cybersecurity professionals building foundational threat-analysis skills

If your day job is containing and eradicating incidents once they fire, CCTA is the natural complement — it teaches you to go looking for the adversary before the alert, using the same ATT&CK language your response playbooks already reference.

Day one sets the frameworks, days two and three run a hunt through prepare, execute, analyse and report, day four turns it into a maturing program, and the exam is sat on day five.

What you learn — the 5-day agenda

The course is four days of training plus the certification exam on day five:

Day 1Cyber threat analysis and threat-hunting frameworks

Cyber threats overview, cyber threat intelligence, cyber threat and attack frameworks (MITRE ATT&CK, the cyber kill chain), and threat modelling — the conceptual foundation for everything that follows.

Day 2Prepare and execute a threat-hunting program

Fundamentals of incident response and the management plan, the Prepare stage (data, tooling, and hypotheses), and the Execute stage — running the hunt itself.

Day 3Analyse and knowledge phases

The Analyse stage and Knowledge stage of the hunt framework, threat-hunting deliverables, and cyber threat-hunt reporting that stakeholders can act on.

Day 4Culture, monitoring, and continual improvement

Threat-hunting metrics, awareness and training programs, monitoring and measurement, and continual improvement — turning one-off hunts into a maturing program.

Day 5Certification exam

The 3-hour PECB exam across five competency domains, remotely proctored (see below).

The learning outcomes are practical: identify types of cyber threats and analyse their impact, establish robust incident response plans, use advanced hunting techniques and tools to search proactively, formulate and validate hunt hypotheses with data-driven approaches, and design, implement, and continually improve a hunt program.

Current examination requirements

Open-book, multiple-choice. Duration: 3 hours. 80 multiple-choice questions in the current English PECB examination record. Passing requirements: 70%. Check the current PECB examination record and assigned examination before booking.

  • Fundamentals of cyber threat analysis and threat hunting
  • Preparation and execution of threat-hunting programs and incident-management plans
  • Analysis and knowledge phases of threat-hunting frameworks
  • Operational aspects of security controls, incident and change management
  • Building a cybersecurity culture, monitoring, and continual improvement

View the current course and booking options

Cost, inclusions and access

Self-Study: A$ 1,165.00 excluding GST (A$ 1,281.50 including Australian GST). Published inclusions (subject to the credential and retake clarification immediately below): 400+ pages of explanatory information, examples, and best practices; Hands-on threat-hunting labs, exercises, and quizzes; 12 months access via myPECB; Official PECB CCTA exam voucher; 3-hour exam, remotely proctored; Two attempts (initial + one free resit within 12 months); PECB digital certificate on pass; 31 CPD credits on completion; Threat-hunting hypotheses and hunt-program design; Aegentra Academy support inbox. Clarification: references to a credential or certificate on pass do not mean automatic award. The eligible PECB credential requires an application and PECB approval, including applicable experience and ethics requirements. PECB’s partner-course policy sets a 12-month examination and included-retake cycle from purchase for Self-Study and eLearning, or from course completion for instructor-led training. A failed attempt does not restart that cycle. The first retake requires at least 15 days after the unsuccessful examination; booking rules and the recorded myPECB deadline also apply. A retained inclusion referring to the initial examination date does not extend or restart this policy cycle. Australian GST follows the billing address. Check the course page for the full inclusions and current booking options.

This course publishes 12 months of material access. Course-material access, examination and retake deadlines, and any certificate-application deadline are separate. Confirm the material-access start date in your booking confirmation and check the deadlines recorded in myPECB before scheduling your examination. PECB’s partner-course policy sets a 12-month examination and included-retake cycle from purchase for Self-Study and eLearning, or from course completion for instructor-led training. A failed attempt does not restart that cycle. The first retake requires at least 15 days after the unsuccessful examination; booking rules and the recorded myPECB deadline also apply.

View the current course and booking options

Credential requirements and how to enrol

Before attending, understand the core principles and concepts of cybersecurity. The full credential has a separate professional-experience requirement assessed by PECB.

On passing you can apply for the PECB Certified Cyber Threat Analyst credential — requires two years of threat-hunting, threat-analysis, and cybersecurity experience, and signing the PECB Code of Ethics. Meets the PECB Examination and Certification Program (ECP) requirements. Passing the examination and receiving a credential are separate: PECB must approve the application. Maintenance depends on the credential awarded; Provisional credentials and Foundation certificates are exempt from CPD and maintenance fees. Check the current PECB policy for other credentials.

View the current course and booking options

Primary references and applicability

These sources explain the requirements and scope distinctions discussed above. Check their applicability to the organisation or credential.

FAQs

What is the PECB Certified Cyber Threat Analyst (CCTA)?

CCTA is a 5-day, hands-on cyber threat analysis and threat-hunting certification from PECB. It combines threat intelligence, cyber threat and attack frameworks, and threat modelling with practical labs, so you can proactively hunt for threats across a network, run a structured hunt program end to end — prepare, execute, analyse, report, and continually improve — and report findings that inform risk and response decisions.

What does the CCTA exam involve?

Open-book, multiple-choice. Duration: 3 hours. 80 multiple-choice questions in the current English PECB examination record. Passing requirements: 70%. Check the current PECB examination record and assigned examination before booking.

How is Cyber Threat Analyst different from Incident Responder?

Cyber Threat Analyst is proactive — it focuses on threat intelligence and hunting for threats before they trigger an incident. Certified Incident Responder is reactive — managing and remediating incidents once they occur. The two are complementary blue-team disciplines, and a mature SOC needs both: hunters who surface adversary activity early, and responders who contain and eradicate it.

Do I need prior experience to take the course?

Before attending, understand the core principles and concepts of cybersecurity. The full credential has a separate professional-experience requirement assessed by PECB.

How much does the Cyber Threat Analyst course cost in Australia?

Self-Study: A$ 1,165.00 excluding GST (A$ 1,281.50 including Australian GST). Published inclusions (subject to the credential and retake clarification immediately below): 400+ pages of explanatory information, examples, and best practices; Hands-on threat-hunting labs, exercises, and quizzes; 12 months access via myPECB; Official PECB CCTA exam voucher; 3-hour exam, remotely proctored; Two attempts (initial + one free resit within 12 months); PECB digital certificate on pass; 31 CPD credits on completion; Threat-hunting hypotheses and hunt-program design; Aegentra Academy support inbox. Clarification: references to a credential or certificate on pass do not mean automatic award. The eligible PECB credential requires an application and PECB approval, including applicable experience and ethics requirements. PECB’s partner-course policy sets a 12-month examination and included-retake cycle from purchase for Self-Study and eLearning, or from course completion for instructor-led training. A failed attempt does not restart that cycle. The first retake requires at least 15 days after the unsuccessful examination; booking rules and the recorded myPECB deadline also apply. A retained inclusion referring to the initial examination date does not extend or restart this policy cycle. Australian GST follows the billing address. Check the course page for the full inclusions and current booking options.

Which frameworks does the course cover?

The course grounds threat hunting in recognised cyber threat and attack frameworks — including MITRE ATT&CK and the cyber kill chain — alongside threat modelling and cyber threat intelligence. These give you a shared language for describing adversary tactics, techniques, and procedures, and a repeatable structure for forming and validating hunt hypotheses.

How long is the course and how is it delivered?

It is a 5-day course equivalent — four days of training content across threat-hunting frameworks, hunt execution, analysis and reporting, followed by the certification exam on day five. The published option is self-paced online through myPECB. Current online training formats and booking arrangements are listed on the course page; an enquiry does not confirm live-training availability.

What CPD credits do I earn, and how many pages are the materials?

Participants who complete the training receive an attestation worth 31 CPD (Continuing Professional Development) credits, and the course materials run to 400+ pages of explanatory information, examples, and best practices, plus hands-on labs, exercises, and quizzes accessed through myPECB for 12 months.

PECB Certified Cyber Threat Analyst

Ready to hunt threats before they become breaches?

The 5-day PECB Certified Cyber Threat Analyst course — hands-on threat-hunting labs, a 3-hour exam across five domains, and the official exam voucher included. Study online; check the course page for current formats and booking arrangements.