CyberSec First Responder (CFR)
Credential: CyberSec First Responder (CFR)
Credentialing Agency: CertNexus (formerly Logical Operations)
Renewal Period: 3 years
CertNexus, CyberSec First Responder (CFR) is a mid-level certification for security professionals who are the first responders against cyber attacks. Candidates should be able to identify, respond to, protect against, and remediate malicious activities involving computing systems. Additionally, candidates should have the foundational knowledge to deal with a changing threat landscape and will be able to assess risk and vulnerabilities, acquire data, perform analysis, continuously communicate, determine scope, recommend remediation actions, and accurately report results. While there are no formal education or experience prerequisites, the certification is targeted to professionals with three to five years of experience working in a computing environment as part of a CERT/CSIRT/SOC who desire or are required to protect critical information systems before, during, and after an incident which may be a cybersecurity attack.
More information can be found on the certifying agency's website.
CyberSec First Responder (CFR)
MINIMUM REQUIREMENTS
Attainability:
Eligibility Requirements (View Details)
- Credential Prerequisite
- Experience: 3 years recommended
- Education
- Training
- Membership
- Other
- Fee
Note: This credential may have multiple options for a Service member to meet eligibility requirements. Requirements listed here are based on the minimum degree required. To view other options, see the Eligibility tab.
Exam Requirements (View Details)
- Exam
- Written Exam
- Oral Exam
- Practical Exam
- Performance Assessment
Exam Administration (View Details)
- In-person exam
- Remote proctored on-line exam
- Third-party test vendor
RECERTIFICATION SUMMARY
Renewal Period: 3 years
AGENCY CONTACT INFORMATION
CertNexus (formerly Logical Operations)
3535 Winton Place
Rochester, NY 14623
Phone: (800) 326-8724
Email: info@certnexus.com
Other REQUIREMENTS
The CyberSec First Responder (CFR) credential has the following other requirements:
- Candidates must adhere to the CertNexus Candidate Agreement.
Written Exam CFR-210
-
1.0 Threat Landscape (25%)
- 1.1 Compare and contrast various threats and classify threat profiles
- 1.2 Explain the purpose and use of attack tools and techniques
- 1.3 Explain the purpose and use of post exploitation tools and tactics
- 1.4 Explain the purpose and use of social engineering tactics
- 1.5 Given a scenario, perform ongoing threat landscape research and use data to prepare for incidents
-
2.0 Passive Data-Driven Analysis (27%)
- 2.1 Explain the purpose and characteristics of various data sources
- 2.2 Given a scenario, use appropriate tools to analyze logs
- 2.3 Given a scenario, use regular expressions to parse log files and locate meaningful data
-
3.0 Active Asset and Network Analysis (28%)
- 3.1 Given a scenario, use Windows tools to analyze incidents
- 3.2 Given a scenario, use Linux-based tools to analyze incidents
- 3.3 Summarize methods and tools used for malware analysis
- 3.4 Given a scenario, analyze common indicators of potential compromise
-
4.0 Incident Response Lifecycle (20%)
- 4.1 Explain the importance of best practices in preparation for incident response
- 4.2 Given a scenario, execute incident response process
- 4.3 Explain the importance of concepts that are unique to forensic analysis
- 4.4 Explain general mitigation methods and devices
Written Exam CFR-310
-
Threats and Attacks (24%)
- Compare and contrast various threats and classify threat profiles
- Explain the purpose and use of attack methods and techniques
- Explain the purpose and use of post exploitation tools and tactics
- Given a scenario, perform ongoing threat landscape research and use data to prepare for incidents
-
Data Collection and Analysis (23%)
- Explain the purpose and characteristics of various data sources
- Given a scenario, use real-time data analysis to detect anomalies
- Given a scenario, analyze common indicators of potential compromise
- Given a scenario, use appropriate tools to analyze logs
-
Incident Response Methods, Tools, and Techniques (22%)
- Given a scenario, use appropriate containment methods or tools
- Given a scenario, use appropriate asset discovery methods or tools
- Given a scenario, use Windows tools to analyze incidents
- Given a scenario, use Linux-based tools to analyze incidents
-
The Incident Response Process (18%)
- Given a scenario, execute the incident response process
- Explain the importance of best practices in preparation for incident response
- Identify applicable compliance, standards, frameworks, and best practices
- Explain the importance of concepts that are unique to forensic analysis
-
Vulnerability Assessment (13%)
- Identify common areas of vulnerability
- Identify the steps of the vulnerability assessment process
Exam Preparation Resources
There are a number of resources available to help you prepare for the CyberSec First Responder (CFR) examination:
- Best Sources
An additional resource is O'Reilly Learning Safari Books Online, a searchable digital library that provides online access to thousands of books, training videos and conference sessions. See the Educational Resources section on the Related Sites page here on COOL to learn how to get free access.
Testing Information
-
Exam Administration
Credential exams may be administered in-person at a testing site, proctored on-line remotely, or have options for both. If an exam is administered through a test vendor, the third-party test vendor box will be checked. The following test administration options apply to the CyberSec First Responder (CFR) credential where checked:
- In-person exam
- Remote proctored on-line exam
- Third-party test vendor
For more information on the CertNexus (formerly Logical Operations) testing process, visit the agency website.
-
Third-Party Test Vendor Information
Testing for this credential is handled by the following vendor:
Pearson VUE
The test centers are located in the U.S. They also have some test centers on military bases.
To find out more, use the following links on the Pearson VUE website:
- Search for Testing Program
- Learn About Testing for Military Communities
- Agency/Certification Specific Testing Information
- Contact Pearson VUE
RECERTIFICATION
CyberSec First Responder (CFR)
Renewal Period: 3 years
Additional considerations for the CyberSec First Responder (CFR) include:
- While there are no formal education or experience prerequisites, CertNexus strongly recommends that before taking the exam, candidates have the knowledge, skills, and abilities to do the following:
- Assess cybersecurity risk in computing environments within a risk management framework.
- Evaluate an organization’s cybersecurity posture.
- Identify that a cybersecurity incident has occurred.
- Collect cybersecurity intelligence.
- Analyze data collected from security and event logs using both Windows and Linux tools.
- Analyze threats to computing environments.
- Analyze attacks on computing environments.
- Analyze post-attack techniques on computing environments.
- Perform analysis on network assets.
- Investigate cybersecurity incidents.
- Provide remediation and containment suggestions in response to cybersecurity incidents.
- Assess and apply cybersecurity policies and procedures.
- Understand the cybersecurity threat landscape.
- Review vulnerability assessments performed on computing environments.
- Identify cybersecurity compliance, standards, frameworks, and best practices.
- Identify and describe basic concepts of forensics.
- Utilize log sources for continuous monitoring and detection of potential anomalies.
- Prepare for incident response and execute the incident response process when an incident has occurred.
- CertNexus recommends that candidates have between 3 and 5 years of experience working in a computing environment as part of a CERT/CSIRT/SOC with responsibility to protect critical information systems before, during, and after an incident which may be a cybersecurity attack.