CSA logo
Focused certification exam prep
Start practice

CSA Certification

TL;DR
  • CSA here means EC-Council's Certified SOC Analyst v2, exam 312-39: 100 multiple-choice questions, three hours, 70% to pass.
  • Incident Detection and Triage plus Incident Response are 25% each, so half the blueprint rests on two domains.
  • The remote-proctored voucher costs USD 450; the self-study route adds a separate nonrefundable USD 100 application fee.
  • Self-study applicants need one year of verified network-administration or security experience and a verifier.

What the Certified SOC Analyst Credential Actually Is

The Certified SOC Analyst credential is issued by EC-Council and is aimed at people who work, or want to work, inside a security operations center. The current version is CSA v2, tested through exam 312-39. Because "CSA" is an acronym shared by several unrelated credentials, it is worth being explicit: this article covers only the EC-Council Certified SOC Analyst and nothing else that happens to share those letters. If you are still orienting yourself, our explainers on what CSA certification is and what CSA stands for cover the naming question in more depth.

The credential sits at the entry-to-intermediate end of the SOC career ladder. Its blueprint is built around the daily work of a tier-one and tier-two analyst: reading logs, tuning SIEM detections, triaging alerts, hunting for threats proactively, and executing incident response playbooks. Version 2 also reflects how SOC work has shifted, with explicit coverage of AI-generated detection rules and cloud SOC environments across Azure, AWS and GCP.

Version warning: Older study material describes a six-domain v1 structure, and some third-party sites advertise a four-domain split or a two-hour exam. None of those describe the verified v2 scope. The official blueprint lists eight domains and a three-hour exam, so check any resource against the issuer's documents before you trust it.

Exam Format: 100 Questions, Three Hours, 70%

The exam is a multiple-choice test of 100 questions with a three-hour time limit and a 70% passing score. That works out to a minimum of 70 correct answers. Three hours for 100 questions gives you roughly 108 seconds per question on average, which is generous for recall items but tight if you let scenario questions about log excerpts or alert chains eat several minutes each.

Two format points trip people up:

  • The three-day training length is not the exam timer. EC-Council's training description refers to the duration of the course. The exam itself is a single three-hour sitting.
  • The exam is not a hands-on lab. The official training includes labs, but the certification exam is a multiple-choice assessment. You will be reasoning about scenarios on paper, not operating a SIEM live.

The exam is delivered through ECC Exam Centre / the EC-Council Exam Portal, and the standard voucher uses remote proctoring, so you test from your own location under supervision rather than traveling to a test center. For a full breakdown of how the threshold works, see our page on the CSA passing score, and for an honest read on difficulty, how hard the CSA exam is. We do not quote a certification-wide pass rate, because no verified one is published; the CSA pass rate discussion explains what can and cannot be said.

Two Routes to Eligibility

EC-Council gates this exam. You cannot simply buy a voucher and sit down; you must qualify through one of two routes.

Route 1: Official training

If you complete EC-Council's official training, or make a qualifying purchase of official courseware, you satisfy the eligibility requirement through that path. The official-training fees already include the USD 100 application charge, so you do not pay it a second time.

Route 2: Self-study with experience

If you prefer to prepare on your own, you apply through the self-study route. That requires:

  • At least one year of verified network-administration or security experience.
  • A verifier, meaning an employer, supervisor or department contact who can confirm that experience.
  • Payment of the USD 100 nonrefundable eligibility-application fee.

Once your application is approved, you have a three-month window to purchase the exam voucher. Miss that window and you risk having to reapply, so do not file the application until you are close to ready.

Training page vs. certification portal: The training page's FAQ can give the impression that official training is mandatory for everyone. The certification portal's CSA-specific eligibility section is the controlling source, and it explicitly provides the self-study path. When the two disagree, follow the portal.

Candidates who are minors face additional requirements, including parental-consent and educational-institution documentation, set out on the portal. The complete walkthrough lives in our guide to CSA requirements and how to qualify.

Sorting Out the Fees

Candidates frequently confuse three different charges. They are separate line items serving different purposes:

ItemAmountWhat it is
CSAv2 Exam Voucher (RPS)USD 450The exam attempt itself, remote proctored; non-transferable and valid for one year
Self-study eligibility applicationUSD 100Nonrefundable; applies only to the self-study route
eCoursewareUSD 250Study content only; it is not an exam voucher
Annual continuing-education feeUSD 80USD 240 across the three-year cycle; does not replace the CPE requirement

A self-study candidate therefore budgets the USD 100 application plus the USD 450 voucher, with any optional study materials on top. A candidate on the training route pays for the training bundle, which includes the application charge, and still needs to account for the voucher unless the bundle explicitly includes it. Always read the bundle contents before assuming. Our CSA certification cost breakdown goes line by line, and scheduling considerations are in CSA exam dates and scheduling.

The Eight Weighted Domains

The official v2 blueprint is titled "Certified SOC Analyst (CSA) v2 Exam Blueprint" for exam 312-39. It lists eight domains whose weights total 100%. These are the exam's official weighted objectives, so they should drive how you allocate study hours.

DomainWeight
1. Security Operations and Management5%
2. Understanding Cyber Threats, IoCs, and Attack Methodology8%
3. Log Management15%
4. Incident Detection and Triage25%
5. Proactive Threat Detection12%
6. Incident Response25%
7. Forensics Investigation and Malware Analysis5%
8. SOC for Cloud Environments5%

Notice the shape of the distribution. Domains 4 and 6 together carry 50%. Add Log Management at 15% and Proactive Threat Detection at 12% and you have 77% of the exam in four domains. The remaining four domains share 23%. A candidate who is excellent at triage and response but neglects everything else can still stumble, but a candidate who spreads effort evenly across all eight domains is misallocating time. For a domain-by-domain treatment, see our complete guide to all eight CSA content areas.

Where the Marks Are: Triage and Response

Domain 4: Incident Detection and Triage (25%)

This domain is about turning a flood of alerts into a prioritized, defensible decision. Expect scenario questions where you are handed alert details, log fragments or enrichment data and asked what the analyst should conclude or do next.

  • Distinguishing true positives, false positives and benign true positives, and knowing what evidence supports each call.
  • Alert prioritization using asset criticality, user context, threat intelligence and the stage of the attack.
  • SIEM use cases: what a detection is meant to catch, what data sources it needs, and why it might misfire.
  • AI-assisted detection content in v2, including judging whether an AI-generated rule is sound, over-broad or missing a condition.
  • Knowing when to escalate versus close, and what to document either way.

A useful original scenario for practice: a SIEM raises a medium-severity alert for repeated failed logons against a service account, followed by one success from an unfamiliar internal host, then a burst of file-share enumeration. A strong triage answer links these into a single narrative (credential guessing, a probable successful compromise, then discovery), raises priority because the account has broad access, and escalates with the timeline attached. A weak answer evaluates each alert in isolation and closes the first as noise. Questions in this domain reward the analyst who correlates.

Domain 6: Incident Response (25%)

Once an incident is confirmed, the exam tests whether you know the sequence of actions and the reasoning behind them.

  • The incident response lifecycle and where each activity belongs: preparation, identification, containment, eradication, recovery and lessons learned.
  • Playbooks and runbooks: why a SOC predefines steps for common incident types and how analysts follow and adapt them.
  • Containment choices, such as isolating a host versus blocking an indicator, and the trade-offs between speed and preserving evidence.
  • Communication and escalation: who is told what, and when, during an active incident.
  • Post-incident review and feeding findings back into detections.

An original scenario: ransomware-style encryption is spreading across a file server. The tempting answer is to start recovery immediately. The exam-style answer recognizes that containment comes first, evidence should be preserved before wiping anything, and the playbook dictates escalation. Questions in this domain often hinge on ordering, so rehearse the lifecycle until the sequence is automatic. Our CSA study guide includes a structured way to drill these two domains.

Key Takeaway

Because Domains 4 and 6 are worth half the exam, build your own mini-scenarios for them: take a log excerpt, write down the triage decision and your reasoning, then write the containment steps in order. Practicing the reasoning, not memorizing definitions, is what the weighting rewards.

The Supporting Domains

Log Management (15%)

The third-largest domain deserves real attention. The blueprint-supported material covers logs from Windows, Linux and Mac systems as well as network devices and applications. You should be able to recognize what a log source records, which events matter for security (authentication, process creation, privilege changes, firewall actions), and how logs are collected, normalized, retained and correlated in a SIEM. Practice reading raw entries and stating what happened, since interpreting log excerpts is a recurring question style. See our log-focused material in the CSA cheat sheet for quick-reference event categories.

Proactive Threat Detection (12%)

This domain moves the analyst from reactive to proactive: threat intelligence consumption, indicator handling, and threat hunting. Know the difference between hunting driven by a hypothesis and alert-driven investigation, how intelligence feeds translate into detections, and how hunting findings should improve monitoring afterward.

Understanding Cyber Threats, IoCs, and Attack Methodology (8%)

Here the focus is attacker behavior: kill-chain style thinking, tactics and techniques, and indicators of compromise versus indicators of attack. Questions typically ask you to map an observed behavior to a stage of an attack or to identify which indicator type you are looking at.

The three 5% domains

Security Operations and Management covers SOC operations and maturity: roles, tiers, processes and metrics. Forensics Investigation and Malware Analysis covers evidence handling and introductory malware analysis concepts. SOC for Cloud Environments covers monitoring in Azure, AWS and GCP. At 5% each they are small individually but together equal 15% of the exam, which is the same as Log Management alone. Skim them rather than skip them; a handful of easy marks here can offset a hard scenario elsewhere.

Scope reminder: Topics like SIEM use cases, AI-generated rules, threat hunting and cloud SOC environments are study examples that live inside the eight published domains. They are not additional weighted domains, so study them in the context of the domain that owns them.

Sequencing Your Preparation

Generic study advice matters less than putting the right domains in the right order. A reasonable sequence for a CSA candidate follows how the knowledge builds on itself, with the heaviest domains getting the most repetition:

Week 1

Foundations

  • Security Operations and Management and attack methodology/IoCs, so the vocabulary is settled.
  • Skim the cloud SOC domain for orientation.
Week 2

Logs

  • Log Management: Windows, Linux, Mac, network and application logs.
  • Read raw log excerpts and narrate what happened.
Weeks 3-4

Triage and hunting

  • Incident Detection and Triage with original alert scenarios and SIEM use-case reasoning.
  • Proactive Threat Detection: intelligence and hunting hypotheses.
Weeks 5-6

Response and review

  • Incident Response lifecycle, playbooks and ordering questions.
  • Forensics and malware basics, then timed mixed practice across all eight domains.

Shorten or stretch that to fit your experience. Someone already working as an analyst may compress the log weeks; someone coming from general IT may need extra time on triage reasoning. Whichever pace you choose, test yourself under timed conditions with original scenario questions, and use the CSA practice tests on the main site to check whether you can sustain accuracy over a full-length sitting. Avoid leaked "dump" content: it is unreliable against a v2 blueprint and undermines the point of certifying. For the training-versus-self-study decision, our overview of CSA training options may help.

Careers, Pay Evidence and Renewal

Who hires for this skill set

SOC analyst roles exist across managed security service providers, enterprise security teams, government and defense contractors, and any organization large enough to monitor its own environment. Job titles you will see alongside this credential include SOC analyst, security analyst, junior incident responder and threat detection analyst. Browse our CSA jobs overview for how the credential appears in postings.

Be careful with salary claims

There is plenty of published data on what SOC analysts earn as an occupation, but there is no verified evidence here of a CSA-specific salary premium, and we do not assert one. Pay depends on location, employer type, shift structure and experience far more than on any single certification. If you are weighing the investment, read the CSA salary guide for how to interpret occupational pay data, and the ROI analysis for a fuller decision framework.

How CSA compares with CySA+

Candidates often compare this credential with CompTIA CySA+, since both target defensive security analysts. The practical differences are administrative: they come from different certifying bodies with different eligibility rules, fees and exam structures. Here the notable features are EC-Council's gated eligibility, the USD 450 voucher and the eight-domain v2 blueprint. Pick based on what your target employers list and which blueprint matches the work you want to do.

Renewal and continuing education

The certification is maintained on a three-year cycle. To keep it active you need 120 CPE/ECE credits within that cycle and must pay the annual continuing-education fee of USD 80, which totals USD 240 over three years. The distinction matters: paying the fee alone does not satisfy the continuing-education requirement. You must earn and report the credits. Reasonable ways to accumulate them include attending relevant training, conferences, webinars and publishing or presenting, subject to EC-Council's CPE policy. Plan the credits from day one so you are not scrambling in year three.

Frequently Asked Questions

How many questions are on the CSA exam, and how long do I have?

The exam has 100 multiple-choice questions with a three-hour time limit. The three-day figure you may see refers to training course duration, not the exam timer.

What score do I need to pass?

The passing score is 70%, which means answering at least 70 of the 100 questions correctly. See the passing score guide for details.

Do I have to take official training to sit the exam?

No. The certification portal provides a self-study route for candidates with one year of verified network-administration or security experience, an employer or department verifier, and payment of the USD 100 nonrefundable application fee. Official training is the alternative route.

What does the exam voucher cost, and does it expire?

The CSAv2 Exam Voucher (RPS) is USD 450, uses remote proctoring, is non-transferable and is valid for one year. After self-study eligibility approval you have a three-month window to purchase it. The USD 250 eCourseware is study material, not a voucher.

Which domains should I prioritize?

Incident Detection and Triage and Incident Response are 25% each, so together they are half the exam. Log Management at 15% and Proactive Threat Detection at 12% come next. Review the domains guide for what each one tests.

Ready to pass your CSA exam?

Put this into practice with free CSA questions across every exam domain.