CSA logo
Focused certification exam prep
Start practice

CSA Cheat Sheet 2026: One-Page Review of Must-Know Facts

TL;DR
  • CSA here means Certified SOC Analyst v2, EC-Council exam 312-39: 100 multiple-choice questions, three hours, 70% to pass.
  • Incident Detection and Triage and Incident Response are each 25%, together half of the blueprint.
  • The USD 450 voucher is separate from the USD 100 self-study application fee and from optional training bundles.
  • Renewal runs on a three-year cycle: 120 CPE/ECE credits plus the USD 80 annual fee; paying alone is not enough.

Identity and Exam Format at a Glance

This cheat sheet covers one credential: the EC-Council Certified SOC Analyst (CSA) v2, exam code 312-39. Other certifications share the same three letters, and their fees, domains and policies do not apply here. If you are still sorting out the name, the explainers on what CSA certification is and what CSA stands for cover the basics; this page assumes you have already chosen the SOC analyst credential and want the facts on one screen.

ItemVerified fact
CredentialCertified SOC Analyst (CSA) v2
Exam code312-39
Certifying bodyEC-Council
Question count100 multiple-choice questions
Time limitThree hours
Passing score70%
DeliveryRemote proctoring via the ECC Exam Centre / EC-Council Exam Portal (voucher listed as RPS)
Format typeKnowledge-based multiple choice, not a hands-on lab exam
Training days are not exam time: The three-day training description refers to how long the course runs. It has nothing to do with your exam timer, which is three hours. Likewise, labs inside the training do not turn the certification exam into a practical assessment. Prepare for scenario-flavored multiple-choice questions that test judgment about alerts, logs and response steps.

At 100 questions in 180 minutes, you have a little under two minutes per question on average. That is generous for definition-style items and tight for long scenario stems, so budget by reading carefully rather than racing. For a fuller treatment of the number you need, see the CSA passing score guide.

Fees, Eligibility and Voucher Rules

The most common source of confusion is that several different dollar amounts circulate, and they cover different things. Keep them separate:

ChargeAmountWhat it actually is
CSAv2 Exam Voucher (RPS)USD 450Remote-proctored exam attempt; non-transferable; valid one year from purchase
Self-study eligibility applicationUSD 100Nonrefundable fee for candidates who skip official training
Official eCoursewareUSD 250A separate training product; it is not an exam voucher
Annual continuing-education feeUSD 80USD 240 across the three-year cycle

Two routes to eligibility

  1. Official training route: Purchase qualifying official training or courseware. EC-Council's eligibility page states that official-training fees include the USD 100 application charge, so you do not pay it twice.
  2. Self-study route: Document one year of verified network-administration or security experience, have an employer, supervisor or department verifier confirm it, and pay the USD 100 nonrefundable application fee. Once approved, you get a three-month window to buy the voucher.
Which page wins? The training page's FAQ suggests official training is mandatory in blanket terms. The certification portal's CSA-specific eligibility section takes precedence, and it provides the self-study path above. Candidates who are minors face additional parental-consent and educational-institution documentation rules on the portal.

Do the arithmetic before you commit: a self-study candidate budgets USD 100 plus USD 450, while a training-route candidate budgets the training bundle plus the voucher as the portal specifies. The full line-by-line view is in the CSA certification cost breakdown, and the prerequisites are expanded in CSA requirements and eligibility. Note the three-month purchase window after approval and the one-year voucher validity; both are deadlines you can miss, which is worth cross-checking against the exam dates and scheduling guide.

The Eight Domains and Their Weights

The official Certified SOC Analyst (CSA) v2 Exam Blueprint lists eight domains with weights totaling 100%. These are weighted exam objectives, not allocations inferred from the course outline. Older six-domain lists, third-party four-domain splits and two-hour exam claims describe other versions or unsupported sources, not v2.

#DomainWeight
1Security Operations and Management5%
2Understanding Cyber Threats, IoCs, and Attack Methodology8%
3Log Management15%
4Incident Detection and Triage25%
5Proactive Threat Detection12%
6Incident Response25%
7Forensics Investigation and Malware Analysis5%
8SOC for Cloud Environments5%

Triage plus response equals 50% of the blueprint, and adding Log Management brings you to 65%. Those three domains are the core of your score. A deeper domain-by-domain walkthrough lives in the CSA exam domains guide.

Incident Detection and Triage Essentials

Domain 4: Incident Detection and Triage (25%)

The heaviest domain, tied with response. Expect questions that hand you an alert, a log excerpt or a short narrative and ask what an analyst should conclude or do next.

  • SIEM use cases: what a detection rule is meant to catch, and why a rule fires or fails to fire
  • AI-assisted rule creation, a v2 topic: treat generated rules as drafts that need validation against real log fields and expected false-positive behavior
  • Alert triage: separating true positives from false positives, then prioritizing by asset criticality and likely impact
  • Correlating events across sources instead of judging a single log line in isolation
  • Escalation: knowing when an alert stays with the analyst and when it moves up

A original triage scenario to rehearse

Suppose a SIEM raises an alert for repeated failed authentications against one account, followed by a single success from an address the account has never used. The reasoning chain the exam rewards looks like this:

  1. Confirm the pattern is real: check that timestamps, source addresses and account names line up across the authentication log and any related network log.
  2. Look for context that changes severity: is the account privileged, is the success followed by unusual activity, is the source address associated with known malicious infrastructure?
  3. Decide the classification: a failure burst then a success from a new source is consistent with credential guessing succeeding, so treat it as a likely true positive pending evidence.
  4. Escalate with a clear summary rather than an unsupported guess.

Practice stems built this way, with a pattern, a context clue and a decision, are far closer to the real exam than rote definitions. You can drill similar items in the CSA practice tests, which use original explanations rather than recalled exam content.

Incident Response Essentials

Domain 6: Incident Response (25%)

The other half of the 50% core. Questions test the order of operations, the purpose of each phase and sensible actions under pressure.

  • The incident response lifecycle and what belongs in each phase: preparation, identification, containment, eradication, recovery and lessons learned
  • Playbooks: how documented, repeatable steps keep response consistent and reduce improvisation
  • Containment judgment: short-term isolation versus longer-term fixes, and the tradeoff between stopping spread and preserving evidence
  • Roles and communication: who is informed, what is documented, and why timelines and notes matter
  • Post-incident review: converting findings into updated detections, playbooks and controls

Key Takeaway

When a response question offers several plausible actions, ask what the current phase is. Eradication steps in a containment-phase scenario, or evidence-destroying cleanup before preservation, are classic wrong answers.

Because triage hands off to response, study them as one pipeline: detection produces a confirmed incident, and the playbook tells you what happens next. The difficulty guide explains why candidates who treat these as separate silos tend to find scenario questions harder than expected.

Log Management Quick Reference

Domain 3: Log Management (15%)

The third-largest domain and the raw material for everything in triage. If you cannot read a log, you cannot triage it.

  • Sources named in the blueprint-supported scope: Windows, Linux and Mac system logs, plus network and application logs
  • Collection and centralization: why logs are forwarded to a central platform and what is lost when collection is incomplete
  • Normalization and correlation: how differing formats become comparable fields
  • Retention and integrity: why log tampering and gaps matter for investigations
  • Reading entries: identifying who, what, when and from where in a record

A good habit is to take any log line and answer four questions out loud: which system produced it, what action occurred, which identity or address was involved, and what would make it suspicious. That drill transfers directly to log analysis questions across Domains 3 and 4.

The Four Smaller Domains in One Pass

The remaining domains total 35% combined, which is too much to ignore even though each is individually modest. Domain 5 (Proactive Threat Detection) alone is 12%.

Domain 5: Proactive Threat Detection (12%)

Moves from waiting for alerts to looking for threats.

  • Threat intelligence: using external and internal intelligence to enrich alerts and guide detections
  • Threat hunting: forming a hypothesis, searching data for evidence, and feeding results back into detections
  • The difference between reactive alert handling and proactive searching

Domain 2: Understanding Cyber Threats, IoCs, and Attack Methodology (8%)

  • Indicators of compromise and what they tell an analyst
  • Attack methodology: how adversaries progress through stages, and where each stage leaves traces

Domain 1: Security Operations and Management (5%)

  • SOC operations: functions, tiers and workflow
  • SOC maturity: how capability and process develop over time

Domain 7: Forensics Investigation and Malware Analysis (5%)

  • Evidence handling and preservation fundamentals
  • Introductory malware analysis concepts at the analyst, not reverse-engineer, level

Domain 8: SOC for Cloud Environments (5%)

  • Monitoring and detection in Azure, AWS and GCP environments
  • How cloud logging differs from traditional on-premises sources

Scheduling Study by Domain Weight

The only planning advice worth giving is tied to the weights: front-load the logs, then the pipeline, then sweep the small domains. A compact sequence that follows the blueprint:

Week 1

Foundations and Logs

  • Domain 1 and Domain 2 in brief
  • Domain 3: read Windows, Linux and network log samples daily
Week 2-3

The 25% Core

  • Domain 4: SIEM use cases, AI-assisted rules, triage scenarios
  • Domain 6: lifecycle phases, playbooks, containment decisions
Week 4

Remaining Domains and Mixed Review

  • Domain 5, Domain 7 and Domain 8
  • Full-length timed practice across all eight domains

Adjust the length to your background, but keep the ordering logic. The fuller plan, with resource suggestions, is in the CSA study guide.

Renewal, Careers and What Not to Assume

Staying certified

The certification is maintained on a three-year cycle requiring 120 CPE/ECE credits, with the published USD 80 annual continuing-education fee (USD 240 over three years). The fee and the credits are separate obligations: paying the fee alone does not satisfy the continuing-education requirement. Track credits from the first year rather than scrambling at the end.

Careers and pay

The credential maps naturally to SOC analyst and incident-handling work; the CSA jobs overview looks at where it fits. On earnings, be careful: occupational SOC analyst pay is documented by labor-market sources, but no certification-specific salary premium for CSA is established here, and no certification-wide pass rate is published in the verified facts. Treat anyone quoting a precise CSA pay bump or pass percentage with skepticism. For a measured discussion, see the salary guide, the pass rate analysis and the ROI analysis.

Version warning: Some third-party pages still describe v1 content, legacy exam codes or a two-hour exam. For v2, rely on the official blueprint and the EC-Council certification pages: exam 312-39, three hours, eight domains. When a source disagrees, the issuer wins.

Frequently Asked Questions

How many questions and how much time does the CSA exam give you?

The Certified SOC Analyst v2 exam (312-39) has 100 multiple-choice questions with a three-hour time limit. The passing score is 70%.

Do I have to take official training before sitting the exam?

Not necessarily. The portal's CSA-specific eligibility section offers a self-study route requiring one year of verified network-administration or security experience, a verifier, and a USD 100 nonrefundable application fee. This takes precedence over the blanket suggestion on the training page.

Which domains matter most for scoring?

Incident Detection and Triage and Incident Response are each 25%, together 50% of the blueprint. Log Management at 15% and Proactive Threat Detection at 12% come next, and the remaining four domains add up to 18%.

Is the USD 250 eCourseware the same as an exam voucher?

No. The eCourseware is a training purchase. The exam voucher is a separate USD 450 product, non-transferable and valid for one year.

What does it take to keep the certification current?

A three-year cycle requiring 120 CPE/ECE credits, plus the USD 80 annual continuing-education fee. The fee alone does not fulfill the credit requirement.

For a broader introduction to the credential before you start drilling, read what CSA is, then test yourself with the CSA exam prep practice tests to see how the eight domains feel under timed conditions.

Ready to pass your CSA exam?

Put this into practice with free CSA questions across every exam domain.