- Identity and Exam Format at a Glance
- Fees, Eligibility and Voucher Rules
- The Eight Domains and Their Weights
- Incident Detection and Triage Essentials
- Incident Response Essentials
- Log Management Quick Reference
- The Four Smaller Domains in One Pass
- Scheduling Study by Domain Weight
- Renewal, Careers and What Not to Assume
- Frequently Asked Questions
- CSA here means Certified SOC Analyst v2, EC-Council exam 312-39: 100 multiple-choice questions, three hours, 70% to pass.
- Incident Detection and Triage and Incident Response are each 25%, together half of the blueprint.
- The USD 450 voucher is separate from the USD 100 self-study application fee and from optional training bundles.
- Renewal runs on a three-year cycle: 120 CPE/ECE credits plus the USD 80 annual fee; paying alone is not enough.
Identity and Exam Format at a Glance
This cheat sheet covers one credential: the EC-Council Certified SOC Analyst (CSA) v2, exam code 312-39. Other certifications share the same three letters, and their fees, domains and policies do not apply here. If you are still sorting out the name, the explainers on what CSA certification is and what CSA stands for cover the basics; this page assumes you have already chosen the SOC analyst credential and want the facts on one screen.
| Item | Verified fact |
|---|---|
| Credential | Certified SOC Analyst (CSA) v2 |
| Exam code | 312-39 |
| Certifying body | EC-Council |
| Question count | 100 multiple-choice questions |
| Time limit | Three hours |
| Passing score | 70% |
| Delivery | Remote proctoring via the ECC Exam Centre / EC-Council Exam Portal (voucher listed as RPS) |
| Format type | Knowledge-based multiple choice, not a hands-on lab exam |
At 100 questions in 180 minutes, you have a little under two minutes per question on average. That is generous for definition-style items and tight for long scenario stems, so budget by reading carefully rather than racing. For a fuller treatment of the number you need, see the CSA passing score guide.
Fees, Eligibility and Voucher Rules
The most common source of confusion is that several different dollar amounts circulate, and they cover different things. Keep them separate:
| Charge | Amount | What it actually is |
|---|---|---|
| CSAv2 Exam Voucher (RPS) | USD 450 | Remote-proctored exam attempt; non-transferable; valid one year from purchase |
| Self-study eligibility application | USD 100 | Nonrefundable fee for candidates who skip official training |
| Official eCourseware | USD 250 | A separate training product; it is not an exam voucher |
| Annual continuing-education fee | USD 80 | USD 240 across the three-year cycle |
Two routes to eligibility
- Official training route: Purchase qualifying official training or courseware. EC-Council's eligibility page states that official-training fees include the USD 100 application charge, so you do not pay it twice.
- Self-study route: Document one year of verified network-administration or security experience, have an employer, supervisor or department verifier confirm it, and pay the USD 100 nonrefundable application fee. Once approved, you get a three-month window to buy the voucher.
Do the arithmetic before you commit: a self-study candidate budgets USD 100 plus USD 450, while a training-route candidate budgets the training bundle plus the voucher as the portal specifies. The full line-by-line view is in the CSA certification cost breakdown, and the prerequisites are expanded in CSA requirements and eligibility. Note the three-month purchase window after approval and the one-year voucher validity; both are deadlines you can miss, which is worth cross-checking against the exam dates and scheduling guide.
The Eight Domains and Their Weights
The official Certified SOC Analyst (CSA) v2 Exam Blueprint lists eight domains with weights totaling 100%. These are weighted exam objectives, not allocations inferred from the course outline. Older six-domain lists, third-party four-domain splits and two-hour exam claims describe other versions or unsupported sources, not v2.
| # | Domain | Weight |
|---|---|---|
| 1 | Security Operations and Management | 5% |
| 2 | Understanding Cyber Threats, IoCs, and Attack Methodology | 8% |
| 3 | Log Management | 15% |
| 4 | Incident Detection and Triage | 25% |
| 5 | Proactive Threat Detection | 12% |
| 6 | Incident Response | 25% |
| 7 | Forensics Investigation and Malware Analysis | 5% |
| 8 | SOC for Cloud Environments | 5% |
Triage plus response equals 50% of the blueprint, and adding Log Management brings you to 65%. Those three domains are the core of your score. A deeper domain-by-domain walkthrough lives in the CSA exam domains guide.
Incident Detection and Triage Essentials
Domain 4: Incident Detection and Triage (25%)
The heaviest domain, tied with response. Expect questions that hand you an alert, a log excerpt or a short narrative and ask what an analyst should conclude or do next.
- SIEM use cases: what a detection rule is meant to catch, and why a rule fires or fails to fire
- AI-assisted rule creation, a v2 topic: treat generated rules as drafts that need validation against real log fields and expected false-positive behavior
- Alert triage: separating true positives from false positives, then prioritizing by asset criticality and likely impact
- Correlating events across sources instead of judging a single log line in isolation
- Escalation: knowing when an alert stays with the analyst and when it moves up
A original triage scenario to rehearse
Suppose a SIEM raises an alert for repeated failed authentications against one account, followed by a single success from an address the account has never used. The reasoning chain the exam rewards looks like this:
- Confirm the pattern is real: check that timestamps, source addresses and account names line up across the authentication log and any related network log.
- Look for context that changes severity: is the account privileged, is the success followed by unusual activity, is the source address associated with known malicious infrastructure?
- Decide the classification: a failure burst then a success from a new source is consistent with credential guessing succeeding, so treat it as a likely true positive pending evidence.
- Escalate with a clear summary rather than an unsupported guess.
Practice stems built this way, with a pattern, a context clue and a decision, are far closer to the real exam than rote definitions. You can drill similar items in the CSA practice tests, which use original explanations rather than recalled exam content.
Incident Response Essentials
Domain 6: Incident Response (25%)
The other half of the 50% core. Questions test the order of operations, the purpose of each phase and sensible actions under pressure.
- The incident response lifecycle and what belongs in each phase: preparation, identification, containment, eradication, recovery and lessons learned
- Playbooks: how documented, repeatable steps keep response consistent and reduce improvisation
- Containment judgment: short-term isolation versus longer-term fixes, and the tradeoff between stopping spread and preserving evidence
- Roles and communication: who is informed, what is documented, and why timelines and notes matter
- Post-incident review: converting findings into updated detections, playbooks and controls
Key Takeaway
When a response question offers several plausible actions, ask what the current phase is. Eradication steps in a containment-phase scenario, or evidence-destroying cleanup before preservation, are classic wrong answers.
Because triage hands off to response, study them as one pipeline: detection produces a confirmed incident, and the playbook tells you what happens next. The difficulty guide explains why candidates who treat these as separate silos tend to find scenario questions harder than expected.
Log Management Quick Reference
Domain 3: Log Management (15%)
The third-largest domain and the raw material for everything in triage. If you cannot read a log, you cannot triage it.
- Sources named in the blueprint-supported scope: Windows, Linux and Mac system logs, plus network and application logs
- Collection and centralization: why logs are forwarded to a central platform and what is lost when collection is incomplete
- Normalization and correlation: how differing formats become comparable fields
- Retention and integrity: why log tampering and gaps matter for investigations
- Reading entries: identifying who, what, when and from where in a record
A good habit is to take any log line and answer four questions out loud: which system produced it, what action occurred, which identity or address was involved, and what would make it suspicious. That drill transfers directly to log analysis questions across Domains 3 and 4.
The Four Smaller Domains in One Pass
The remaining domains total 35% combined, which is too much to ignore even though each is individually modest. Domain 5 (Proactive Threat Detection) alone is 12%.
Domain 5: Proactive Threat Detection (12%)
Moves from waiting for alerts to looking for threats.
- Threat intelligence: using external and internal intelligence to enrich alerts and guide detections
- Threat hunting: forming a hypothesis, searching data for evidence, and feeding results back into detections
- The difference between reactive alert handling and proactive searching
Domain 2: Understanding Cyber Threats, IoCs, and Attack Methodology (8%)
- Indicators of compromise and what they tell an analyst
- Attack methodology: how adversaries progress through stages, and where each stage leaves traces
Domain 1: Security Operations and Management (5%)
- SOC operations: functions, tiers and workflow
- SOC maturity: how capability and process develop over time
Domain 7: Forensics Investigation and Malware Analysis (5%)
- Evidence handling and preservation fundamentals
- Introductory malware analysis concepts at the analyst, not reverse-engineer, level
Domain 8: SOC for Cloud Environments (5%)
- Monitoring and detection in Azure, AWS and GCP environments
- How cloud logging differs from traditional on-premises sources
Scheduling Study by Domain Weight
The only planning advice worth giving is tied to the weights: front-load the logs, then the pipeline, then sweep the small domains. A compact sequence that follows the blueprint:
Foundations and Logs
- Domain 1 and Domain 2 in brief
- Domain 3: read Windows, Linux and network log samples daily
The 25% Core
- Domain 4: SIEM use cases, AI-assisted rules, triage scenarios
- Domain 6: lifecycle phases, playbooks, containment decisions
Remaining Domains and Mixed Review
- Domain 5, Domain 7 and Domain 8
- Full-length timed practice across all eight domains
Adjust the length to your background, but keep the ordering logic. The fuller plan, with resource suggestions, is in the CSA study guide.
Renewal, Careers and What Not to Assume
Staying certified
The certification is maintained on a three-year cycle requiring 120 CPE/ECE credits, with the published USD 80 annual continuing-education fee (USD 240 over three years). The fee and the credits are separate obligations: paying the fee alone does not satisfy the continuing-education requirement. Track credits from the first year rather than scrambling at the end.
Careers and pay
The credential maps naturally to SOC analyst and incident-handling work; the CSA jobs overview looks at where it fits. On earnings, be careful: occupational SOC analyst pay is documented by labor-market sources, but no certification-specific salary premium for CSA is established here, and no certification-wide pass rate is published in the verified facts. Treat anyone quoting a precise CSA pay bump or pass percentage with skepticism. For a measured discussion, see the salary guide, the pass rate analysis and the ROI analysis.
Frequently Asked Questions
The Certified SOC Analyst v2 exam (312-39) has 100 multiple-choice questions with a three-hour time limit. The passing score is 70%.
Not necessarily. The portal's CSA-specific eligibility section offers a self-study route requiring one year of verified network-administration or security experience, a verifier, and a USD 100 nonrefundable application fee. This takes precedence over the blanket suggestion on the training page.
Incident Detection and Triage and Incident Response are each 25%, together 50% of the blueprint. Log Management at 15% and Proactive Threat Detection at 12% come next, and the remaining four domains add up to 18%.
No. The eCourseware is a training purchase. The exam voucher is a separate USD 450 product, non-transferable and valid for one year.
A three-year cycle requiring 120 CPE/ECE credits, plus the USD 80 annual continuing-education fee. The fee alone does not fulfill the credit requirement.
For a broader introduction to the credential before you start drilling, read what CSA is, then test yourself with the CSA exam prep practice tests to see how the eight domains feel under timed conditions.