- How the Eight Domains Fit Together
- The Weight Map at a Glance
- Domain 4: Incident Detection and Triage (25%)
- Domain 6: Incident Response (25%)
- Domain 3: Log Management (15%)
- Domain 5: Proactive Threat Detection (12%)
- Domain 2: Cyber Threats, IoCs, and Attack Methodology (8%)
- The Three 5% Domains
- Sequencing Your Preparation by Domain
- Exam Mechanics That Shape Domain Strategy
- Frequently Asked Questions
- The CSA v2 (exam 312-39) blueprint has eight weighted domains that total 100%.
- Incident Detection and Triage and Incident Response are 25% each, making up half the blueprint.
- Log Management (15%) and Proactive Threat Detection (12%) together add another 27% of the exam.
- The exam is 100 multiple-choice questions in three hours, with a 70% passing score.
How the Eight Domains Fit Together
The Certified SOC Analyst (CSA) v2 exam, code 312-39, is built from a published blueprint titled Certified SOC Analyst (CSA) v2 Exam Blueprint. EC-Council lists eight weighted domains, and those weights are official exam objectives rather than allocations derived from the training curriculum. This distinction matters: when you decide where to spend study hours, the blueprint weights are the authoritative signal.
The eight domains follow the real flow of SOC work. Foundations come first (operations, threats, logs), the heavy middle covers detecting, triaging and responding, and the closing domains handle forensics and cloud environments. Reading them as a workflow rather than eight isolated topic lists makes the material easier to retain, because scenario questions typically ask what an analyst does next in that workflow.
If you are still orienting yourself on the credential itself, the overview at What Is CSA Certification? covers the basics, while this guide focuses on how the exam content is divided. Candidates who want a week-by-week plan can pair this article with the CSA Study Guide 2026: How to Pass on Your First Attempt.
The Weight Map at a Glance
Because the weights are official, you can treat them as a rough guide to how many of the 100 questions each area is likely to draw on. The blueprint does not publish exact question counts per domain, so treat any per-domain question number as an estimate rather than a guarantee.
| Domain | Name | Weight |
|---|---|---|
| 1 | Security Operations and Management | 5% |
| 2 | Understanding Cyber Threats, IoCs, and Attack Methodology | 8% |
| 3 | Log Management | 15% |
| 4 | Incident Detection and Triage | 25% |
| 5 | Proactive Threat Detection | 12% |
| 6 | Incident Response | 25% |
| 7 | Forensics Investigation and Malware Analysis | 5% |
| 8 | SOC for Cloud Environments | 5% |
Notice the shape: two domains at 25% each account for 50% of the blueprint, and the three 5% domains together account for just 15%. A candidate who masters Domains 3, 4, 5 and 6 has covered 77% of the published weighting, which is why this guide spends most of its space there.
Domain 4: Incident Detection and Triage (25%)
This is the joint-largest domain, and it is where the blueprint-supported topics of SIEM use cases, AI-generated rules and alert triage live. The skill being tested is judgment under volume: given an alert, an analyst must decide whether it is real, how severe it is, and where it goes next.
What candidates must understand
How alerts are produced, enriched, prioritized and escalated within a SIEM-centered SOC.
- SIEM use cases: the detection logic behind an alert and what data sources it depends on
- AI-assisted rule creation, a v2 topic: understanding how generated detection rules should be reviewed rather than trusted blindly
- Alert triage: separating false positives from true positives, assigning severity, and choosing escalation paths
- Contextual enrichment: using asset criticality, user behavior and threat intelligence to rank alerts
An original triage scenario to practice
Suppose a SIEM raises an alert for 40 failed logons against a single service account in five minutes, followed by one success from an unfamiliar external IP address. A strong analyst works through a sequence: confirm the account's normal behavior, check whether the source IP appears in threat intelligence, look for subsequent activity from that session, and decide whether the pattern fits password spraying or a misconfigured application. The exam rewards recognizing which evidence changes the severity and which merely adds noise.
Practice questions in this domain tend to present a short alert description and ask for the best next action or the correct classification. Drilling that format with original scenarios, such as those in the CSA practice tests, builds the pattern recognition that 25% of the blueprint demands.
Domain 6: Incident Response (25%)
The other 25% domain covers what happens after an alert is confirmed. Study examples within this domain include incident response processes and playbooks, and the exam expects you to understand the lifecycle well enough to place any action in the right phase.
Core response knowledge
The sequence from preparation through containment, eradication, recovery and lessons learned, applied to realistic situations.
- Playbooks: how documented procedures standardize response for recurring incident types
- Containment decisions: short-term isolation versus long-term fixes, and the evidence-preservation tradeoffs involved
- Roles and communication: who is notified, when, and what the analyst's responsibilities are versus the incident manager's
- Post-incident activity: documenting findings and feeding improvements back into detection rules
An original response scenario to practice
A workstation is confirmed to be beaconing to an external host. Before wiping it, what should happen? The reasoning chain involves isolating the host from the network, preserving volatile evidence where policy allows, identifying other hosts contacting the same destination, and only then moving to eradication. Questions in this domain often hinge on ordering: knowing that scoping and evidence handling come before remediation is worth more than memorizing definitions.
If you are weighing how demanding this material is overall, How Hard Is the CSA Exam? Complete Difficulty Guide 2026 discusses what makes scenario-driven questions tricky.
Domain 3: Log Management (15%)
At 15%, Log Management is the third-largest domain, and it underpins both Domain 4 and Domain 6. You cannot triage what you cannot read. The blueprint-supported preparation here spans Windows, Linux and Mac logs as well as network and application logs.
Log sources to know
What each platform records, where it lives, and which events matter for investigation.
- Windows: authentication events, process creation, service installation and policy changes
- Linux and Mac: authentication logs, system logs and command or audit records
- Network: firewall, proxy, DNS and IDS/IPS records that reveal communication patterns
- Application: web server and application logs showing requests, errors and abuse attempts
Beyond sources, expect questions on collection and centralization: how logs reach a SIEM, why timestamps and time synchronization matter for correlation, and why retention and integrity are operational concerns. A practical drill is to take a single event, such as a successful remote login, and list which log sources would each hold a piece of the story. Candidates who can do that tend to handle log analysis questions comfortably.
Domain 5: Proactive Threat Detection (12%)
This 12% domain covers threat intelligence and hunting, and it is where the v2 emphasis on proactive work shows up. Rather than waiting for an alert, hunters form a hypothesis and search for evidence of activity that existing rules missed.
Hunting and intelligence essentials
How intelligence informs detection and how hypotheses drive searches.
- Threat intelligence types and how indicators are consumed, aged and validated
- Hypothesis-driven hunting: starting from a technique or behavior, then querying data for it
- Turning findings into durable detections so a one-time hunt becomes an ongoing rule
- Recognizing the limits of indicator-based detection compared with behavioral approaches
A useful mental exercise: take a published adversary behavior, write one sentence stating what it would look like in your logs, and identify which data source would show it. That habit connects Domain 5 directly back to Domain 3.
Domain 2: Cyber Threats, IoCs, and Attack Methodology (8%)
Domain 2 carries 8% and supplies the vocabulary the other domains depend on. It covers attack methodology and indicators of compromise, meaning the stages an attacker moves through and the artifacts they leave behind.
- Attack methodology: how intrusions progress from reconnaissance through execution and objectives, and how defenders map observed activity to those stages
- Indicators of compromise: file hashes, domains, IP addresses and behavioral artifacts, along with how reliable and how perishable each type is
- Threat categories: common malware families, social engineering and network or application attacks, understood well enough to recognize them in an alert description
Though the weight is modest, this material pays off elsewhere: you cannot confidently classify an alert in Domain 4 without knowing what the attack stages look like.
The Three 5% Domains
Domains 1, 7 and 8 are each 5%. Small does not mean skippable, since together they represent 15% of the blueprint, but they deserve proportionate effort.
Domain 1: Security Operations and Management
This domain covers SOC operations and maturity: how a SOC is structured, how its processes and people are organized, and how maturity is assessed and improved. Expect conceptual questions about roles, workflows and measurement rather than technical depth.
Domain 7: Forensics Investigation and Malware Analysis
Use the blueprint's exact heading, Forensics Investigation and Malware Analysis, when searching for or organizing materials. Study evidence handling, the order of volatility, and a foundational understanding of how malware is analyzed. At the SOC analyst level this is about knowing what to preserve and when to escalate, not about performing deep reverse engineering.
Domain 8: SOC for Cloud Environments
Cloud SOC work spans Azure, AWS and GCP. Focus on what monitoring looks like when infrastructure is provider-managed: which cloud log sources exist, how identity and API activity are tracked, and how cloud telemetry feeds a SIEM. Learn the concepts shared across providers first, then note the naming differences.
Key Takeaway
The blueprint-supported topics such as AI-generated rules, cloud SOC work and threat hunting are study examples inside the eight published domains. They are not extra weighted domains, so fold them into the domain they belong to rather than treating them as separate subjects.
Sequencing Your Preparation by Domain
Generic scheduling advice is less useful than ordering your study by dependency. Logs come before triage because triage is log reading; triage comes before response because response begins with a confirmed incident. This is one reasonable sequence, which you can compress or stretch to fit your timeline.
Foundations: Domains 1 and 2
- SOC structure and maturity concepts
- Attack stages and IoC types
Evidence base: Domain 3
- Windows, Linux, Mac, network and application log sources
- Collection, centralization and time correlation
The 25% domain: Domain 4
- SIEM use cases, rule logic and AI-generated rule review
- Alert triage drills with original scenarios
The other 25%: Domains 6 and 5
- Playbooks and the response lifecycle
- Threat intelligence and hypothesis-driven hunting
Specialty and review: Domains 7 and 8
- Forensics, malware analysis basics, Azure/AWS/GCP SOC concepts
- Full-length timed practice across all eight domains
For a quick pre-exam recap of the facts that recur across these domains, the CSA Cheat Sheet 2026: One-Page Review of Must-Know Facts is a useful companion.
Exam Mechanics That Shape Domain Strategy
The domain weights only matter if you understand the container they sit in. The exam has 100 multiple-choice questions, a three-hour time limit and a 70% passing score. That works out to a little under two minutes per question, which is generous for definitional items and tight only if you linger on long scenario stems. The three-day training description you may see in marketing materials refers to course duration, not the exam timer, and the training labs do not make the certification a hands-on lab assessment.
The exam is delivered through the ECC Exam Centre/EC-Council Exam Portal, and the official CSAv2 Exam Voucher - RPS is USD 450 with remote proctoring. A purchased voucher is non-transferable and valid for one year. Two eligibility routes exist: an official-training route and a self-study route. Self-study applicants need one year of verified network-administration or security experience, an employer, supervisor or department verifier, and must pay a USD 100 nonrefundable eligibility-application fee; approved eligibility opens a three-month window to buy the voucher. The separately listed USD 250 eCourseware purchase is not an exam voucher.
For the full eligibility walkthrough, see CSA Requirements 2026: Eligibility, Prerequisites & How to Qualify, and for the money side, CSA Certification Cost 2026: Complete Pricing Breakdown separates the voucher, application fee and optional bundles. The exact threshold is explained in CSA Passing Score 2026: Exactly What You Need to Pass.
Finally, no certification-wide pass rate is asserted here, and none should be assumed from third-party claims. To test yourself against the weighting described above, work through original scenario questions in the CSA practice exam environment and track your results by domain rather than by overall score alone.
Frequently Asked Questions
The Certified SOC Analyst (CSA) v2 blueprint for exam 312-39 lists eight weighted domains totaling 100%. Older six-domain v1 lists and third-party four-domain groupings do not describe the current v2 scope.
Incident Detection and Triage and Incident Response are the largest at 25% each, together making up 50% of the blueprint. Log Management follows at 15% and Proactive Threat Detection at 12%.
Cloud SOC is Domain 8, SOC for Cloud Environments, at 5%. AI-generated rules are a study example within the detection and triage material, not an extra weighted domain.
The exam has 100 multiple-choice questions with a three-hour limit and a 70% passing score. It is not a hands-on lab assessment, even though the training includes labs.
No. The CSA-specific eligibility provisions allow a self-study route with one year of verified network-administration or security experience and a USD 100 nonrefundable application fee. Those provisions take precedence over the blanket suggestion on the training page that training is mandatory.