- The Number: 70% on 100 Questions
- What 70% Means in Practice
- Where the Points Live: Domain Weights
- Format, Timing, and Delivery
- Before You Can Earn a Score: Eligibility and Cost
- Winning the 50%: Triage and Incident Response
- Log Management and Proactive Detection
- The Small Domains Still Matter
- Setting Your Own Readiness Threshold
- After You Pass: Maintaining the Credential
- Frequently Asked Questions
- The Certified SOC Analyst (CSA) v2 exam, 312-39, has 100 multiple-choice questions and a published 70% passing score.
- Incident Detection and Triage and Incident Response are 25% each, so half the blueprint rides on two domains.
- You get three hours; the three-day training course length is not your exam timer.
- The voucher costs USD 450 and is valid for one year; self-study applicants also pay a USD 100 application fee.
The Number: 70% on 100 Questions
The published passing score for the EC-Council Certified SOC Analyst (CSA) v2 exam, code 312-39, is 70%. The exam consists of 100 multiple-choice questions delivered within a three-hour limit. Those three figures come straight from EC-Council's certification page for the credential, and they are the ones that matter for planning.
Be careful with older material. Third-party sites sometimes describe a two-hour exam, a four-domain split, or the six-domain list that belonged to version 1. None of that describes the verified v2 exam. If a study resource quotes a different duration or a different domain count, treat it as outdated until you have checked it against the official CSA exam domains guide and the issuer's blueprint.
One more note on naming. In this article, "CSA" always means Certified SOC Analyst from EC-Council. Other credentials share the same three letters, and their fees, scoring, and domains are entirely different. If you want the identity question settled first, the explainers on what CSA certification is and what CSA stands for cover it.
What 70% Means in Practice
On a 100-question exam, 70% translates to answering roughly 70 questions correctly if each question counts equally. EC-Council's public pages state the percentage and the question count but do not publish a scoring formula beyond that, so avoid assuming anything about weighted questions or partial credit. The safest planning assumption is simple: you need to be right on about seven of every ten questions you see.
Because the exam is multiple-choice rather than a hands-on lab, you are being tested on recognition and judgment: reading an alert description, a log excerpt, or a short scenario and choosing the best analyst action. The training labs that accompany the official course do not turn the certification exam into a practical assessment. For how this affects difficulty, see how hard the CSA exam is.
Where the Points Live: Domain Weights
The eight domain lines below are official weighted exam objectives from the Certified SOC Analyst (CSA) v2 Exam Blueprint. They total 100%.
| Domain | Weight | What it rewards |
|---|---|---|
| Security Operations and Management | 5% | SOC operations and maturity concepts |
| Understanding Cyber Threats, IoCs, and Attack Methodology | 8% | Recognizing indicators and attacker behavior |
| Log Management | 15% | Windows, Linux, Mac, network, and application logs |
| Incident Detection and Triage | 25% | SIEM use cases, alert triage, prioritization |
| Proactive Threat Detection | 12% | Threat intelligence and hunting |
| Incident Response | 25% | Response process, playbooks, containment decisions |
| Forensics Investigation and Malware Analysis | 5% | Evidence handling and malware basics |
| SOC for Cloud Environments | 5% | Azure, AWS, and GCP SOC monitoring |
Notice the shape. Incident Detection and Triage plus Incident Response account for 50% of the blueprint. Add Log Management at 15% and you reach 65%, and Proactive Threat Detection at 12% takes you to 77%. Four domains therefore hold more than three-quarters of the available weight, and a 70% passing score means those four are where the exam is won or lost.
The study examples attached to these domains, such as AI-generated SIEM rules or cloud SOC environments, are topics inside the eight published domains rather than extra weighted domains. For a deeper walk through each area, use the CSA study guide.
Format, Timing, and Delivery
The exam is remotely proctored and sold as the CSAv2 Exam Voucher - RPS through the EC-Council store. Testing is administered through the ECC Exam Centre and EC-Council Exam Portal. Three hours for 100 questions gives you an average of 108 seconds per question, which is generous for recognition-style items but tighter than it sounds if you linger on scenario questions that include log excerpts.
Pacing for a three-hour, 100-question exam
Use the time asymmetry to your advantage: short definitional questions should take well under a minute, which banks time for the scenario items.
- Answer fast on definition and process questions, then flag anything that needs a log or timeline read.
- Do a first pass through all 100 questions, then return to flagged items with the time you saved.
- Reserve the final stretch to re-read questions where two options looked plausible.
- Never leave an item blank; there is no stated reason to prefer an unanswered question.
Remember that the "three-day" figure you may see on training pages describes the course length. It is not the exam clock. Scheduling specifics, including testing windows and deadlines, are covered in CSA exam dates.
Before You Can Earn a Score: Eligibility and Cost
A passing score only matters once you have a voucher, and the path to a voucher has rules. The certification portal's CSA-specific eligibility provisions take precedence over the blanket suggestion on the training page FAQ that official training is mandatory. There are two routes:
- Official training route: You buy qualifying official courseware or training. The eligibility page states that official-training fees include the USD 100 application charge.
- Self-study route: You need one year of verified network-administration or security experience, an employer, supervisor, or department verifier, and you pay the USD 100 nonrefundable eligibility-application fee.
Approved eligibility provides a three-month window to purchase the voucher. The voucher itself is USD 450, non-transferable, and valid for one year. Candidates who are minors must follow the portal's additional parental-consent and educational-institution documentation rules.
If you are budgeting, the CSA certification cost breakdown lays out the combinations, and CSA requirements walks through qualifying step by step. Since a voucher expires after a year and a retake means planning around that clock, it pays to arrive ready; sample the format first with the free practice tests at CSA Exam Prep.
Winning the 50%: Triage and Incident Response
Because Incident Detection and Triage and Incident Response are 25% each, build your preparation around original scenarios rather than memorized lists. Here is the kind of reasoning each domain demands.
Incident Detection and Triage (25%)
Expect to judge alerts, not just define them. A typical scenario: a SIEM rule fires on repeated failed logons followed by one success from a new geography.
- Decide whether the pattern points to credential stuffing, a misconfigured service account, or a user traveling.
- Know which supporting data to pull next: authentication logs, VPN records, endpoint telemetry.
- Prioritize by asset criticality and likelihood of true positive, not by alert count.
- Understand SIEM use cases and how AI-assisted rule creation fits into rule design, including why generated rules still need analyst validation.
Incident Response (25%)
Here the question is usually "what should the analyst do next?" Scenario: a workstation shows signs of a commodity malware infection with outbound beaconing.
- Sequence the response phases correctly: preparation, identification, containment, eradication, recovery, lessons learned.
- Choose containment that preserves evidence, such as isolating the host rather than wiping it immediately.
- Recognize when a playbook applies and when escalation is the right answer.
- Know who gets notified and what gets documented at each stage.
When you practice, write your own two- or three-sentence scenarios like these and explain the correct action aloud. You are training the judgment the multiple-choice format tests. Domain-by-domain practice sets are available at the main practice site.
Log Management and Proactive Detection
Log Management (15%) and Proactive Threat Detection (12%) together add 27% and are where steady, concrete knowledge pays off.
Log Management
You should be comfortable reading and reasoning about Windows, Linux, and Mac logs as well as network and application logs. That means knowing what a given event source can and cannot tell you, how log collection and retention affect investigations, and how normalization lets a SIEM correlate across sources. A common exam-style trap is choosing an answer that sounds sophisticated when the plain answer is simply "check the authoritative log source."
Proactive Threat Detection
This domain covers threat intelligence and hunting. Know the difference between reactive alert handling and hypothesis-driven hunting, how indicators of compromise feed detection, and how threat intelligence is consumed and operationalized in a SOC. Questions here tend to reward understanding of purpose: why you hunt, what you need before you start, and what a good outcome looks like.
The Small Domains Still Matter
Security Operations and Management (5%), Forensics Investigation and Malware Analysis (5%), and SOC for Cloud Environments (5%) each look skippable. Together with Understanding Cyber Threats, IoCs, and Attack Methodology at 8%, they make up 23% of the blueprint. Since the passing line is 70%, ignoring that 23% leaves you needing near-perfection elsewhere.
Key Takeaway
You do not need to master the small domains, but you do need reliable baseline points from them: SOC maturity and operations vocabulary, core attacker-methodology and IoC concepts, evidence-handling and malware-analysis basics, and the monitoring differences across Azure, AWS, and GCP. Cheap, early points here reduce the pressure on the two big domains.
Setting Your Own Readiness Threshold
This article does not assert any certification-wide pass rate, and you should be skeptical of any site that does without citing EC-Council. For context on how to think about the question, see what the CSA pass-rate data does and doesn't show. Instead of relying on a population statistic, set a personal rule: do not book your exam until you are consistently scoring comfortably above 70% on each of the four heavy domains, not just overall.
If you want a schedule that respects the blueprint weights, this is one reasonable ordering:
Foundations and logs
- SOC operations, IoCs, and attack methodology (13% combined)
- Log Management across Windows, Linux, Mac, network, and application sources
The 50% block
- Incident Detection and Triage: SIEM use cases, alert prioritization
- Incident Response: phases, playbooks, containment decisions
Hunting, cloud, forensics, then full review
- Proactive Threat Detection, SOC for Cloud Environments, forensics basics
- Timed 100-question run-throughs against the three-hour limit
Triage and response get the most weeks because they carry the most points. The quick-reference CSA cheat sheet is useful for the final review pass.
After You Pass: Maintaining the Credential
Certification is maintained on a three-year cycle requiring 120 CPE/ECE credits, with a published USD 80 annual continuing-education fee, or USD 240 across three years. Paying the fee alone does not satisfy the credit requirement; you must earn the credits too.
Whether the effort pays off professionally is a separate question. SOC analyst roles have their own pay ranges, and there is no verified CSA-specific salary premium to quote, so treat any precise figure attached to the credential with caution. For an honest treatment, read the CSA salary guide and the analysis of whether the certification is worth it.
Frequently Asked Questions
The published passing score for the Certified SOC Analyst (CSA) v2 exam, 312-39, is 70%. The exam has 100 multiple-choice questions and a three-hour time limit.
The published figure is a single 70% passing score for the exam. EC-Council's public pages do not describe separate per-domain cut scores, but domain weights still determine where most of your points come from, with Incident Detection and Triage and Incident Response at 25% each.
No. It is a multiple-choice exam. The official training includes labs, but those labs do not make the certification exam a hands-on lab assessment.
The CSAv2 Exam Voucher - RPS is USD 450 and uses remote proctoring. Self-study applicants also pay a nonrefundable USD 100 eligibility-application fee, while official-training fees include the application charge. See the cost breakdown for combinations.
No. The USD 80 annual continuing-education fee is only part of maintenance. You also need 120 CPE/ECE credits over the three-year cycle, and paying the fee alone does not satisfy that requirement.