- Here, CSA means Certified SOC Analyst, an EC-Council credential tested through exam 312-39, version 2.
- The exam has 100 multiple-choice questions, a three-hour limit, and a 70% passing score.
- Incident Detection and Triage and Incident Response are 25% each, making half the blueprint.
- The remote-proctored voucher costs USD 450 and is non-transferable and valid for one year.
Why "CSA" Is a Crowded Acronym
Search for "CSA" and you will land in several unrelated corners of the professional world. Different industries, standards bodies, and certifying organizations have all claimed the same three letters, and a casual search result can send you toward a credential that has nothing to do with the one you actually want. That ambiguity is the reason this article exists: before you spend money or study hours, you need to know exactly which credential a given page is talking about.
The practical consequence is that facts do not transfer between credentials sharing an acronym. An exam fee, a duration, a passing threshold, or a list of content areas that is accurate for one "CSA" can be flatly wrong for another. Candidates who collect study materials from mixed sources sometimes discover, weeks in, that their notes describe a different exam. Treat the acronym as a prompt to verify the full name, the issuing body, and the exam code every single time.
What CSA Means on This Site
On this site, CSA stands for Certified SOC Analyst. It is a certification governed by EC-Council, aimed at people who work, or want to work, in a Security Operations Center (SOC). The current version is CSA v2, and the exam code is 312-39. If you want the short-form explanations of the term from other angles, our pages on what CSA stands for and what CSA certification is cover the same ground in a more compact form.
What the Credential Measures
The Certified SOC Analyst credential targets the day-to-day work of a SOC: watching telemetry, deciding which alerts matter, escalating real incidents, and supporting the response. It is a role-oriented credential rather than a broad theory exam. The blueprint reflects that emphasis by putting half of its weight on two activities: detecting and triaging incidents, and responding to them.
Preparation that maps well to the blueprint includes SOC operations and maturity, attack methodology and indicators of compromise, Windows, Linux, and Mac logs alongside network and application logs, SIEM use cases (including AI-generated rules), alert triage, threat intelligence and hunting, incident response and playbooks, forensics and malware analysis, and SOC work in Azure, AWS, and GCP environments. These are study examples inside the eight published domains, not extra weighted domains of their own.
One thing worth stating plainly: the three-day training description you may see on EC-Council pages describes course length, not the exam timer. And although training includes labs, the certification exam itself is a multiple-choice assessment, not a hands-on lab practical.
Exam Format and Fees at a Glance
| Item | Certified SOC Analyst (CSA) v2 |
|---|---|
| Exam code | 312-39 |
| Governing body | EC-Council |
| Question count and style | 100 multiple-choice questions |
| Time limit | Three hours |
| Passing score | 70% |
| Delivery | Remote proctoring through the EC-Council exam portal |
| Voucher price | USD 450 (CSAv2 Exam Voucher - RPS) |
| Voucher terms | Non-transferable, valid for one year |
Be careful with older or third-party material. Lists describing six domains belong to version 1, some third-party sites describe a four-domain split, and certain pages claim a two-hour exam. None of those describe the verified v2 scope. For deeper discussion of scoring, see our breakdown of the CSA passing score, and for the full money picture see the CSA certification cost breakdown.
How Eligibility Works
EC-Council gates this exam with an eligibility process, and the fee structure is where candidates most often get confused. There are two routes:
- Official training route. Purchase qualifying official training or courseware, and your eligibility follows from that purchase. The official-training fees already include the USD 100 application charge.
- Self-study route. You need one year of verified network-administration or security experience, an employer, supervisor, or department verifier, and a USD 100 nonrefundable eligibility-application fee.
Once an application is approved, you get a three-month window to purchase the voucher. That deadline matters: do not apply for eligibility until you are close to ready to schedule.
You may notice that the training-page FAQ suggests official training is mandatory in general terms. For this credential, the certification portal's CSA-specific eligibility provisions take precedence, and they include the self-study path. Candidates who are minors face additional rules, including parental-consent and educational-institution documentation requirements. Our guide to CSA requirements and eligibility walks through the application step by step.
The Eight Weighted Domains
The official blueprint, titled Certified SOC Analyst (CSA) v2 Exam Blueprint for exam 312-39, lists eight domains whose weights total 100%. These are official weighted exam objectives, not allocations derived from the curriculum.
| Domain | Weight |
|---|---|
| Domain 1: Security Operations and Management | 5% |
| Domain 2: Understanding Cyber Threats, IoCs, and Attack Methodology | 8% |
| Domain 3: Log Management | 15% |
| Domain 4: Incident Detection and Triage | 25% |
| Domain 5: Proactive Threat Detection | 12% |
| Domain 6: Incident Response | 25% |
| Domain 7: Forensics Investigation and Malware Analysis | 5% |
| Domain 8: SOC for Cloud Environments | 5% |
Domain 4: Incident Detection and Triage (25%)
This is where SOC work lives or dies. Expect to reason about which alerts deserve escalation and why.
- Reading SIEM alerts and deciding true positive versus false positive
- Prioritizing by asset criticality and likely attacker stage
- Recognizing how SIEM use cases and AI-generated rules change the alert stream you must triage
Domain 6: Incident Response (25%)
The other half of the heavy weighting. It covers what happens after an alert becomes an incident.
- Following incident response processes and playbooks
- Containment, eradication, and recovery decisions
- Coordinating communication and documentation during an incident
Domain 3: Log Management (15%)
The third-largest domain, and the foundation for Domain 4. You cannot triage what you cannot read.
- Understanding Windows, Linux, and Mac logs, plus network and application logs
- Knowing what each log source can and cannot tell you
- Connecting log fields to investigative questions
Domain 5, Proactive Threat Detection (12%), is where threat intelligence and hunting come in. The remaining domains, at 5% to 8% each, are smaller but still examined. Domain 2 covers attack methodology and indicators of compromise, which underpins good triage. For a domain-by-domain walkthrough, see the complete guide to all eight CSA content areas.
Key Takeaway
Domains 4 and 6 together are 50% of the blueprint. Build original practice scenarios around them first: a burst of failed logins followed by a successful one, a suspicious process spawned from an office application, a cloud console login from an unusual location. Walk each from alert to triage decision to response step.
Who Uses This Credential
The Certified SOC Analyst credential is relevant to entry- and mid-level SOC roles: tier 1 and tier 2 analysts, security monitoring staff, and people moving into a SOC from network or systems administration. Because the self-study route asks for one year of network-administration or security experience, it fits that transition path well. Employers filling SOC seats typically care about demonstrated skill with alert triage, log analysis, and incident handling, and a credential aligned to exactly those tasks can support a resume, particularly where an organization recognizes EC-Council certifications.
On compensation, stay disciplined. SOC analyst pay as an occupation is well documented elsewhere, but no CSA-specific salary premium is established here, and this article makes no claim about one. For a more careful treatment, read the CSA salary guide, and for a value-judgment framework see whether the CSA certification is worth it. If you are scanning for openings, our overview of CSA-related jobs is the place to start.
Sequencing Your Preparation by Weight
You do not need an elaborate study system; you need a sequence that respects the blueprint. A sensible order builds foundations first, then spends the most time where the points are.
Foundations: Domains 1, 2, and 3
- SOC roles, operations, and maturity concepts
- Attack methodology and indicators of compromise
- Log sources across Windows, Linux, Mac, network, and applications
The 25% core: Domain 4
- SIEM use cases and AI-assisted rule creation
- Alert triage and prioritization scenarios
The other 25%: Domains 5 and 6
- Threat intelligence and proactive hunting
- Incident response processes and playbooks
Remaining domains and review
- Forensics and malware analysis, plus cloud SOC (Azure, AWS, GCP)
- Timed practice with three-hour pacing in mind
Three hours for 100 questions leaves roughly 1.8 minutes per question on average, which is comfortable for recall questions but tighter for scenario-style items that require you to read logs or alert details. Practice at full length at least once so the pacing is familiar. For a broader plan, our CSA study guide covers the process in more depth, and the CSA cheat sheet is useful for last-pass review. When you are ready to test yourself, the CSA practice tests are built around the current blueprint with original explanations rather than leaked exam content.
Keeping the Credential Active
Passing is not the end of the cost story. The certification runs on a three-year cycle and requires 120 CPE/ECE credits over that period. There is also a published continuing-education fee of USD 80 per year, or USD 240 across three years. Paying the fee alone does not satisfy the continuing-education requirement; you must earn and report the credits too. Plan for both the money and the activity, such as training, conferences, publishing, or other qualifying learning, so renewal does not become a scramble in year three.
Frequently Asked Questions
It means Certified SOC Analyst, an EC-Council credential tested through exam 312-39, version 2. It is a SOC-focused certification, distinct from other credentials that share the same acronym.
The exam has 100 multiple-choice questions with a three-hour limit and a 70% passing score. The three-day training description refers to course length, not the exam timer.
No. The CSA-specific eligibility provisions allow a self-study route requiring one year of verified network-administration or security experience and a USD 100 nonrefundable application fee, with an employer, supervisor, or department verifier.
Incident Detection and Triage and Incident Response are each 25% of the blueprint, together 50%. Log Management follows at 15%. See the difficulty guide for how these weights affect preparation.
Maintenance runs on a three-year cycle with 120 CPE/ECE credits and a USD 80 annual continuing-education fee, USD 240 across three years. The fee alone does not satisfy the credit requirement.