CSA logo
Focused certification exam prep
Start practice

What Does CSA Mean?

TL;DR
  • Here, CSA means Certified SOC Analyst, an EC-Council credential tested through exam 312-39, version 2.
  • The exam has 100 multiple-choice questions, a three-hour limit, and a 70% passing score.
  • Incident Detection and Triage and Incident Response are 25% each, making half the blueprint.
  • The remote-proctored voucher costs USD 450 and is non-transferable and valid for one year.

Why "CSA" Is a Crowded Acronym

Search for "CSA" and you will land in several unrelated corners of the professional world. Different industries, standards bodies, and certifying organizations have all claimed the same three letters, and a casual search result can send you toward a credential that has nothing to do with the one you actually want. That ambiguity is the reason this article exists: before you spend money or study hours, you need to know exactly which credential a given page is talking about.

The practical consequence is that facts do not transfer between credentials sharing an acronym. An exam fee, a duration, a passing threshold, or a list of content areas that is accurate for one "CSA" can be flatly wrong for another. Candidates who collect study materials from mixed sources sometimes discover, weeks in, that their notes describe a different exam. Treat the acronym as a prompt to verify the full name, the issuing body, and the exam code every single time.

What CSA Means on This Site

On this site, CSA stands for Certified SOC Analyst. It is a certification governed by EC-Council, aimed at people who work, or want to work, in a Security Operations Center (SOC). The current version is CSA v2, and the exam code is 312-39. If you want the short-form explanations of the term from other angles, our pages on what CSA stands for and what CSA certification is cover the same ground in a more compact form.

A note on naming: The research behind this credential carries an "ECSA" acronym as supplied metadata, but the credential discussed here is Certified SOC Analyst, exam 312-39, version 2. It is not the EC-Council Security Analyst program or any other certification. When you see an exam code, use it as your anchor: 312-39 is the identifier that matters.

What the Credential Measures

The Certified SOC Analyst credential targets the day-to-day work of a SOC: watching telemetry, deciding which alerts matter, escalating real incidents, and supporting the response. It is a role-oriented credential rather than a broad theory exam. The blueprint reflects that emphasis by putting half of its weight on two activities: detecting and triaging incidents, and responding to them.

Preparation that maps well to the blueprint includes SOC operations and maturity, attack methodology and indicators of compromise, Windows, Linux, and Mac logs alongside network and application logs, SIEM use cases (including AI-generated rules), alert triage, threat intelligence and hunting, incident response and playbooks, forensics and malware analysis, and SOC work in Azure, AWS, and GCP environments. These are study examples inside the eight published domains, not extra weighted domains of their own.

One thing worth stating plainly: the three-day training description you may see on EC-Council pages describes course length, not the exam timer. And although training includes labs, the certification exam itself is a multiple-choice assessment, not a hands-on lab practical.

Exam Format and Fees at a Glance

ItemCertified SOC Analyst (CSA) v2
Exam code312-39
Governing bodyEC-Council
Question count and style100 multiple-choice questions
Time limitThree hours
Passing score70%
DeliveryRemote proctoring through the EC-Council exam portal
Voucher priceUSD 450 (CSAv2 Exam Voucher - RPS)
Voucher termsNon-transferable, valid for one year

Be careful with older or third-party material. Lists describing six domains belong to version 1, some third-party sites describe a four-domain split, and certain pages claim a two-hour exam. None of those describe the verified v2 scope. For deeper discussion of scoring, see our breakdown of the CSA passing score, and for the full money picture see the CSA certification cost breakdown.

How Eligibility Works

EC-Council gates this exam with an eligibility process, and the fee structure is where candidates most often get confused. There are two routes:

  1. Official training route. Purchase qualifying official training or courseware, and your eligibility follows from that purchase. The official-training fees already include the USD 100 application charge.
  2. Self-study route. You need one year of verified network-administration or security experience, an employer, supervisor, or department verifier, and a USD 100 nonrefundable eligibility-application fee.

Once an application is approved, you get a three-month window to purchase the voucher. That deadline matters: do not apply for eligibility until you are close to ready to schedule.

Three different purchases, not one: The USD 450 exam voucher, the USD 100 self-study application fee, and the separately listed USD 250 eCourseware are distinct items. The eCourseware is study material, not an exam voucher. If you choose official training, the application charge is already included; if you self-study, you pay it separately on top of the voucher.

You may notice that the training-page FAQ suggests official training is mandatory in general terms. For this credential, the certification portal's CSA-specific eligibility provisions take precedence, and they include the self-study path. Candidates who are minors face additional rules, including parental-consent and educational-institution documentation requirements. Our guide to CSA requirements and eligibility walks through the application step by step.

The Eight Weighted Domains

The official blueprint, titled Certified SOC Analyst (CSA) v2 Exam Blueprint for exam 312-39, lists eight domains whose weights total 100%. These are official weighted exam objectives, not allocations derived from the curriculum.

DomainWeight
Domain 1: Security Operations and Management5%
Domain 2: Understanding Cyber Threats, IoCs, and Attack Methodology8%
Domain 3: Log Management15%
Domain 4: Incident Detection and Triage25%
Domain 5: Proactive Threat Detection12%
Domain 6: Incident Response25%
Domain 7: Forensics Investigation and Malware Analysis5%
Domain 8: SOC for Cloud Environments5%

Domain 4: Incident Detection and Triage (25%)

This is where SOC work lives or dies. Expect to reason about which alerts deserve escalation and why.

  • Reading SIEM alerts and deciding true positive versus false positive
  • Prioritizing by asset criticality and likely attacker stage
  • Recognizing how SIEM use cases and AI-generated rules change the alert stream you must triage

Domain 6: Incident Response (25%)

The other half of the heavy weighting. It covers what happens after an alert becomes an incident.

  • Following incident response processes and playbooks
  • Containment, eradication, and recovery decisions
  • Coordinating communication and documentation during an incident

Domain 3: Log Management (15%)

The third-largest domain, and the foundation for Domain 4. You cannot triage what you cannot read.

  • Understanding Windows, Linux, and Mac logs, plus network and application logs
  • Knowing what each log source can and cannot tell you
  • Connecting log fields to investigative questions

Domain 5, Proactive Threat Detection (12%), is where threat intelligence and hunting come in. The remaining domains, at 5% to 8% each, are smaller but still examined. Domain 2 covers attack methodology and indicators of compromise, which underpins good triage. For a domain-by-domain walkthrough, see the complete guide to all eight CSA content areas.

Key Takeaway

Domains 4 and 6 together are 50% of the blueprint. Build original practice scenarios around them first: a burst of failed logins followed by a successful one, a suspicious process spawned from an office application, a cloud console login from an unusual location. Walk each from alert to triage decision to response step.

Who Uses This Credential

The Certified SOC Analyst credential is relevant to entry- and mid-level SOC roles: tier 1 and tier 2 analysts, security monitoring staff, and people moving into a SOC from network or systems administration. Because the self-study route asks for one year of network-administration or security experience, it fits that transition path well. Employers filling SOC seats typically care about demonstrated skill with alert triage, log analysis, and incident handling, and a credential aligned to exactly those tasks can support a resume, particularly where an organization recognizes EC-Council certifications.

On compensation, stay disciplined. SOC analyst pay as an occupation is well documented elsewhere, but no CSA-specific salary premium is established here, and this article makes no claim about one. For a more careful treatment, read the CSA salary guide, and for a value-judgment framework see whether the CSA certification is worth it. If you are scanning for openings, our overview of CSA-related jobs is the place to start.

Sequencing Your Preparation by Weight

You do not need an elaborate study system; you need a sequence that respects the blueprint. A sensible order builds foundations first, then spends the most time where the points are.

Weeks 1-2

Foundations: Domains 1, 2, and 3

  • SOC roles, operations, and maturity concepts
  • Attack methodology and indicators of compromise
  • Log sources across Windows, Linux, Mac, network, and applications
Weeks 3-4

The 25% core: Domain 4

  • SIEM use cases and AI-assisted rule creation
  • Alert triage and prioritization scenarios
Weeks 5-6

The other 25%: Domains 5 and 6

  • Threat intelligence and proactive hunting
  • Incident response processes and playbooks
Week 7

Remaining domains and review

  • Forensics and malware analysis, plus cloud SOC (Azure, AWS, GCP)
  • Timed practice with three-hour pacing in mind

Three hours for 100 questions leaves roughly 1.8 minutes per question on average, which is comfortable for recall questions but tighter for scenario-style items that require you to read logs or alert details. Practice at full length at least once so the pacing is familiar. For a broader plan, our CSA study guide covers the process in more depth, and the CSA cheat sheet is useful for last-pass review. When you are ready to test yourself, the CSA practice tests are built around the current blueprint with original explanations rather than leaked exam content.

Keeping the Credential Active

Passing is not the end of the cost story. The certification runs on a three-year cycle and requires 120 CPE/ECE credits over that period. There is also a published continuing-education fee of USD 80 per year, or USD 240 across three years. Paying the fee alone does not satisfy the continuing-education requirement; you must earn and report the credits too. Plan for both the money and the activity, such as training, conferences, publishing, or other qualifying learning, so renewal does not become a scramble in year three.

Frequently Asked Questions

What does CSA mean in this context?

It means Certified SOC Analyst, an EC-Council credential tested through exam 312-39, version 2. It is a SOC-focused certification, distinct from other credentials that share the same acronym.

How many questions are on the exam and how long do I have?

The exam has 100 multiple-choice questions with a three-hour limit and a 70% passing score. The three-day training description refers to course length, not the exam timer.

Is official training required to sit the exam?

No. The CSA-specific eligibility provisions allow a self-study route requiring one year of verified network-administration or security experience and a USD 100 nonrefundable application fee, with an employer, supervisor, or department verifier.

Which domains matter most?

Incident Detection and Triage and Incident Response are each 25% of the blueprint, together 50%. Log Management follows at 15%. See the difficulty guide for how these weights affect preparation.

What does it cost to maintain the certification?

Maintenance runs on a three-year cycle with 120 CPE/ECE credits and a USD 80 annual continuing-education fee, USD 240 across three years. The fee alone does not satisfy the credit requirement.

Ready to pass your CSA exam?

Put this into practice with free CSA questions across every exam domain.