CSA logo
Focused certification exam prep
Start practice

What Is A CSA?

TL;DR
  • CSA here means Certified SOC Analyst (v2, exam 312-39), issued by EC-Council, not any other credential sharing the acronym.
  • The exam is 100 multiple-choice questions in three hours with a 70% passing score, delivered by remote proctoring.
  • Incident Detection and Triage and Incident Response are 25% each, so half the blueprint sits in two domains.
  • The voucher costs USD 450; self-study applicants also pay a USD 100 nonrefundable eligibility fee and need one year of experience.

What "CSA" Means on This Site

Search for "What is a CSA?" and you will find a crowded field. The same three letters are used by several unrelated credentials and job titles across cloud security, agile practice, and other industries. This article is about exactly one of them: the Certified SOC Analyst credential from EC-Council, currently in its second version (CSA v2), tested through exam code 312-39.

If you landed here looking for a different certification that shares the acronym, nothing below will apply to it. Fees, exam length, domain weights, and renewal rules described in this article belong only to the Certified SOC Analyst program. For other angles on the same question, you can also browse our explainers on what CSA stands for and CSA meaning.

What the Certified SOC Analyst Credential Is

The Certified SOC Analyst credential validates that a candidate understands the daily work of a Security Operations Center: monitoring telemetry, recognizing malicious activity, triaging alerts, escalating or containing incidents, and feeding lessons back into detection. It is positioned as an entry-to-intermediate certification for people who work, or want to work, in a SOC.

The version 2 blueprint, titled Certified SOC Analyst (CSA) v2 Exam Blueprint, reflects how modern SOCs operate. Beyond classic alert handling, it covers SIEM use cases (including AI-generated detection rules), proactive threat hunting, and SOC work in Azure, AWS, and GCP environments. Older six-domain descriptions of v1 you may see on third-party sites do not describe the current scope.

Training is not the exam: EC-Council's training course is described as a three-day program, and it includes labs. That three-day figure is course duration only. It is not the examination timer, and the labs do not turn the certification exam into a hands-on practical. The exam itself is multiple-choice.

The 312-39 Exam Format

The mechanics are simple, which lets you focus preparation on content instead of logistics.

AttributeCertified SOC Analyst (312-39)
Issuing bodyEC-Council
Question count100 multiple-choice questions
Time limitThree hours
Passing score70%
DeliveryRemote proctoring (voucher: CSAv2 Exam Voucher - RPS)
Voucher priceUSD 450
Voucher validityOne year, non-transferable

Three hours for 100 questions averages out to roughly 108 seconds per item. That is generous for recall questions but tighter for scenario-style items that ask you to interpret a log excerpt or choose the correct next response step. For a closer look at the cut line, see our breakdown of the CSA passing score, and for realistic expectations on difficulty, read how hard the CSA exam is.

You should be wary of any source claiming a two-hour limit or a different question count. Those claims do not match the verified v2 exam details.

The Eight Domains and What They Test

The official blueprint publishes eight weighted domains totaling 100%. The weights are official exam objectives, which makes them the best guide for allocating study time. Our complete guide to all eight CSA content areas goes deeper; here is the overview.

DomainWeight
Security Operations and Management5%
Understanding Cyber Threats, IoCs, and Attack Methodology8%
Log Management15%
Incident Detection and Triage25%
Proactive Threat Detection12%
Incident Response25%
Forensics Investigation and Malware Analysis5%
SOC for Cloud Environments5%

Security Operations and Management (5%)

The organizational layer: how a SOC is structured and how mature it is.

  • SOC operations, roles, and maturity concepts
  • How people, process, and technology fit together

Understanding Cyber Threats, IoCs, and Attack Methodology (8%)

The vocabulary of adversary behavior that every later domain depends on.

  • Attack methodology and the stages of an intrusion
  • Indicators of compromise and how they appear in telemetry

Log Management (15%)

The evidence layer. You cannot triage what you cannot read.

  • Windows, Linux, and Mac logs
  • Network and application logs
  • Collection, normalization, and centralization concepts

Proactive Threat Detection (12%)

Moving from waiting for alerts to looking for adversaries.

  • Threat intelligence consumption
  • Threat hunting concepts
  • SIEM use cases, including AI-generated rules in v2

Forensics Investigation and Malware Analysis (5%)

A small but conceptually distinct slice covering evidence handling and the basics of analyzing malicious code.

SOC for Cloud Environments (5%)

How monitoring and response change when workloads live in Azure, AWS, and GCP.

Note that items like SIEM use cases or malware analysis are study topics inside the eight published domains. They are not extra weighted domains of their own.

Where the Marks Are: Triage and Response

Incident Detection and Triage and Incident Response are each 25%, together representing half of the entire blueprint. Because the weights are so lopsided, a candidate who is strong here and merely adequate elsewhere is in a far better position than one who spreads effort evenly.

Incident Detection and Triage in practice

Expect questions framed around a SOC analyst's queue. A typical scenario might describe an alert firing on a burst of failed authentications followed by a success from an unfamiliar location, then ask what you should verify first or how to prioritize it against other open alerts. Skills worth drilling:

  • Separating true positives from false positives using context, not just the alert title
  • Prioritizing by asset criticality, scope, and confidence
  • Correlating events across log sources inside a SIEM
  • Recognizing IoCs in raw log lines and knowing which source would confirm them

Incident Response in practice

Response questions test whether you know the sequence and the reasoning behind it: preparation, identification, containment, eradication, recovery, and lessons learned, along with playbooks that standardize those steps. A scenario might present a confirmed compromised endpoint and ask which action preserves evidence while limiting spread. Know why containment decisions differ for a single workstation versus a domain controller, and how communication and documentation fit in.

Key Takeaway

Practice by writing your own mini-scenarios for these two domains: take a log excerpt, decide whether it is malicious, state the evidence, then list your first three response actions. This builds the judgment these 25% domains reward far better than rereading definitions. You can pressure-test it with questions on our CSA practice test site.

Eligibility Routes and the Real Cost Structure

Cost confusion is the most common stumbling block, so it helps to separate the line items clearly. For a fuller breakdown, see our CSA certification cost guide and the CSA requirements and eligibility overview.

Two routes to sit the exam

  • Official training route: You qualify by purchasing qualifying official EC-Council courseware or training. The USD 100 application charge is included in official-training fees.
  • Self-study route: You need one year of verified experience in network administration or security, an employer, supervisor, or department verifier, and you must pay a USD 100 nonrefundable eligibility-application fee. Approval opens a three-month window in which to buy the voucher.

The certification portal's CSA-specific eligibility provisions take precedence over the more blanket suggestion on the training page's FAQ that official training is mandatory. Applicants who are minors must also follow the portal's extra parental-consent and educational-institution documentation requirements.

What each charge actually is

ItemAmountWhat it is
CSAv2 Exam Voucher - RPSUSD 450The exam attempt itself, remotely proctored
Self-study eligibility applicationUSD 100Nonrefundable; only for the self-study route
eCoursewareUSD 250Study material only; not an exam voucher
Do not confuse the eCourseware with the voucher: The separately listed USD 250 eCourseware is a learning product. Buying it does not buy you an exam attempt. Likewise, a self-study applicant pays the USD 100 application and the USD 450 voucher as distinct charges, and the voucher is valid for one year and cannot be transferred to someone else.

If you are planning timing around deadlines and windows, our CSA exam dates guide covers scheduling considerations.

Who Should Pursue It and Who Hires for It

The credential fits people moving toward or already inside security monitoring roles: aspiring Tier 1 and Tier 2 SOC analysts, IT administrators transitioning into security, help-desk or network staff cross-training, and junior incident handlers. Employers that run or outsource security monitoring, such as managed security service providers, enterprise security teams, government contractors, and large IT services firms, are the typical audiences for SOC-analyst talent, and a role-aligned certification is one way to signal readiness.

A caution on expectations: general SOC analyst compensation is well documented in occupational data, but there is no basis here to claim a CSA-specific salary premium. Treat the credential as evidence of skills and a foot in the door rather than a guaranteed pay bump. Our CSA salary guide and analysis of whether the certification is worth it frame this honestly, and CSA jobs covers the role landscape.

Candidates often compare it with CompTIA's CySA+. They are different credentials from different bodies with different exams, so compare the blueprints, formats, and costs rather than assuming equivalence.

A Domain-Weighted Preparation Plan

Rather than a generic schedule, sequence your study by dependency and weight. Logs and threat concepts come first because triage and response depend on them. For deeper method, see our CSA study guide.

Weeks 1-2

Foundations and evidence

  • Security Operations and Management, plus threats, IoCs, and attack methodology
  • Log Management: read real Windows, Linux, and network log samples until the fields feel familiar
Weeks 3-4

The 25% domain: triage

  • SIEM correlation and use cases, including how AI-generated rules are reviewed
  • Daily alert-triage drills: classify, prioritize, justify
Weeks 5-6

The other 25% domain: response

  • Playbooks and the response lifecycle
  • Proactive Threat Detection: threat intelligence and hunting hypotheses
Week 7

Small domains and review

  • Forensics and malware analysis basics; Azure, AWS, and GCP SOC concepts
  • Timed practice sets to rehearse the three-hour pace

A one-page recap can help in the final days; our CSA cheat sheet is built for that. Use original practice questions and explanations rather than leaked exam content, which is unreliable and undermines the credential's value. The main practice test offers original scenario-based items aligned to the eight domains. Curious about outcomes? Our piece on the CSA pass rate explains what can and cannot be said from available data.

Keeping the Certification Active

Passing is not the end of the obligation. The certification runs on a three-year cycle, and holders must earn 120 CPE/ECE credits across that period. There is also a published continuing-education fee of USD 80 per year, or USD 240 over three years.

Paying is not the same as qualifying: The annual fee does not satisfy the credit requirement. You need both the fee and the 120 documented credits, so start logging activities such as training, conferences, and relevant projects early rather than scrambling in year three.

Frequently Asked Questions

What is a CSA in cybersecurity?

On this site, CSA means Certified SOC Analyst, an EC-Council certification (v2, exam 312-39) that validates skills in SOC monitoring, alert triage, log analysis, threat detection, and incident response.

How many questions are on the CSA exam, and how long do I have?

The exam has 100 multiple-choice questions with a three-hour time limit. The passing score is 70%, and it is delivered through remote proctoring.

Do I have to take the official training to sit the exam?

Not necessarily. There is an official-training route and a self-study route. Self-study applicants need one year of verified network-administration or security experience, a verifier, and the USD 100 nonrefundable application fee, then have three months to buy the USD 450 voucher.

Which domains matter most for the CSA exam?

Incident Detection and Triage and Incident Response are each 25%, together half the blueprint. Log Management follows at 15%, then Proactive Threat Detection at 12%.

How do I keep the CSA certification current?

Maintain it on a three-year cycle by earning 120 CPE/ECE credits and paying the USD 80 annual continuing-education fee (USD 240 over three years). The fee alone does not meet the credit requirement.

Ready to pass your CSA exam?

Put this into practice with free CSA questions across every exam domain.