- What CSA Means Here: Certified SOC Analyst
- Who Issues It and What the Exam Looks Like
- The Eight Blueprint Domains and Their Weights
- Why Detection/Triage and Incident Response Dominate
- Concrete Topics a Candidate Must Master
- Eligibility, Fees and Voucher Mechanics
- Who Hires CSA Holders and What the Role Involves
- CSA Compared With CySA+
- Sequencing Your Preparation Around the Weights
- Keeping the Credential Active
- Frequently Asked Questions
- CSA here means Certified SOC Analyst, EC-Council's version 2 credential tested through exam 312-39.
- The exam has 100 multiple-choice questions, a three-hour limit and a 70% passing score.
- Incident Detection and Triage and Incident Response are 25% each, making half the blueprint.
- The remote-proctored voucher costs USD 450; self-study applicants also pay a USD 100 nonrefundable application fee.
What CSA Means Here: Certified SOC Analyst
The acronym CSA is shared by several unrelated credentials across the IT and security industry, which is a frequent source of confusion when people search for it. On this site, and in this article, CSA means Certified SOC Analyst, an entry-to-intermediate security operations credential from EC-Council. It validates that a candidate can work inside a Security Operations Center: watching alerts, reading logs, triaging incidents, escalating correctly and participating in response.
The current release is Certified SOC Analyst version 2, and the associated exam code is 312-39. If you have seen older material describing a six-domain structure or a shorter exam, that describes the earlier version and not the one you would sit today. For a deeper look at the naming question, see our explainer on what CSA stands for and the broader overview of what CSA certification is.
Who Issues It and What the Exam Looks Like
EC-Council is the governing body. The exam is delivered through the ECC Exam Centre / EC-Council Exam Portal, and the standard voucher is remotely proctored, so you test from your own location under supervision rather than traveling to a test center.
| Exam Attribute | Certified SOC Analyst (312-39) |
|---|---|
| Version | CSA v2 |
| Format | 100 multiple-choice questions |
| Time limit | Three hours |
| Passing score | 70% |
| Delivery | Remote proctoring through EC-Council's exam portal |
| Voucher price | USD 450 (CSAv2 Exam Voucher - RPS) |
| Voucher validity | One year, non-transferable |
One point deserves emphasis: the official training course is described as three days long, but that is the length of the class, not the exam timer. Likewise, although the training includes labs, the certification exam itself is a multiple-choice test, not a hands-on lab assessment. You are being tested on recognition, interpretation and decision-making from scenario-style questions. For more on how that affects difficulty, read how hard the CSA exam is, and for the scoring threshold specifically, see the CSA passing score breakdown.
The Eight Blueprint Domains and Their Weights
The published document is titled Certified SOC Analyst (CSA) v2 Exam Blueprint for exam 312-39. It lists eight weighted domains that total 100%. These weights are the official exam objectives, so they are the best guide to where your study hours should go.
| Domain | Weight |
|---|---|
| Domain 1: Security Operations and Management | 5% |
| Domain 2: Understanding Cyber Threats, IoCs, and Attack Methodology | 8% |
| Domain 3: Log Management | 15% |
| Domain 4: Incident Detection and Triage | 25% |
| Domain 5: Proactive Threat Detection | 12% |
| Domain 6: Incident Response | 25% |
| Domain 7: Forensics Investigation and Malware Analysis | 5% |
| Domain 8: SOC for Cloud Environments | 5% |
Our full walkthrough of each content area lives in the CSA exam domains guide; the sections below focus on what the weights imply for your preparation.
Why Detection/Triage and Incident Response Dominate
Incident Detection and Triage and Incident Response each carry 25%, which together account for half of the blueprint. That split mirrors the actual job: most of a SOC analyst's day is deciding whether an alert is real, how severe it is, and what to do next. If you are weak in these two areas, strength elsewhere is unlikely to rescue your score.
Domain 4: Incident Detection and Triage (25%)
This domain tests whether you can look at an alert and make a sound judgment call.
- Distinguishing true positives from false positives using supporting evidence
- Using SIEM use cases and correlating events across multiple sources
- Understanding AI-generated detection rules and when they need human validation
- Prioritizing alerts by asset criticality, context and likely impact
- Knowing when and how to escalate
Domain 6: Incident Response (25%)
This domain covers what happens after an alert is confirmed as an incident.
- Following the incident response lifecycle from preparation through lessons learned
- Applying playbooks consistently for common incident types
- Containment, eradication and recovery decisions and their trade-offs
- Coordination, communication and documentation during an incident
Concrete Topics a Candidate Must Master
The blueprint's eight domains map to a recognizable set of study areas. These are examples within the published domains, not extra weighted categories.
Logs and SIEM
Log Management is the third-heaviest domain at 15%, and it underpins everything in triage. Expect to interpret logs from Windows, Linux and Mac systems as well as network and application sources. The skill being tested is not memorizing event IDs in isolation but recognizing what a log pattern suggests: brute force, lateral movement, persistence, data staging. You also need to understand how SIEM platforms collect, normalize and correlate events, and how use cases translate into detection logic.
Threats, IoCs and Attack Methodology
Domain 2 is only 8%, but its vocabulary shows up inside triage and response questions. Know the stages of an attack, how indicators of compromise differ from indicators of attack, and how adversary behavior maps to what you would see in telemetry.
Proactive Threat Detection
At 12%, Domain 5 covers threat intelligence and threat hunting. Candidates should understand how intelligence feeds are consumed and operationalized, and how a hunt differs from reactive alert handling: it starts with a hypothesis rather than a fired rule.
Forensics, Malware and Cloud
Forensics Investigation and Malware Analysis (5%) and SOC for Cloud Environments (5%) are small individually but easy points if prepared. Expect evidence handling concepts, basic malware analysis ideas, and monitoring considerations across Azure, AWS and GCP. Security Operations and Management (5%) rounds things out with SOC roles, processes and maturity concepts.
Key Takeaway
Do not treat the 5% domains as skippable. Together, Domains 1, 7 and 8 are 15% of the exam, equivalent to the entire Log Management domain, and they are usually the most straightforward to learn by reading.
Eligibility, Fees and Voucher Mechanics
EC-Council offers two routes to sit the exam, and the costs differ depending on which you take. The CSA-specific provisions on the certification portal take precedence over the blanket statement on the training page that official training is mandatory.
| Route | What You Need | Cost Notes |
|---|---|---|
| Official training / qualifying official courseware | Complete the official training or purchase qualifying official courseware | Official-training fees include the USD 100 application charge; the exam voucher is separate |
| Self-study | One year of verified network-administration or security experience, confirmed by an employer, supervisor or department verifier | USD 100 nonrefundable eligibility application fee, plus the USD 450 voucher |
Several details trip candidates up:
- Approved self-study eligibility gives you a three-month window to purchase the voucher, so do not apply until you are close to ready.
- The separately listed USD 250 eCourseware purchase is not an exam voucher. Buying it does not by itself let you test.
- The voucher is non-transferable and valid for one year.
- Applicants who are minors must follow additional parental-consent and educational-institution documentation rules on the portal.
For the full breakdown of what you will pay, see the CSA certification cost guide, and for the qualification paperwork, the CSA requirements guide.
Who Hires CSA Holders and What the Role Involves
The credential targets people who work or want to work as SOC analysts, typically Tier 1 and Tier 2, along with related roles such as security monitoring analysts, incident responders in training and network or system administrators moving toward security. Employers hiring for these roles include managed security service providers, enterprise security teams, government and defense contractors, and organizations running in-house SOCs.
A typical day involves monitoring a SIEM queue, validating alerts against log evidence, documenting findings, following playbooks and escalating confirmed incidents. The certification maps closely to those tasks, which is why its two largest domains focus on triage and response. For listings and role titles, see our overview of CSA-related jobs.
CSA Compared With CySA+
Candidates often weigh Certified SOC Analyst against CompTIA CySA+, since both address analyst-level security work. They come from different certifying bodies and differ in structure, so compare the current official exam pages for each rather than assuming equivalence.
| Consideration | Certified SOC Analyst (312-39) |
|---|---|
| Issuer | EC-Council |
| Center of gravity | SOC workflow: log management, triage and incident response (65% across Domains 3, 4 and 6) |
| Format | 100 multiple-choice questions in three hours |
| Distinctive v2 content | AI-generated rule creation, proactive threat hunting, cloud SOC environments |
If your goal is specifically a SOC-floor role and you want a blueprint organized around that workflow, the CSA blueprint is explicit about it. Check CySA+'s published objectives directly if you are considering it, rather than relying on secondhand summaries.
Sequencing Your Preparation Around the Weights
You do not need an elaborate method here; you need an order that follows the weights. One reasonable approach for a candidate with some networking background:
Foundations: Domains 1 and 2
- SOC roles, processes and maturity concepts
- Attack stages, IoCs and adversary behavior
Log Management: Domain 3 (15%)
- Windows, Linux, Mac, network and application log sources
- SIEM collection, normalization and correlation
The 25% core: Domains 4 and 6
- Alert triage scenarios and escalation decisions
- Incident response lifecycle and playbooks
Remaining domains and review
- Threat intelligence and hunting (Domain 5)
- Forensics, malware analysis and cloud SOC (Domains 7 and 8)
- Timed practice sets to rehearse the three-hour pace
Logs come before triage because you cannot judge an alert without reading the evidence behind it. Leave your timed practice for the end so that pacing, roughly a little under two minutes per question on average, is tested once you know the material. Our CSA study guide expands this into a fuller plan, and the CSA cheat sheet works well for final review. When you are ready to test yourself, try the practice exams, which use original scenario questions rather than recalled exam content.
Key Takeaway
Schedule your heaviest study blocks for Domains 3, 4 and 6, which together are 65% of the blueprint. Cover everything else, but never at the expense of these three.
Keeping the Credential Active
Certified SOC Analyst runs on a three-year cycle. To maintain it you need 120 CPE/ECE credits in that period, and EC-Council publishes a USD 80 annual continuing-education fee, which is USD 240 across three years. Paying the fee alone does not satisfy the credit requirement; you must earn and report the credits as well. Plan your renewal costs and activities from day one rather than in the final year. For exam scheduling and windows, see the CSA exam dates guide.
As for how many candidates pass, no certification-wide pass rate is asserted here. Our pass rate discussion explains what can and cannot be said from available data.
Frequently Asked Questions
It means Certified SOC Analyst from EC-Council, version 2, exam 312-39. Other credentials share the acronym, but none of their details apply here.
The exam has 100 multiple-choice questions with a three-hour limit and a 70% passing score. The three-day figure you may see refers to the training course, not the exam.
Not necessarily. The CSA-specific eligibility provisions allow a self-study route requiring one year of verified network-administration or security experience and a USD 100 nonrefundable application fee, in addition to the USD 450 voucher.
Incident Detection and Triage and Incident Response are 25% each, for 50% combined. Log Management follows at 15%, then Proactive Threat Detection at 12%.
No. Training labs exist, but the certification exam is multiple-choice, so preparation should emphasize interpreting logs, alerts and scenarios in written form.
Over a three-year cycle you need 120 CPE/ECE credits and must pay the USD 80 annual continuing-education fee. The fee alone does not satisfy the credit requirement.