CSA logo
Focused certification exam prep
Start practice

What Is CSA?

TL;DR
  • CSA here means Certified SOC Analyst, EC-Council's version 2 credential tested through exam 312-39.
  • The exam has 100 multiple-choice questions, a three-hour limit and a 70% passing score.
  • Incident Detection and Triage and Incident Response are 25% each, making half the blueprint.
  • The remote-proctored voucher costs USD 450; self-study applicants also pay a USD 100 nonrefundable application fee.

What CSA Means Here: Certified SOC Analyst

The acronym CSA is shared by several unrelated credentials across the IT and security industry, which is a frequent source of confusion when people search for it. On this site, and in this article, CSA means Certified SOC Analyst, an entry-to-intermediate security operations credential from EC-Council. It validates that a candidate can work inside a Security Operations Center: watching alerts, reading logs, triaging incidents, escalating correctly and participating in response.

The current release is Certified SOC Analyst version 2, and the associated exam code is 312-39. If you have seen older material describing a six-domain structure or a shorter exam, that describes the earlier version and not the one you would sit today. For a deeper look at the naming question, see our explainer on what CSA stands for and the broader overview of what CSA certification is.

Why the distinction matters: Exam fees, domain weights, certifying bodies and renewal rules differ completely between credentials that share this acronym. Everything in this article applies only to the Certified SOC Analyst exam 312-39. Always confirm details against EC-Council's own certification pages before you pay for anything.

Who Issues It and What the Exam Looks Like

EC-Council is the governing body. The exam is delivered through the ECC Exam Centre / EC-Council Exam Portal, and the standard voucher is remotely proctored, so you test from your own location under supervision rather than traveling to a test center.

Exam AttributeCertified SOC Analyst (312-39)
VersionCSA v2
Format100 multiple-choice questions
Time limitThree hours
Passing score70%
DeliveryRemote proctoring through EC-Council's exam portal
Voucher priceUSD 450 (CSAv2 Exam Voucher - RPS)
Voucher validityOne year, non-transferable

One point deserves emphasis: the official training course is described as three days long, but that is the length of the class, not the exam timer. Likewise, although the training includes labs, the certification exam itself is a multiple-choice test, not a hands-on lab assessment. You are being tested on recognition, interpretation and decision-making from scenario-style questions. For more on how that affects difficulty, read how hard the CSA exam is, and for the scoring threshold specifically, see the CSA passing score breakdown.

The Eight Blueprint Domains and Their Weights

The published document is titled Certified SOC Analyst (CSA) v2 Exam Blueprint for exam 312-39. It lists eight weighted domains that total 100%. These weights are the official exam objectives, so they are the best guide to where your study hours should go.

DomainWeight
Domain 1: Security Operations and Management5%
Domain 2: Understanding Cyber Threats, IoCs, and Attack Methodology8%
Domain 3: Log Management15%
Domain 4: Incident Detection and Triage25%
Domain 5: Proactive Threat Detection12%
Domain 6: Incident Response25%
Domain 7: Forensics Investigation and Malware Analysis5%
Domain 8: SOC for Cloud Environments5%

Our full walkthrough of each content area lives in the CSA exam domains guide; the sections below focus on what the weights imply for your preparation.

Why Detection/Triage and Incident Response Dominate

Incident Detection and Triage and Incident Response each carry 25%, which together account for half of the blueprint. That split mirrors the actual job: most of a SOC analyst's day is deciding whether an alert is real, how severe it is, and what to do next. If you are weak in these two areas, strength elsewhere is unlikely to rescue your score.

Domain 4: Incident Detection and Triage (25%)

This domain tests whether you can look at an alert and make a sound judgment call.

  • Distinguishing true positives from false positives using supporting evidence
  • Using SIEM use cases and correlating events across multiple sources
  • Understanding AI-generated detection rules and when they need human validation
  • Prioritizing alerts by asset criticality, context and likely impact
  • Knowing when and how to escalate

Domain 6: Incident Response (25%)

This domain covers what happens after an alert is confirmed as an incident.

  • Following the incident response lifecycle from preparation through lessons learned
  • Applying playbooks consistently for common incident types
  • Containment, eradication and recovery decisions and their trade-offs
  • Coordination, communication and documentation during an incident
A practical scenario to rehearse: A SIEM alert fires for repeated failed logons followed by one success from an unfamiliar external address on a privileged account. Ask yourself: what additional logs would confirm compromise, what is the immediate containment step, and who needs to be told? Working through original scenarios like this builds the judgment these two domains reward. Our CSA practice tests are built around that style of reasoning.

Concrete Topics a Candidate Must Master

The blueprint's eight domains map to a recognizable set of study areas. These are examples within the published domains, not extra weighted categories.

Logs and SIEM

Log Management is the third-heaviest domain at 15%, and it underpins everything in triage. Expect to interpret logs from Windows, Linux and Mac systems as well as network and application sources. The skill being tested is not memorizing event IDs in isolation but recognizing what a log pattern suggests: brute force, lateral movement, persistence, data staging. You also need to understand how SIEM platforms collect, normalize and correlate events, and how use cases translate into detection logic.

Threats, IoCs and Attack Methodology

Domain 2 is only 8%, but its vocabulary shows up inside triage and response questions. Know the stages of an attack, how indicators of compromise differ from indicators of attack, and how adversary behavior maps to what you would see in telemetry.

Proactive Threat Detection

At 12%, Domain 5 covers threat intelligence and threat hunting. Candidates should understand how intelligence feeds are consumed and operationalized, and how a hunt differs from reactive alert handling: it starts with a hypothesis rather than a fired rule.

Forensics, Malware and Cloud

Forensics Investigation and Malware Analysis (5%) and SOC for Cloud Environments (5%) are small individually but easy points if prepared. Expect evidence handling concepts, basic malware analysis ideas, and monitoring considerations across Azure, AWS and GCP. Security Operations and Management (5%) rounds things out with SOC roles, processes and maturity concepts.

Key Takeaway

Do not treat the 5% domains as skippable. Together, Domains 1, 7 and 8 are 15% of the exam, equivalent to the entire Log Management domain, and they are usually the most straightforward to learn by reading.

Eligibility, Fees and Voucher Mechanics

EC-Council offers two routes to sit the exam, and the costs differ depending on which you take. The CSA-specific provisions on the certification portal take precedence over the blanket statement on the training page that official training is mandatory.

RouteWhat You NeedCost Notes
Official training / qualifying official coursewareComplete the official training or purchase qualifying official coursewareOfficial-training fees include the USD 100 application charge; the exam voucher is separate
Self-studyOne year of verified network-administration or security experience, confirmed by an employer, supervisor or department verifierUSD 100 nonrefundable eligibility application fee, plus the USD 450 voucher

Several details trip candidates up:

  • Approved self-study eligibility gives you a three-month window to purchase the voucher, so do not apply until you are close to ready.
  • The separately listed USD 250 eCourseware purchase is not an exam voucher. Buying it does not by itself let you test.
  • The voucher is non-transferable and valid for one year.
  • Applicants who are minors must follow additional parental-consent and educational-institution documentation rules on the portal.

For the full breakdown of what you will pay, see the CSA certification cost guide, and for the qualification paperwork, the CSA requirements guide.

Who Hires CSA Holders and What the Role Involves

The credential targets people who work or want to work as SOC analysts, typically Tier 1 and Tier 2, along with related roles such as security monitoring analysts, incident responders in training and network or system administrators moving toward security. Employers hiring for these roles include managed security service providers, enterprise security teams, government and defense contractors, and organizations running in-house SOCs.

A typical day involves monitoring a SIEM queue, validating alerts against log evidence, documenting findings, following playbooks and escalating confirmed incidents. The certification maps closely to those tasks, which is why its two largest domains focus on triage and response. For listings and role titles, see our overview of CSA-related jobs.

On pay: SOC analyst compensation is well documented as an occupation, but there is no reliable evidence here of a premium attributable specifically to holding this certification, and we do not assert one. Treat salary conversations as occupational data and read the CSA salary guide and the ROI analysis with that in mind.

CSA Compared With CySA+

Candidates often weigh Certified SOC Analyst against CompTIA CySA+, since both address analyst-level security work. They come from different certifying bodies and differ in structure, so compare the current official exam pages for each rather than assuming equivalence.

ConsiderationCertified SOC Analyst (312-39)
IssuerEC-Council
Center of gravitySOC workflow: log management, triage and incident response (65% across Domains 3, 4 and 6)
Format100 multiple-choice questions in three hours
Distinctive v2 contentAI-generated rule creation, proactive threat hunting, cloud SOC environments

If your goal is specifically a SOC-floor role and you want a blueprint organized around that workflow, the CSA blueprint is explicit about it. Check CySA+'s published objectives directly if you are considering it, rather than relying on secondhand summaries.

Sequencing Your Preparation Around the Weights

You do not need an elaborate method here; you need an order that follows the weights. One reasonable approach for a candidate with some networking background:

Week 1

Foundations: Domains 1 and 2

  • SOC roles, processes and maturity concepts
  • Attack stages, IoCs and adversary behavior
Weeks 2-3

Log Management: Domain 3 (15%)

  • Windows, Linux, Mac, network and application log sources
  • SIEM collection, normalization and correlation
Weeks 4-5

The 25% core: Domains 4 and 6

  • Alert triage scenarios and escalation decisions
  • Incident response lifecycle and playbooks
Week 6

Remaining domains and review

  • Threat intelligence and hunting (Domain 5)
  • Forensics, malware analysis and cloud SOC (Domains 7 and 8)
  • Timed practice sets to rehearse the three-hour pace

Logs come before triage because you cannot judge an alert without reading the evidence behind it. Leave your timed practice for the end so that pacing, roughly a little under two minutes per question on average, is tested once you know the material. Our CSA study guide expands this into a fuller plan, and the CSA cheat sheet works well for final review. When you are ready to test yourself, try the practice exams, which use original scenario questions rather than recalled exam content.

Key Takeaway

Schedule your heaviest study blocks for Domains 3, 4 and 6, which together are 65% of the blueprint. Cover everything else, but never at the expense of these three.

Keeping the Credential Active

Certified SOC Analyst runs on a three-year cycle. To maintain it you need 120 CPE/ECE credits in that period, and EC-Council publishes a USD 80 annual continuing-education fee, which is USD 240 across three years. Paying the fee alone does not satisfy the credit requirement; you must earn and report the credits as well. Plan your renewal costs and activities from day one rather than in the final year. For exam scheduling and windows, see the CSA exam dates guide.

As for how many candidates pass, no certification-wide pass rate is asserted here. Our pass rate discussion explains what can and cannot be said from available data.

Frequently Asked Questions

What does CSA mean on this site?

It means Certified SOC Analyst from EC-Council, version 2, exam 312-39. Other credentials share the acronym, but none of their details apply here.

How many questions are on the exam and how long do I get?

The exam has 100 multiple-choice questions with a three-hour limit and a 70% passing score. The three-day figure you may see refers to the training course, not the exam.

Do I have to take the official training to sit the exam?

Not necessarily. The CSA-specific eligibility provisions allow a self-study route requiring one year of verified network-administration or security experience and a USD 100 nonrefundable application fee, in addition to the USD 450 voucher.

Which domains matter most?

Incident Detection and Triage and Incident Response are 25% each, for 50% combined. Log Management follows at 15%, then Proactive Threat Detection at 12%.

Is the exam hands-on?

No. Training labs exist, but the certification exam is multiple-choice, so preparation should emphasize interpreting logs, alerts and scenarios in written form.

What does it take to renew?

Over a three-year cycle you need 120 CPE/ECE credits and must pay the USD 80 annual continuing-education fee. The fee alone does not satisfy the credit requirement.

Ready to pass your CSA exam?

Put this into practice with free CSA questions across every exam domain.