- What CSA Certification Actually Is
- Who Issues It and What Version Is Current
- Exam Format at a Glance
- The Eight Blueprint Domains
- Why Triage and Response Carry the Exam
- Eligibility Routes and Fee Mechanics
- Skills You Will Be Expected to Show
- Roles, Employers, and Pay Expectations
- How CSA Compares With CySA+
- Scheduling Your Preparation Around the Weights
- Keeping the Credential Current
- Frequently Asked Questions
- CSA here means Certified SOC Analyst, EC-Council's entry-to-mid-level SOC credential, currently version 2 under exam code 312-39.
- The exam has 100 multiple-choice questions, a three-hour limit, and a 70% passing score.
- Incident Detection and Triage plus Incident Response are 25% each, making half the blueprint.
- The USD 450 voucher is separate from the USD 100 self-study application fee.
What CSA Certification Actually Is
"CSA" is an acronym shared by several unrelated credentials, which causes real confusion in search results. On this site, CSA means Certified SOC Analyst: a security operations certification from EC-Council aimed at people who monitor, triage, and respond to alerts inside a Security Operations Center (SOC). It does not refer to any cloud-governance, safety, or other credential that happens to abbreviate to the same three letters.
The certification validates that a candidate can work the daily SOC loop: collect and interpret logs, recognize attack indicators, triage alerts in a SIEM, escalate or contain incidents, and communicate findings. It is a knowledge-based exam, not a hands-on lab assessment, even though the associated training includes labs. If you want the short-form definitions, our pages on what CSA is, what CSA stands for, and CSA meaning cover the acronym question directly. This article focuses on what the credential contains and what it takes to earn it.
Who Issues It and What Version Is Current
The governing body is EC-Council. The exam is delivered through the ECC Exam Centre / EC-Council Exam Portal, and the official voucher is the CSAv2 Exam Voucher with remote proctoring. The current exam is Certified SOC Analyst (CSA) version 2, exam code 312-39.
Version matters when you choose study material. Older six-domain v1 outlines, third-party four-domain breakdowns, and claims of a two-hour exam do not describe the verified v2 scope. The authoritative reference is EC-Council's Certified SOC Analyst (CSA) v2 Exam Blueprint - Exam 312-39, an undated PDF that lists eight weighted domains. When a practice resource lists different domain names or a different time limit, treat it with suspicion and check it against the blueprint.
Exam Format at a Glance
| Item | Certified SOC Analyst (CSA) v2 |
|---|---|
| Exam code | 312-39 |
| Question count | 100 multiple-choice questions |
| Time limit | Three hours |
| Passing score | 70% |
| Delivery | Remote proctoring via the EC-Council exam portal |
| Voucher price | USD 450 (CSAv2 Exam Voucher - RPS) |
| Voucher validity | One year, non-transferable |
Three hours for 100 questions gives you an average of 108 seconds per question, which is comfortable for recall items but tight if you hit several long scenario-style questions that require reading log excerpts or alert details. Pacing is a real skill here: bank time on quick definition questions so you can think carefully through triage and response scenarios. For a closer look at how scoring works, see our CSA passing score breakdown, and for scheduling logistics see CSA exam dates and scheduling.
The Eight Blueprint Domains
The v2 blueprint divides the exam into eight weighted domains. The weights are official exam objectives and total 100%.
| Domain | Name | Weight |
|---|---|---|
| 1 | Security Operations and Management | 5% |
| 2 | Understanding Cyber Threats, IoCs, and Attack Methodology | 8% |
| 3 | Log Management | 15% |
| 4 | Incident Detection and Triage | 25% |
| 5 | Proactive Threat Detection | 12% |
| 6 | Incident Response | 25% |
| 7 | Forensics Investigation and Malware Analysis | 5% |
| 8 | SOC for Cloud Environments | 5% |
For a deeper treatment of each area, our complete guide to all eight CSA exam domains goes domain by domain. Below is a quick orientation to what each one asks of you.
Domain 1: Security Operations and Management (5%)
The organizational layer of a SOC.
- SOC operations, roles, and processes
- SOC maturity and how capabilities grow over time
Domain 2: Understanding Cyber Threats, IoCs, and Attack Methodology (8%)
The attacker's side of the picture, so you can recognize it in telemetry.
- Attack methodology and the stages of an intrusion
- Indicators of compromise and how they surface in data
Domain 3: Log Management (15%)
The raw material of all SOC work.
- Windows, Linux, and Mac logs
- Network and application logs
- Knowing which log source answers which investigative question
Domain 4: Incident Detection and Triage (25%)
Turning alerts into decisions.
- SIEM use cases and AI-generated detection rules
- Alert triage: true positive, false positive, severity, escalation
Domain 5: Proactive Threat Detection (12%)
Looking for threats before an alert fires.
- Threat intelligence and how it informs detection
- Threat hunting as a proactive practice
Domain 6: Incident Response (25%)
What happens after an incident is confirmed.
- Incident response processes and playbooks
- Containment, eradication, recovery, and coordination
Domain 7: Forensics Investigation and Malware Analysis (5%)
Evidence handling and understanding malicious code at an analyst level.
- Forensic investigation fundamentals
- Malware analysis concepts
Domain 8: SOC for Cloud Environments (5%)
Monitoring workloads you do not physically host.
- SOC considerations across Azure, AWS, and GCP
Why Triage and Response Carry the Exam
Domains 4 and 6, Incident Detection and Triage and Incident Response, are jointly the largest at 25% each. Together they represent half of the blueprint. Add Log Management at 15% and you reach 65% of the exam from three domains. Anyone planning a study schedule should let that arithmetic drive their time allocation rather than spreading hours evenly across all eight areas.
What triage questions tend to test
Expect scenarios where an analyst receives an alert and must decide what it means. The style is original-scenario reasoning rather than memorized trivia. For example, you might be asked to judge which of several signals deserves escalation first, which log source would confirm a suspected credential attack, or why a particular detection rule would generate excessive false positives. Practice reasoning about alert context: what asset is involved, what the baseline behavior looks like, and what corroborating evidence exists in other log sources.
What response questions tend to test
Response questions emphasize sequence and judgment. Which step comes next after confirming a compromise? When should containment take priority over evidence preservation? What does a playbook specify for a given incident type, and who must be notified? Knowing the phases of the incident response lifecycle and why each exists is more valuable than memorizing tool names.
Key Takeaway
Build your own mini-scenarios for the two 25% domains: write down an alert, list the log sources you would check, and decide on an escalation call. Original practice like this transfers better than memorizing leaked questions, and leaked questions are an unreliable and ethically poor way to prepare. You can test yourself with questions on the CSA practice exam site.
Eligibility Routes and Fee Mechanics
The money and paperwork around this exam are often misunderstood, because several different charges sound similar. Separating them clearly saves confusion and avoids paying for the wrong item.
Two routes to eligibility
- Official training route. Candidates who complete EC-Council official training, or make a qualifying official-courseware purchase, follow this route. The eligibility page states that official-training fees include the USD 100 application charge.
- Self-study route. Candidates who prepare on their own need one year of verified network-administration or security experience, must pay the USD 100 nonrefundable eligibility-application fee, and need an employer, supervisor, or department verifier to confirm the experience.
The certification portal's CSA-specific eligibility provisions take precedence over the training page's blanket suggestion that official training is mandatory. In other words, self-study is a legitimate documented path, but only when the experience requirement is met and verified.
Separate charges to keep straight
| Item | Amount | What it is |
|---|---|---|
| CSAv2 Exam Voucher - RPS | USD 450 | The exam itself, remotely proctored |
| Self-study eligibility application | USD 100 | Nonrefundable; for the self-study route only |
| eCourseware | USD 250 | A separately listed training product; not an exam voucher |
Once your eligibility is approved, you get a three-month window to purchase the voucher. After purchase, the voucher is valid for one year and cannot be transferred to another person. Candidates who are minors must also follow the portal's additional parental-consent and educational-institution documentation rules. For a full breakdown of what total spend looks like under each route, read our CSA certification cost guide, and for the eligibility process in detail see CSA requirements and how to qualify.
Skills You Will Be Expected to Show
Because the blueprint is organized around SOC work, the content maps neatly to day-to-day analyst tasks. Blueprint-supported preparation topics include the following, all of which sit inside the eight published domains rather than forming extra weighted domains:
- SOC operations and maturity: how a SOC is staffed, tiered, and improved over time.
- Attack methodology and IoCs: recognizing adversary behavior and the artifacts it leaves.
- Multi-platform log literacy: Windows, Linux, and Mac logs, plus network and application logs.
- SIEM use cases and AI-generated rules: understanding what a detection rule is meant to catch, and how AI-assisted rule creation fits into that work.
- Alert triage: classification, prioritization, enrichment, and escalation.
- Threat intelligence and hunting: using intelligence to look for threats proactively.
- Incident response and playbooks: following and applying structured response procedures.
- Forensics and malware analysis: evidence basics and conceptual malware understanding.
- Cloud SOC environments: monitoring across Azure, AWS, and GCP.
The v2 emphasis on AI-assisted rule creation, proactive hunting, and cloud monitoring reflects how modern SOCs actually operate. If your study materials predate v2, check that they cover these areas. Our CSA study guide maps preparation to the current blueprint, and the CSA cheat sheet condenses the must-know facts into a one-page review.
Roles, Employers, and Pay Expectations
The certification is aimed at SOC-facing roles. Typical job titles that align with the skill set include SOC analyst (tier 1 and tier 2), security monitoring analyst, incident response analyst, and cyber defense analyst. The organizations that employ people in these roles are broad: managed security service providers, enterprise security teams in finance, healthcare, and government, consultancies, and any organization running a 24/7 monitoring function. Browse our CSA jobs overview for more on role types.
On compensation, be careful with the claims you read online. SOC analyst pay is well documented as an occupation, and it varies widely by region, employer type, shift structure, and experience. What is not established is a certification-specific salary premium for holding CSA in particular; no such figure is asserted here, and you should be skeptical of any site that quotes one without sourcing. A sound way to think about it: the credential helps demonstrate baseline competence and can support a resume for entry and mid-level SOC roles, while your actual pay will depend mostly on your market and experience. Our CSA salary guide separates occupational pay from certification effects, and the ROI analysis helps you weigh cost against likely benefit for your situation.
How CSA Compares With CySA+
Candidates frequently ask whether to pursue EC-Council's Certified SOC Analyst or CompTIA's CySA+ (Cybersecurity Analyst). Both target analyst-level defensive work, but they differ in issuer, blueprint structure, and emphasis.
| Dimension | Certified SOC Analyst (CSA) | CompTIA CySA+ |
|---|---|---|
| Issuer | EC-Council | CompTIA |
| Framing | Built explicitly around SOC workflow | Broader security-analyst scope |
| Heaviest content | Incident Detection and Triage and Incident Response, 25% each | Check CompTIA's current objectives directly |
| Exam format | 100 multiple-choice questions, three hours, 70% to pass | Check CompTIA's current exam page for format details |
The practical advice: pick based on the job postings you are targeting and the issuer your employer recognizes. If the roles you want describe SOC monitoring, triage, and incident handling, CSA's blueprint maps closely to that language. Always verify CySA+ details on CompTIA's own site, since this article only claims facts about CSA.
Scheduling Your Preparation Around the Weights
Generic study tricks matter less than allocating time to the right domains. Here is one way to sequence preparation so effort follows the blueprint. Adjust the pace to your own experience level.
Foundations: Domains 1 and 2
- SOC roles, processes, and maturity
- Attack methodology and indicators of compromise
Log Management (15%)
- Windows, Linux, and Mac log sources
- Network and application logs; which source answers which question
Incident Detection and Triage (25%)
- SIEM use cases and AI-generated rule concepts
- Write and work through your own triage scenarios
Incident Response (25%) and Proactive Detection (12%)
- Playbooks and response lifecycle
- Threat intelligence and hunting
Small domains and full review
- Forensics and malware analysis; cloud SOC for Azure, AWS, and GCP
- Timed practice sets to rehearse three-hour pacing
The logic: logs come before triage because you cannot judge an alert without understanding the data behind it, and triage comes before response because response decisions depend on correct classification. The three smallest domains at 5% each are worth reviewing but should not consume weeks that belong to the 25% areas. Timed practice near the end helps you rehearse the three-hour limit. You can run timed sets on the main practice test site. If you are unsure how demanding the exam is for your background, our CSA difficulty guide and pass rate analysis discuss what is and is not known; note that no certification-wide pass rate is asserted here.
Keeping the Credential Current
Certified SOC Analyst runs on a three-year certification cycle. To maintain it, you must earn 120 CPE/ECE credits within the cycle. EC-Council also publishes a continuing-education fee of USD 80 per year, or USD 240 across three years. These are two separate obligations: paying the fee alone does not satisfy the continuing-education requirement, so you still need to document the credits.
Practically, that means treating renewal as an ongoing habit rather than a last-minute scramble: attend relevant training, conferences, or webinars, contribute to the field, and log the activity as you go. Review EC-Council's CPE Policy page for the activities it accepts. For a wider look at the credential's lifecycle, see our overview of CSA certification and the CSA training options.
Frequently Asked Questions
On this site, CSA stands for Certified SOC Analyst, an EC-Council credential for security operations center work. The current version is v2, exam code 312-39. Other credentials share the acronym but are unrelated.
The exam has 100 multiple-choice questions with a three-hour time limit and a 70% passing score. The three-day figure you may see refers to the training course length, not the exam duration.
Not necessarily. There is an official-training route and a self-study route. Self-study requires one year of verified network-administration or security experience, a USD 100 nonrefundable application fee, and a verifier. The portal's CSA-specific provisions take precedence over the training page's general suggestion that training is mandatory.
Incident Detection and Triage and Incident Response are 25% each, together half the blueprint. Log Management is next at 15%, followed by Proactive Threat Detection at 12%. The remaining four domains are 8% or less each.
Maintain it over a three-year cycle by earning 120 CPE/ECE credits and paying the published USD 80 annual continuing-education fee. The fee does not replace the credit requirement; you must meet both.