The CND is EC-Council's vendor-neutral network defense certification, earned by passing exam 312-38: 100 multiple-choice questions in 4 hours, with a per-form cut score between 60% and 85%. Prepare by checking your coverage against the eight weighted blueprint domains, practicing control-selection decisions with written justifications, and confirming administrative details directly with EC-Council.
What the Certified Network Defender covers
The CND is a vendor-neutral, lab-intensive network defense credential for network and security administrators, built on a protect, detect, respond, and predict structure and mapped to the NICE framework.
EC-Council describes the Certified Network Defender as a program for network administrators who need to protect, detect, and respond to threats on the network. You pass exam 312-38 to earn the credential. The program is skills-based and lab-intensive, and EC-Council states it is built on a job-task analysis and the NICE cybersecurity education framework.
The curriculum is organized around a continual security strategy: protect, detect, respond, and predict. In practice that spans attack and defense strategy, administrative and technical controls, perimeter devices, Windows, Linux, mobile, and IoT endpoints, application and data protection, virtual, cloud, and wireless environments, traffic and log monitoring, incident response, business continuity, risk management, and threat intelligence.
EC-Council lists several recognitions: ANAB accreditation under ISO/IEC 17024, approval under US DoD Directive 8570/8140, and recognition by the UK's National Cyber Security Centre. The current exam blueprint is version 4.0, while EC-Council's course page describes the credential itself as CND v3; treat the downloadable blueprint as the authoritative testing reference.
Official sources used: Certified Network Defender - EC-Council certification page — Exam Information and CND Exam Details; Age Requirements and Policies; CND Certification | Certified Network Defender | Network Security Course — Course outline, Training and Exam Details, career and FAQ sections
Exam format and how scoring works
Exam 312-38 has 100 multiple-choice questions with a 4-hour limit, delivered through the EC-Council Exam Portal. Cut scores are set per exam form and range from 60% to 85%.
The logistics are fixed and verified: 100 questions, 4 hours, multiple-choice format, available through the EC-Council Exam Portal. Four hours for 100 questions averages under two and a half minutes each, so pacing practice under a timer is worthwhile.
Scoring needs one careful reading. EC-Council delivers exams in multiple forms with different question banks, each beta-tested and reviewed by subject-matter experts. Each form gets its own cut score, and those cut scores range from 60% to 85%. There is no single fixed pass mark, so aim to master the domains rather than targeting a specific percentage.
One administrative rule worth knowing early: minors may not sit an EC-Council exam without written consent from a parent or legal guardian plus a supporting letter from their institution. If that applies to you, contact EC-Council before booking.
Official sources used: Certified Network Defender - EC-Council certification page — Exam Information and CND Exam Details; Age Requirements and Policies; CND Certification | Certified Network Defender | Network Security Course — Course outline, Training and Exam Details, career and FAQ sections
The eight blueprint domains and their weights
CND Blueprint v4 groups its subdomains into eight weighted domains. Use these groups to check coverage, then review the detailed objectives within each.
The PDF distinguishes domain groups from their individual subdomains. Endpoint Protection carries 20%; Enterprise Virtual, Cloud, and Wireless Network Protection and Incident Prediction each carry 15%; the other five groups each carry 10%.
Compare this map with your current skills. For each unfamiliar control or analysis task, review the corresponding course explanation and an authorized lab. Domain weights describe assessment coverage, not a required order or fixed number of study hours.
| Blueprint domain | Weight |
|---|---|
| Network Defense Management | 10% |
| Network Perimeter Protection | 10% |
| Endpoint Protection | 20% |
| Application and Data Protection | 10% |
| Enterprise Virtual, Cloud, and Wireless Network Protection | 15% |
| Incident Detection | 10% |
| Incident Response | 10% |
| Incident Prediction | 15% |
Official sources used: EC-Council CND Exam Blueprint v4.0 (exam 312-38) — Domain and sub-domain table, pages 1-11
Choosing perimeter controls: a worked decision
Compare each device's stated configuration against the action the scenario requires: a passive IDS configured only to alert reports attack patterns, while an inline IPS configured to drop them stops them before delivery.
The perimeter objectives include firewall capabilities and deployment, IDS/IPS classification, and the limits of detection systems. Read the configured behavior in a question before deciding whether it meets the stated requirement.
The following paper example explicitly defines two offered configurations. Its answer follows from those configurations; it does not claim that every product with a particular acronym has identical capabilities.
Try it yourself
Your team manages a public web server in a DMZ. Policy requires that known attack patterns against the server be blocked automatically before they reach it, not merely logged for later review. You must choose between two offered deployments: a passive network-based intrusion detection system (IDS) that inspects a copy of the traffic and raises alerts, and an inline intrusion prevention system (IPS) configured to drop sessions matching known attack patterns. Which deployment satisfies the policy, and why does the other fail it?
Show answer
Deploy the inline IPS configured to drop matching sessions. The policy's operative requirement is automatic blocking before delivery, which needs a device positioned in the traffic path with a drop action enabled. The offered IDS inspects a copy of the traffic and raises alerts only, so it meets the detection and reporting duty but cannot satisfy the blocking requirement as configured. Note the scoping: this conclusion follows from the stated passive, alert-only configuration, not from the acronym IDS alone.
This maps to the blueprint's perimeter sub-topics on the role, capabilities, and limitations of IDS deployment and IDS/IPS classification. The transferable habit: anchor the choice to the stated configuration and the required action in the scenario. When a question offers devices with different configurations, compare those configurations rather than defaulting to the better-known acronym.
Official sources used: EC-Council CND Exam Blueprint v4.0 (exam 312-38) — Domain and sub-domain table, pages 1-11
Reading alerts: baselines, signatures, and anomalies
Identify the rule that produced an alert, then distinguish the observed condition from an explanation for it.
The Incident Detection domain includes traffic monitoring, baseline and anomaly analysis, and log monitoring. The paper example supplies a specific detection rule so you can check what its output establishes.
Try it yourself
A lab detector alerts when a host opens more than 1,000 outbound connections to one external address in an hour. Its threshold was defined as five times a recorded baseline of 200. It reports 2,400 connections from one host to one address during the last hour. Has its stated condition been met, and does the alert alone identify why the traffic occurred?
Show answer
Yes: 2,400 exceeds 1,000. The rule condition is met, but the alert alone does not identify the traffic purpose or establish whether it is malicious.
The comparison verifies the rule outcome. Several causes can be consistent with a high connection count, and no cause is supplied in this example. Keep the measured activity separate from an unverified explanation when reviewing the alert.
Official sources used: EC-Council CND Exam Blueprint v4.0 (exam 312-38) — Domain and sub-domain table, pages 1-11; CND Certification | Certified Network Defender | Network Security Course — Course outline, Training and Exam Details, career and FAQ sections
Endpoints, applications, and protecting data by state
Review the platform-specific endpoint objectives alongside application security and data protection.
Endpoint protection in the blueprint splits into Windows, Linux, mobile devices, and IoT, each with its own sub-topics: Windows security features, baselines, patching, and Active Directory; Linux installation, hardening, and access management; enterprise mobile usage policies such as BYOD and COPE with their management tooling; and IoT security challenges and measures. Study each platform's controls on their own terms rather than assuming one hardening checklist transfers.
The blueprint lists application whitelisting and blacklisting, sandboxing, patch management and web application firewalls. Data-protection objectives include encryption of stored and transmitted data, masking, backup and retention, destruction and data-loss prevention. Use the relevant course guidance to understand each control and its limits.
Official sources used: EC-Council CND Exam Blueprint v4.0 (exam 312-38) — Domain and sub-domain table, pages 1-11; CND Certification | Certified Network Defender | Network Security Course — Course outline, Training and Exam Details, career and FAQ sections
Training routes, expectations, and next steps
EC-Council routes CND candidates through official training with several delivery formats; the program is designed as five days and includes the exam voucher, and you should arrive with fundamental networking knowledge.
EC-Council's course page lists three delivery routes: iLearn, a self-paced video format; iWeek, live online instructor-led training; and in-person training through accredited training partners. The program is designed as five days, and official materials describe packages that include courseware, lab access, and an exam voucher.
On readiness, EC-Council's own guidance is consistent: students should have at least fundamental knowledge of networking concepts before the class, and the program is described as intermediate-level, though applicable to newcomers with that grounding. If you are unsure whether your networking baseline is sufficient, review core topics such as addressing, routing, and common protocols before enrolling.
Cost is the one detail to verify directly: EC-Council states that pricing varies by delivery mode and directs candidates to its website or career advisors for current figures. Keep the course outline supplementary: EC-Council's candidate FAQ states that official courseware is recommended but not mandatory and is developed independently of exam content, so use the blueprint and objectives, not the course page, as your coverage checklist.
Official sources used: CND Certification | Certified Network Defender | Network Security Course — Course outline, Training and Exam Details, career and FAQ sections; Certified Network Defender - EC-Council certification page — Exam Information and CND Exam Details; Age Requirements and Policies; EC-Council candidate FAQ: exam preparation and blueprint updates — Exam Preparation:
Where the CND fits in a career
The CND maps to network security and defense roles, is recognized under DoD 8140 for three cyber defense work roles, and sits on a blue-team path with natural follow-on credentials.
EC-Council maps the CND to job roles including network security engineer, network security administrator, network security analyst, network defense specialist, firewall and IDS/IPS specialist, and network traffic analyst. Under DoD 8140, EC-Council lists the CND for work roles 511 Cyber Defense Analyst, 521 Cyber Defense Infrastructure Support Specialist, and 531 Cyber Defense Incident Responder.
EC-Council positions the CND against CCNA and Network+ as security-focused rather than networking-focused, and labels that comparison its own view; judge it accordingly. For progression, EC-Council suggests blue-team specializations such as ECIH, CSA, CTIA, and CHFI for incident handling, threat intelligence, and forensics, or offensive paths such as CEH and CPENT.
Official sources used: CND Certification | Certified Network Defender | Network Security Course — Course outline, Training and Exam Details, career and FAQ sections
A study sequence and final checklist
Sequence your preparation across the blueprint families from foundations to detection and prediction, finish with mixed timed practice, and verify every administrative detail on EC-Council's official pages.
The sequence below is study advice, not an official requirement. Adjust the pacing to your existing networking knowledge and the time you have before your exam date.
- Weeks 1-2: attacks and defense strategy, administrative and technical controls, and perimeter security, writing the three-part description (function, placement, trigger) for every control you meet
- Week 3: endpoint, application, and data protection, drilling the data-state matching habit across Windows, Linux, mobile, and IoT topics
- Week 4: virtual, cloud, and wireless security, reusing the same classification in shared and untrusted-media environments
- Weeks 5-6: traffic and log monitoring, incident response, business continuity, risk management, attack surface analysis, and threat intelligence
- Final stretch: mixed timed practice at roughly 2.5 minutes per question, plus a full read of the official blueprint to confirm coverage and weights
- Booking: confirm the current delivery route, fee, and any consent requirements on EC-Council's certification pages before scheduling exam 312-38
Official sources used: EC-Council CND Exam Blueprint v4.0 (exam 312-38) — Domain and sub-domain table, pages 1-11; CND Certification | Certified Network Defender | Network Security Course — Course outline, Training and Exam Details, career and FAQ sections
Official sources used
Facts checked against official EC-Council pages:
