Study Guide

EC-Council CSA Exam Guide: Prepare for the SOC Analyst Exam

Prepare for the EC-Council Certified SOC Analyst (CSA) exam: verified 312-39 facts, official domain weights, prerequisites, and a triage task.

Updated September 202611 min readStudy GuideCEH Exam
Gabrielle Wallace

Gabrielle Wallace

CEH Exam Editorial Team

The EC-Council Certified SOC Analyst (CSA) exam (code 312-39) is a 3-hour, 100-question multiple-choice exam with a 70% passing score, available through the EC-Council Exam Portal after you complete the official CSA training. Preparation means covering the eight domains in EC-Council's published CSAv2 exam blueprint — incident detection and triage and incident response each weighted 25% — and practicing the triage decisions that separate a valid alert from a confirmed incident.

What the CSA credential covers

CSA is EC-Council's credential for current and aspiring Tier I and Tier II SOC analysts, covering entry-level and intermediate security operations work end to end.

The program is built around the security operations center (SOC) — the team that continuously monitors for threats, triages alerts, and escalates real incidents. EC-Council describes CSA as the first step toward joining a SOC, engineered for analysts performing entry-level and intermediate-level operations.

Training is delivered as an intensive three-day program that starts with SOC operations fundamentals and progresses through log management and correlation, SIEM deployment, advanced incident detection, and incident response. You also learn to manage SOC processes and to collaborate with the computer security incident response team (CSIRT) when incidents are escalated.

One framing note: EC-Council maps the program to the NICE 2.0 workforce framework under the Protect and Defend category for the Cyber Defense Analysis role, and states the training dedicates more than half its time to labs. That hands-on emphasis shapes how you should study — the credential validates applied SOC workflow, not just definitions.

Sources: Certified SOC Analyst (CSA) Certification | EC-Council — Official program page, retrieved 2026-09-15

Exam format and passing requirements

Exam 312-39 has 100 multiple-choice questions, lasts 3 hours, and requires a minimum score of 70% to pass.

The exam is delivered through the EC-Council Exam Portal. These are the specifics EC-Council publishes for the current exam: code 312-39, exam title Certified SOC Analyst, 100 questions, 3-hour duration, and multiple-choice format. EC-Council's certification site lists the same figures.

Certification is training-gated. EC-Council's stated path is to complete the official CSA training and then attempt the three-hour exam; passing it earns the credential. Your enrollment includes an examination voucher alongside courseware and lab access, so you do not book the exam separately from training.

The passing requirement is a minimum score of 70%. EC-Council also publishes an official domain-weighted blueprint for this exam — the Certified SOC Analyst v2 blueprint — so you can plan study time from published weights rather than guessing a percentage split.

Sources: Certified SOC Analyst (CSA) Certification | EC-Council — Official program page, retrieved 2026-09-15; Certified SOC Analyst — https://cert.eccouncil.org/certified-soc-analyst.html; Blue Print — https://cert.eccouncil.org/images/doc/CSAv2-Exam-Blueprint.pdf

The eight exam domains and their published weights

EC-Council's published CSAv2 exam blueprint for 312-39 defines eight domains with fixed weights: incident detection and triage and incident response each carry 25%, while log management (15%) and proactive threat detection (12%) form the second tier.

EC-Council publishes an official exam blueprint — the Certified SOC Analyst v2 blueprint — for exam 312-39. It lists eight domains with explicit percentage weights, and that blueprint, not the training module list, is your authoritative coverage map.

The weighting tells you where to spend time: two domains, Incident Detection and Triage and Incident Response, carry 25% each and together account for half the exam. Log Management (15%) and Proactive Threat Detection (12%) form the second tier, and the remaining four domains carry 5–8% each.

The blueprint's domain names match the course modules almost one for one, so the official courseware and its SIEM teaching — Splunk, AlienVault, OSSIM, the ELK Stack, and Microsoft Sentinel in the cloud module — remain useful preparation. Treat the course materials as supplementary, though: EC-Council states that its exams are developed independently of courseware and assess competence in the skills, so the blueprint's sub-domains, not the course page's marketing, define what can be tested.

Exam domainWeightBlueprint coverage
Security Operations and Management5%Security management principles, SOC importance, capabilities and functions, SOC workflow, people/process/technology, SOC models, maturity, KPIs and best practices
Understanding Cyber Threats, IoCs, and Attack Methodology8%Cyber threats and their impact; network, host, application, social engineering, email, and insider attack TTPs; recognizing IoCs; attack methodology and frameworks
Log Management15%Log management approaches; local logging for Windows, Linux, Mac, firewall, router, web server, database, and email; centralized logging
Incident Detection and Triage25%SIEM importance and architecture, SIEM solution types, deployment, use case management, AI for SIEM rules, incident detection, alert triage and analysis, dashboards, SOC reports
Proactive Threat Detection12%Threat intelligence concepts, types, strategies, sources, and platforms; intelligence-driven SOC; intelligence use cases; threat hunting frameworks and hunting with PowerShell and YARA
Incident Response25%The incident response process and its phases; responding to network, application, email, insider, and malware incidents; SOC playbooks; EDR and XDR
Forensics Investigation and Malware Analysis5%Forensic investigation of network, application, email, and insider incidents; malware analysis; static and dynamic malware analysis
SOC for Cloud Environments5%Azure SOC architecture with Microsoft Sentinel; AWS SOC architecture with Security Hub; GCP SOC architecture with Security Command Center and Chronicle

Sources: Blue Print — https://cert.eccouncil.org/images/doc/CSAv2-Exam-Blueprint.pdf; Certified SOC Analyst (CSA) Certification | EC-Council — Official program page, retrieved 2026-09-15; EC-Council candidate FAQ: exam preparation and blueprint updates — Exam Preparation:

Prerequisites, background, and delivery modes

EC-Council recommends foundational cybersecurity or IT knowledge — networking concepts, the TCP/IP protocol suite, and security technologies such as firewalls and IDS/IPS — and official training enrollment is required.

There is no application or experience threshold published for CSA; the stated expectation is that you already understand networking concepts, TCP/IP, security technologies, and common cyberthreats before starting. Official training is required, and it comes in three modes: iLearn self-study (asynchronous video), iWeek live online with an instructor, and in-person training through a partner.

If you are starting from zero, EC-Council's SOC Essentials (SCE) course is the designed feeder. It requires no prior IT or cybersecurity experience, covers network and security fundamentals, SOC architecture, SIEM basics, log management, threat intelligence, and incident response in eight modules, and leads to its own proctored certification. EC-Council explicitly points SCE completers toward CSA as the next step.

Choose the delivery mode honestly against your schedule: self-study suits disciplined self-paced learners, while live online and in-person formats give you instructor access for the lab-heavy portions of the program.

  • Recommended before CSA: networking concepts, TCP/IP, firewalls, IDS/IPS, and awareness of common cyberthreats
  • Absolute beginner route: SOC Essentials (SCE) first, then CSA
  • Three training modes: iLearn self-study, iWeek live online, and in-person through a training partner

Sources: Certified SOC Analyst (CSA) Certification | EC-Council — Official program page, retrieved 2026-09-15; SOC Essentials Course | SOC Training & Certification | EC-Council — Official SOC Essentials page, retrieved 2026-09-15

How to structure your preparation

Study the eight blueprint domains in proportion to their published weights — incident detection and triage and incident response first at 25% each — and practice the corroboration habit that separates a valid alert from a confirmed incident.

The published weights make your priorities concrete. Incident Detection and Triage and Incident Response each carry 25%, so SIEM use case development, correlation rules, alert triage, and the incident response phases deserve roughly half your study time. For each SIEM use case you review, ask what log source feeds it, what behavior it matches, and what a real versus noisy hit looks like.

Log Management (15%) gives you the vocabulary that makes detection questions answerable. Be able to say, for any log type in the blueprint — Windows event logs, firewall logs, Apache or IIS logs, and so on — what events it records and what questions it can answer. Proactive Threat Detection (12%) adds the context layer: threat intelligence feeds integrated into SIEM support faster, more accurate triage, which is exactly the skill the exercise below practices.

Two practical suggestions, offered as advice rather than requirements. First, use the hands-on labs your enrollment includes — Splunk, ELK, OSSIM, Sentinel — until basic queries feel routine. Second, when reviewing any attack type from the threats domain, pair it with its detection: which SIEM use case would catch it, and which log source provides the confirming evidence. Note that EC-Council states exams are developed independently of courseware, so treat the blueprint's sub-domains as your scope check.

Cover all eight domains rather than skipping the lighter ones — the four 5–8% domains still add up to about a quarter of the exam. The blueprint PDF on EC-Council's certification site is free to download and lists every sub-domain, so you can tick off coverage explicitly instead of relying on the course page's summary.

Practice

Practice a triage decision with all assumptions stated. Your SIEM rule for SSH brute-force detection fires whenever a single account records 20 or more failed SSH authentications within five minutes; its positive condition is the failure burst itself, not proof that an attack occurred. Today the rule alerts: 25 failed SSH authentications for the service account svc_backup, all from one internal host, 10.20.4.9, within five minutes. You confirm in the authentication logs that no attempt from that source succeeded during the window. The service owner then confirms two facts: svc_backup's password was rotated on the standard schedule two nights ago, and the backup job on 10.20.4.9 still runs its old stored credential because its configuration update failed. Assume no other hosts or accounts show related failures, and the source host shows no other suspicious activity. Answer three questions: did the rule fire correctly, does the burst indicate malicious activity, and what is the follow-up?

Show answer

The rule fired correctly: its defined condition — at least 20 failed authentications for one account within five minutes — was met, so this is a valid detection, not a malfunction. The burst does not indicate malicious activity. The evidence for that call is the service owner's confirmed root cause (a scheduled rotation plus a failed configuration update left the stored credential stale), the single internal source with no other suspicious behavior, and no related failures on other hosts or accounts. Note that zero successful logins alone would not prove the activity benign — an attacker failing to brute-force the account would also show no successes — so the benign classification rests on the corroborated rotation finding, not on the absence of successes. Follow-up: open or route a ticket to fix the backup job's stored credential, document the confirmed cause in the case record, and close the alert with the justification attached. Any tuning belongs with the rule owner and should target this verified service account, not a blanket suppression of alerts around scheduled rotations, which would reduce detection coverage.

The exercise separates two judgments candidates often blur. First, detection quality: the rule did exactly what its logic says, so the alert is valid. Second, incident classification: a valid alert is not automatically an attack, and it is not automatically noise. Zero successful authentications cannot rule out an attack, because a failing brute-force attempt looks identical at that level; what makes the benign call defensible is the independent, confirmed explanation from the service owner. That corroboration habit — check the underlying logs, verify the operational context, document the justification — is the triage workflow the CSA's detection and triage domain teaches. Because an attacker could act during the same rotation window, the safe response is targeted tuning for verified service accounts, never suppressing the rule around all rotations.

Sources: Certified SOC Analyst (CSA) Certification | EC-Council — Official program page, retrieved 2026-09-15; Blue Print — https://cert.eccouncil.org/images/doc/CSAv2-Exam-Blueprint.pdf; EC-Council candidate FAQ: exam preparation and blueprint updates — Exam Preparation:

Roles and credentials after CSA

CSA maps to SOC analyst roles at levels 1 through 3, and EC-Council positions CND, ECIH, CHFI, and CTIA as follow-on blue-team credentials.

EC-Council lists the roles the program opens: SOC analysts at L1, L2, and L3, junior SOC security analysts, security incident response analysts, SOC threat analysts, and information security analysts. The tier structure matters for expectations: L1 analysts monitor alerts and triage, L2 handle complex incidents and deeper investigations, and L3 conduct threat hunting and guide lower tiers — CSA's training targets the entry and intermediate tiers where most careers start.

For specialization after CSA, EC-Council points to its blue-team track: Certified Network Defender (CND) for network security depth, Certified Incident Handler (ECIH) for incident response, Computer Hacking Forensic Investigator (CHFI) for forensics, and Certified Threat Intelligence Analyst (CTIA) for the threat intelligence discipline. CTIA is aimed at more experienced professionals, so treat it as a later step, while CEH is the suggested route for understanding offensive techniques from the attacker's side.

Sources: Certified SOC Analyst (CSA) Certification | EC-Council — Official program page, retrieved 2026-09-15; Cyber Threat Intelligence Analyst | CTIA Certification | EC-Council — Official CTIA page, retrieved 2026-09-15

Sources

Facts checked:

Next steps

FAQ

Frequently Asked Questions

Practical answers to help you apply the guidance for EC-Council Certified SOC Analyst (CSA).

How much does CSA training and certification cost?
EC-Council states the cost depends on the delivery mode you choose — in-person, live online, or self-study — and does not publish a single price on the program page. Your enrollment package includes the exam voucher, courseware, and lab access. Contact EC-Council or a training partner for a current quote and funding options such as Army Credentialing Assistance.
Is official training mandatory, or can I challenge the exam directly?
EC-Council's published path requires completing the official CSA training before attempting the exam, and the training enrollment is where you receive your exam voucher. There is no self-study-and-book-exam-only route described on the program page.
How is CSA different from SOC Essentials (SCE)?
SCE is a beginner-level course requiring no IT or cybersecurity experience, covering SOC fundamentals in about ten hours of video with a proctored essentials exam. CSA is the intermediate credential: it assumes foundational networking and security knowledge, requires official training, and culminates in the three-hour, 100-question 312-39 exam. EC-Council positions SCE as preparation for CSA.
Do I need hands-on SIEM product experience before starting CSA?
You need the recommended conceptual background — networking, TCP/IP, firewalls, IDS/IPS — and the training itself supplies hands-on SIEM experience through its labs in Splunk, ELK Stack, OSSIM, and Microsoft Sentinel. Prior product familiarity helps but is not listed as a prerequisite.
Where can I confirm details this guide does not cover, like scheduling and version?
Domain weights are published: EC-Council's CSAv2 exam blueprint for 312-39 on its certification website lists all eight domains and their percentages. For anything the blueprint and program page do not cover — scheduling steps, current costs, or future blueprint revisions — use the program page's brochure and EC-Council's certification site, which are the authoritative sources.

Keep Reading

Related Study Guides

Explore related guides and preparation topics.