0.1 Current Exam Facts, Blueprint, and Study Plan

Key Takeaways

  • EC-Council identifies the current Certified SOC Analyst examination as exam 312-39 with 100 multiple-choice questions and a three-hour time limit.
  • Independent exam candidates need one year of Network Administration or Security experience and must document eligibility unless they complete official EC-Council training.
  • The CSA v2 blueprint has eight domains; Incident Detection and Triage and Incident Response are the largest at 25% each.
  • EC-Council’s certification site publishes a 70% passing score for CSA but no standalone voucher price, so candidates must confirm the current fee in their booking channel.
  • Use the blueprint weights to prioritize SIEM detection, triage, and incident response while still covering every listed subdomain.
Last updated: September 2026

Verify the Exam Before You Study

This guide prepares you for EC-Council Certified SOC Analyst (CSA), exam 312-39. EC-Council’s current certification page describes a 100-question, three-hour, multiple-choice examination delivered through the EC-Council Exam Portal. The same page states that an independent candidate must have one year of work experience in Network Administration or Security and provide proof through the application process; completing official EC-Council training waives that experience-application route.

Use the current EC-Council CSA certification page and the official CSA v2 exam blueprint as the controlling sources. EC-Council’s certification site lists the CSA exam details as 3 hours, 100 questions, and a 70% passing score, delivered at the ECC Exam Centre. Neither the certification page nor the current training page publishes a standalone exam-voucher price, so treat any fee you see on a reseller page as unofficial; verify the price, delivery method, identification rules, and eligibility status in the portal or authorized booking channel before paying.

Published exam factCurrent official value
Exam titleCertified SOC Analyst
Exam code312-39
FormatMultiple choice
Questions100
Time limit3 hours
Passing score70%
DeliveryEC-Council Exam Portal / ECC Exam Centre
Independent-candidate eligibility1 year of Network Administration or Security experience, with proof through the application process
Official-training routeThe experience application is waived for candidates who attend official training

The Eight-Domain CSA v2 Blueprint

The official blueprint lists 59 explicit subdomains. Several are tightly coupled—for example, dashboard management and SOC reporting—but none may be skipped merely because it has a small weight.

DomainWeightApproximate share of a 100-question form
Security Operations and Management5%about 5 questions
Understanding Cyber Threats, IoCs, and Attack Methodology8%about 8 questions
Log Management15%about 15 questions
Incident Detection and Triage25%about 25 questions
Proactive Threat Detection12%about 12 questions
Incident Response25%about 25 questions
Forensics Investigation and Malware Analysis5%about 5 questions
SOC for Cloud Environments5%about 5 questions

The question estimates are planning aids obtained by applying the published percentages to a 100-question exam. They are not a promise that every delivered form will contain exactly that count in each domain.

A Weight-Aware Study Sequence

  1. Build the operating model. Learn SOC functions, people/process/technology, sourcing models, workflow, maturity, and metrics.
  2. Understand the adversary and the evidence. Connect network, host, application, social-engineering, email, and insider TTPs to indicators and attack frameworks.
  3. Master telemetry before tools. Practice reading Windows, Linux, macOS, firewall, router, web, database, and email logs, then learn centralized collection and normalization.
  4. Spend half of your core review on detection/triage and response. Together these two official domains account for 50% of the blueprint. Work through SIEM architecture, deployment, use cases, AI-assisted rule development, alert analysis, reporting, vector-specific response, playbooks, and EDR/XDR.
  5. Add proactive detection and investigation. Cover threat-intelligence sources and platforms, threat hunting, PowerShell, YARA, evidence handling, vector-specific investigation, and static/dynamic malware analysis.
  6. Finish with cloud context. Compare shared responsibility and the native SOC services in Azure, AWS, and Google Cloud.
free CSA practice questionsPractice questions with detailed explanations

Build a Traceable Review Loop

Keep an error log organized by the eight blueprint domains. For each missed practice item, record the observable evidence, the incident phase, the control or data source you chose, why the keyed action fits, and why each distractor fails. Tag the miss as a knowledge gap, sequencing error, tool-confusion error, or overreaction. Revisit high-weight Incident Detection and Triage and Incident Response gaps first, but do not let a low-weight domain remain uncovered.

Use short, controlled lab exercises where practical: parse a Windows or Linux authentication event, normalize a small syslog sample, write a narrowly scoped Sigma or YARA rule, trace a mock phishing message, and map a response decision to evidence-preservation needs. A lab is valuable only when you can explain the resulting telemetry and limitations. Tool output without interpretation is not analysis, and an alert without corroboration is not automatically an incident.

Exam-Day Reasoning

CSA questions commonly reward operational sequencing. First decide whether the evidence describes an event, an alert, or a confirmed incident. Then identify the phase—collection, triage, investigation, containment, eradication, recovery, or lessons learned—and choose the action that preserves evidence while reducing risk. Treat numeric alert thresholds, severity labels, and service-level targets in examples as organization-defined unless EC-Council’s blueprint explicitly fixes them.

Test Your Knowledge

Which exam format is published on EC-Council’s current CSA certification page for exam 312-39?

A
B
C
D
Test Your Knowledge

Which two CSA v2 domains receive the largest official weights?

A
B
C
D
Test Your Knowledge

An independent candidate has not attended official EC-Council CSA training. What eligibility condition does EC-Council publish?

A
B
C
D