0.1 Current Exam Facts, Blueprint, and Study Plan
Key Takeaways
- EC-Council identifies the current Certified SOC Analyst examination as exam 312-39 with 100 multiple-choice questions and a three-hour time limit.
- Independent exam candidates need one year of Network Administration or Security experience and must document eligibility unless they complete official EC-Council training.
- The CSA v2 blueprint has eight domains; Incident Detection and Triage and Incident Response are the largest at 25% each.
- EC-Council’s certification site publishes a 70% passing score for CSA but no standalone voucher price, so candidates must confirm the current fee in their booking channel.
- Use the blueprint weights to prioritize SIEM detection, triage, and incident response while still covering every listed subdomain.
Verify the Exam Before You Study
This guide prepares you for EC-Council Certified SOC Analyst (CSA), exam 312-39. EC-Council’s current certification page describes a 100-question, three-hour, multiple-choice examination delivered through the EC-Council Exam Portal. The same page states that an independent candidate must have one year of work experience in Network Administration or Security and provide proof through the application process; completing official EC-Council training waives that experience-application route.
Use the current EC-Council CSA certification page and the official CSA v2 exam blueprint as the controlling sources. EC-Council’s certification site lists the CSA exam details as 3 hours, 100 questions, and a 70% passing score, delivered at the ECC Exam Centre. Neither the certification page nor the current training page publishes a standalone exam-voucher price, so treat any fee you see on a reseller page as unofficial; verify the price, delivery method, identification rules, and eligibility status in the portal or authorized booking channel before paying.
| Published exam fact | Current official value |
|---|---|
| Exam title | Certified SOC Analyst |
| Exam code | 312-39 |
| Format | Multiple choice |
| Questions | 100 |
| Time limit | 3 hours |
| Passing score | 70% |
| Delivery | EC-Council Exam Portal / ECC Exam Centre |
| Independent-candidate eligibility | 1 year of Network Administration or Security experience, with proof through the application process |
| Official-training route | The experience application is waived for candidates who attend official training |
The Eight-Domain CSA v2 Blueprint
The official blueprint lists 59 explicit subdomains. Several are tightly coupled—for example, dashboard management and SOC reporting—but none may be skipped merely because it has a small weight.
| Domain | Weight | Approximate share of a 100-question form |
|---|---|---|
| Security Operations and Management | 5% | about 5 questions |
| Understanding Cyber Threats, IoCs, and Attack Methodology | 8% | about 8 questions |
| Log Management | 15% | about 15 questions |
| Incident Detection and Triage | 25% | about 25 questions |
| Proactive Threat Detection | 12% | about 12 questions |
| Incident Response | 25% | about 25 questions |
| Forensics Investigation and Malware Analysis | 5% | about 5 questions |
| SOC for Cloud Environments | 5% | about 5 questions |
The question estimates are planning aids obtained by applying the published percentages to a 100-question exam. They are not a promise that every delivered form will contain exactly that count in each domain.
A Weight-Aware Study Sequence
- Build the operating model. Learn SOC functions, people/process/technology, sourcing models, workflow, maturity, and metrics.
- Understand the adversary and the evidence. Connect network, host, application, social-engineering, email, and insider TTPs to indicators and attack frameworks.
- Master telemetry before tools. Practice reading Windows, Linux, macOS, firewall, router, web, database, and email logs, then learn centralized collection and normalization.
- Spend half of your core review on detection/triage and response. Together these two official domains account for 50% of the blueprint. Work through SIEM architecture, deployment, use cases, AI-assisted rule development, alert analysis, reporting, vector-specific response, playbooks, and EDR/XDR.
- Add proactive detection and investigation. Cover threat-intelligence sources and platforms, threat hunting, PowerShell, YARA, evidence handling, vector-specific investigation, and static/dynamic malware analysis.
- Finish with cloud context. Compare shared responsibility and the native SOC services in Azure, AWS, and Google Cloud.
Build a Traceable Review Loop
Keep an error log organized by the eight blueprint domains. For each missed practice item, record the observable evidence, the incident phase, the control or data source you chose, why the keyed action fits, and why each distractor fails. Tag the miss as a knowledge gap, sequencing error, tool-confusion error, or overreaction. Revisit high-weight Incident Detection and Triage and Incident Response gaps first, but do not let a low-weight domain remain uncovered.
Use short, controlled lab exercises where practical: parse a Windows or Linux authentication event, normalize a small syslog sample, write a narrowly scoped Sigma or YARA rule, trace a mock phishing message, and map a response decision to evidence-preservation needs. A lab is valuable only when you can explain the resulting telemetry and limitations. Tool output without interpretation is not analysis, and an alert without corroboration is not automatically an incident.
Exam-Day Reasoning
CSA questions commonly reward operational sequencing. First decide whether the evidence describes an event, an alert, or a confirmed incident. Then identify the phase—collection, triage, investigation, containment, eradication, recovery, or lessons learned—and choose the action that preserves evidence while reducing risk. Treat numeric alert thresholds, severity labels, and service-level targets in examples as organization-defined unless EC-Council’s blueprint explicitly fixes them.
Which exam format is published on EC-Council’s current CSA certification page for exam 312-39?
Which two CSA v2 domains receive the largest official weights?
An independent candidate has not attended official EC-Council CSA training. What eligibility condition does EC-Council publish?