312-39: EC-Council Certified SOC Analyst (CSA)

Associate EC-Council EC-Council
Browse certifications

Exam Resources

Official learning paths, exam details, skills measured, and community resources to supplement your study.

About the CSA (312-39) Exam

Run the SOC the right way — read the logs, build the SIEM detection, triage the alert, map the attack to the kill chain, hunt for what slipped past, and hand a clean, evidence-backed incident to the response team.

The EC-Council Certified SOC Analyst (CSA v2, exam 312-39) validates the day-to-day skills a Tier I / Tier II Security Operations Center analyst needs to monitor, detect, triage, and escalate security activity. It is vendor-neutral and hands-on, built around real SIEM, logging, threat-intelligence, and detection tooling. The current v2 revision covers eight modules: Security Operations and Management (SOC models, maturity, and metrics like MTTD and MTTR); Understanding Cyber Threats, IoCs, and Attack Methodology (network, host, application, social-engineering, email, and insider TTPs mapped to the Cyber Kill Chain, MITRE ATT&CK, MITRE D3FEND, and the Diamond Model); Log Management (Windows, Linux, macOS, firewall, web-server, database, and email logs with centralized logging and normalization); Incident Detection and Triage (SIEM architecture, the use-case lifecycle, correlation rules, AI-enabled SIEM, SIGMA rules, alert triage, and dashboards in Splunk and ELK); Proactive Threat Detection (the cyber-threat-intelligence lifecycle and TIPs, plus threat hunting with PowerShell, YARA, and Velociraptor); Incident Response (PICERL and NIST SP 800-61 across network, application, email, insider, and malware incidents with EDR/XDR/SOAR playbooks); Forensics Investigation and Malware Analysis (order of volatility, chain of custody, and static vs dynamic malware analysis); and SOC for Cloud Environments (Azure Sentinel, AWS Security Hub, and GCP Security Command Center). Every practice question is an original SOC-analyst scenario with detailed explanations, why-wrong analysis, and exam tips.

Who Should Take This Exam?

The CSA is an intermediate certification for current and aspiring Tier I and Tier II SOC analysts, SIEM and detection engineers, security monitoring and log-analysis specialists, threat hunters and threat-intelligence analysts, and network/security administrators moving into a SOC role. There is no mandatory work-experience prerequisite when you take official EC-Council CSA v2 training (a voucher is typically included); without training, an exam-eligibility application may apply. A working knowledge of networking, operating systems, logging, and core security concepts makes the material far easier.

Typical study time: 5-8 weeks of focused study

Exam Quick Facts

DetailValue
Exam Code312-39
TitleEC-Council Certified SOC Analyst (CSA v2)
Duration180 minutes
Questions100
Pass Score70% (form-dependent)
Cost$450 USD
ProviderECC Exam Portal (EC-Council)
Validity3 years (ECE required)
Question TypesMultiple choice
Official PageView on EC-Council →

Exam Domains & Weights

The CSA v2 exam covers 8 modules. The percentages below are the official weights from EC-Council’s CSA v2 exam blueprint, mapped to our 250-question practice bank so you can prioritise realistically.

DomainWeightPractice Qs
Security Operations and Management5%24
Understanding Cyber Threats, IoCs, and Attack Methodology8%26
Log Management15%34
Incident Detection and Triage25%44
Proactive Threat Detection12%30
Incident Response25%44
Forensics Investigation and Malware Analysis5%24
SOC for Cloud Environments5%24
Total100%250

💡 Study tip: Two modules — Incident Detection and Triage and Incident Response — are 25% each, so together they are half the exam; master SIEM correlation, alert triage, and the incident-response phase order first. Log Management (15%) is the foundation underneath detection, so learn your Windows Event IDs, Sysmon events, and log sources cold. Do not neglect the smaller modules: the SIEM detection questions reward knowing the right log source and correlation logic, and the cloud module tests Azure Sentinel, AWS Security Hub, and GCP Security Command Center side by side — never mix up which service belongs to which cloud.

Practice Exam — 250 Questions

Prepare for the CSA v2 exam with our 250-question practice exam covering all 8 modules. Every question includes detailed explanations, why-wrong analysis, and exam tips, and maps to the official CSA v2 module blueprint.

What you get:

  • ✅ Exam simulation mode with timer
  • ✅ Spaced repetition for weak areas
  • ✅ Detailed explanations for every question
  • ✅ Progress tracking across domains
  • ✅ 20 free questions — no account needed

EC-Council Certification Path

CSA is EC-Council’s dedicated SOC-analyst credential. It pairs naturally with CTIA (threat intelligence) for the proactive-detection side, feeds into E|CIH (incident handling) when you take the response lead, and sits alongside CHFI (forensics) for deep investigation and CEH (ethical hacking) for understanding the attacker’s playbook. There is no strict hierarchy — CSA is the natural choice if you work in, or are moving into, a Security Operations Center.

If you’re studying for the CSA exam, you might also be interested in these EC-Council certifications:

Study Tips

  1. Master SIEM detection and triage — the biggest module (25%): know how correlation rules combine events across sources within a time window, how to cut false positives, and how to triage an alert’s severity and escalate it
  2. Learn the incident-response phase order — the other 25% module: PICERL (Preparation, Identification, Containment, Eradication, Recovery, Lessons learned) and NIST SP 800-61; never eradicate before you contain and preserve evidence
  3. Know your log sources cold — Windows Security Event IDs (4624/4625/4688/4720), Sysmon events (1 process create, 3 network connect, 11 file create, 22 DNS query), Linux auditd/syslog, and firewall/web-server logs; the exam rewards picking the source that actually holds the field you need
  4. Map attacks to the Cyber Kill Chain and MITRE ATT&CK — distinguish an IoC (atomic artifact) from a TTP (behaviour), and know which kill-chain phase or ATT&CK tactic an observed activity belongs to
  5. Use threat intelligence and hunting proactively — know the CTI types (strategic, tactical, operational, technical — tactical = TTPs), the intel lifecycle, and hypothesis- vs IoC- vs TTP-based hunting with PowerShell and YARA
  6. Don’t mix up cloud SOC tools — Azure = Microsoft Sentinel / Defender for Cloud; AWS = Security Hub / CloudTrail / GuardDuty; GCP = Security Command Center / Chronicle / Cloud Audit Logs
  7. Use our practice exam — try the 20 free questions first to gauge your readiness, then use timed exam mode to practise under pressure
20 Free Questions Practice Exam $9 →