HanuxLearning
Loading…
Have a voucher code? Redeem it and reserve your seat
Grab your voucher →HanuxLearning
Loading…
EC-Council Certified SOC Analyst (CSA) training and exam prep - become a Security Operations Center analyst skilled in SIEM, threat intelligence and incident response.
Group Enrollment with Friends or Colleagues | Get a quote

EC-Council's Certified SOC Analyst (CSA) is the certification for the Security Operations Center (SOC) analyst role. It prepares Tier 1 and Tier 2 analysts to monitor, detect, triage and respond to security alerts. The lab-intensive program covers SOC operations and management, log management and correlation, SIEM (Security Information and Event Management) deployment and use, enhanced incident detection with threat intelligence, and incident response - all mapped to real SOC workflows, MITRE ATT&CK and the cyber kill chain. The certification is earned by one exam (code 312-39): 100 multiple-choice questions in 3 hours (confirm current duration), taken online through the EC-Council Exam Portal or at an authorised centre. The passing score is 70% - EC-Council uses a form-dependent cut score, so it can vary slightly by exam version.
The EC-Council Certified SOC Analyst (CSA) is the certification for the Security Operations Center (SOC) analyst role. It validates the skills needed by Tier 1 and Tier 2 analysts to monitor, detect, triage and respond to security alerts. The program covers SOC operations and management, log management and correlation, SIEM (Security Information and Event Management), enhanced incident detection with threat intelligence, and incident response - mapped to real SOC workflows, MITRE ATT&CK and the cyber kill chain. The SOC analyst is one of the most in-demand, entry-friendly roles in cybersecurity - and CSA is built specifically for it. The course teaches the exact skills SOC teams hire for: SIEM, log analysis, alert triage, threat intelligence and incident response, all mapped to MITRE ATT&CK and the cyber kill chain. It is a strong first step into security operations and a natural companion to network defence (CND) and incident handling (ECIH).
Source: Glassdoor
Source: Indeed
Annual Salary
Source: Glassdoor
Hiring Companies
Source: Indeed
Batch starting from:
CSA is ideal for people entering or working in security operations: - Aspiring and current SOC analysts (Tier 1 / Tier 2) - Security and network administrators moving into a SOC - Cybersecurity analysts who want structured SIEM and incident-response skills - Anyone building a career in blue-team / defensive security
How to earn it:
1. Prepare with a CSA exam-prep course with hands-on SIEM labs - that is what we provide.
2. Meet eligibility: attend official training, OR show 1 year of Network Admin / Security experience (proof via the EC-Council application process).
3. Register for the ex...
The EC-Council Certified SOC Analyst (CSA) certification validates your ability to monitor, detect, investigate, and respond to cybersecurity threats within a Security Operations Center (SOC) environment. The exam assesses your knowledge of SOC operations, security monitoring, threat intelligence, log analysis, incident detection, SIEM technologies, network security monitoring, and incident response processes. Understanding the exam structure and certification requirements can help you plan your preparation effectively and build confidence before the assessment. This section explains the exam pattern, question format, duration, certification requirements, SOC-focused assessment areas, and other important details you should know before taking the EC-Council Certified SOC Analyst (312-39) exam.
Exam details verified on 16 August 2026. The CSA exam (312-39) is 100 multiple-choice questions in 3 hours (confirm current duration); the passing score is 70% (a form-dependent cut score). It is valid 3 years and maintained with 120 ECE credits plus an annual membership fee. Exam pricing varies (commonly cited around US$250-$450). Confirm current details and pricing at eccouncil.org, and confirm CSA's DoD status at the DoD Cyber Exchange.
CSA is aimed at people entering or working in security operations: - Aspiring and current SOC analysts (Tier 1 / Tier 2) - Security and network administrators moving into a SOC - Cybersecurity analysts wanting structured SIEM and incident-response skills - Anyone building a blue-team / defensive security career If you want the broader network-defence picture first, our Certified Network Defender (CND) course is a strong companion; for incident handling, see ECIH.