Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-COUNCIL

EC-Council Certified SOC Analyst

CSACertified SOC Analyst (C|SA)

The EC-Council Certified SOC Analyst (CSA) certification validates your ability to detect, investigate, and respond to security threats in a Security Operations Center. It covers SOC operations, SIEM deployment, log management, incident triage, and threat intelligence. Earning CSA demonstrates you have the hands-on skills to monitor, analyze, and escalate alerts effectively, making you a valuable asset to any security team.

701 practice questions · Updated 2026-07-30

6Domains
15Objectives
130Concepts
701Questions

CSA Curriculum

Every domain, objective, and concept the CSA exam measures.

  1. SOC Definition and Purpose
  2. SOC Roles and Responsibilities
  3. SOC Organizational Models
  4. SOC Processes and Procedures
  5. SOC Technologies and Tools
  6. SOC Metrics and KPIs
  7. SOC Maturity Models
  8. SOC Challenges and Best Practices

SOC Components, Workflow, and Metrics

3 concepts · 41 questions
  1. SOC Components
  2. SOC Workflow
  3. SOC Metrics

Understanding Cyber Threats and Attacks

10 concepts · 54 questions
  1. Cyber Threat Landscape
  2. Attack Vectors and Surfaces
  3. Malware Types and Behaviors
  4. Social Engineering Techniques
  5. Network Attacks
  6. Web Application Attacks
  7. Insider Threats
  8. Advanced Persistent Threats (APTs)
  9. Attack Lifecycle and Kill Chain
  10. Threat Intelligence

Indicators of Compromise (IoCs)

10 concepts · 45 questions
  1. Definition of IoCs
  2. Types of IoCs
  3. IoCs vs. TTPs
  4. Sources of IoCs
  5. IoCs in the Attack Lifecycle
  6. Collecting IoCs
  7. Analyzing IoCs
  8. Using IoCs for Detection
  9. Limitations of IoCs
  10. IoCs in Incident Response
  1. Attacker Methodology Overview
  2. Cyber Kill Chain Phases
  3. Reconnaissance
  4. Weaponization
  5. Delivery
  6. Exploitation
  7. Installation
  8. Command and Control (C2)
  9. Actions on Objectives
  10. Mapping to MITRE ATT&CK
  11. Indicators of Compromise (IoCs)

Log Management and Correlation

10 concepts · 48 questions
  1. Log Management Fundamentals
  2. Log Sources and Types
  3. Log Collection and Aggregation
  4. Log Normalization and Parsing
  5. Log Retention and Archival
  6. Correlation Concepts
  7. Correlation Rules and Techniques
  8. Correlation Engines and SIEM Integration
  9. Use Cases for Correlation
  10. Correlation Challenges and Best Practices

SIEM Deployment and Architecture

9 concepts · 43 questions
  1. SIEM Architecture Components
  2. Data Collection Methods
  3. Log Normalization and Parsing
  4. Correlation Rules and Use Cases
  5. SIEM Deployment Models
  6. Scalability and Performance Tuning
  7. High Availability and Redundancy
  8. Integration with Other Security Tools
  9. SIEM Administration and Maintenance

Incident Detection with SIEM

8 concepts · 50 questions
  1. SIEM Fundamentals
  2. Log Sources and Collection
  3. Normalization and Parsing
  4. Correlation Rules and Use Cases
  5. Threat Intelligence Integration
  6. Alert Triage and Prioritization
  7. Investigation and Hunting
  8. Dashboards and Reporting
  1. Use Case Development Fundamentals
  2. Correlation Rule Basics
  3. Data Source Identification
  4. Rule Logic and Conditions
  5. False Positive and Negative Management
  6. Rule Testing and Validation
  7. Use Case Documentation
  8. Correlation Rule Lifecycle Management

Alert Triaging and Analysis

7 concepts · 35 questions
  1. Alert Triaging Fundamentals
  2. Alert Categorization and Prioritization
  3. Alert Enrichment and Contextualization
  4. False Positive and True Positive Identification
  5. Alert Correlation and Aggregation
  6. Alert Escalation and Response Decision-Making
  7. Alert Documentation and Reporting

Threat Intelligence

10 concepts · 51 questions
  1. Threat Intelligence Fundamentals
  2. Threat Intelligence Lifecycle
  3. Threat Intelligence Sources
  4. Threat Intelligence Types
  5. Indicators of Compromise (IoCs)
  6. Threat Intelligence Feeds
  7. Threat Intelligence Integration
  8. Threat Intelligence Analysis
  9. Threat Intelligence Sharing
  10. Threat Intelligence in Detection

Threat Hunting

10 concepts · 49 questions
  1. Threat Hunting Fundamentals
  2. Threat Hunting Process
  3. Hypothesis-Driven Hunting
  4. Data Sources and Collection
  5. Indicators of Compromise (IOCs)
  6. Indicators of Attack (IOAs)
  7. Tactics, Techniques, and Procedures (TTPs)
  8. Threat Hunting Tools and Techniques
  9. Hunting for Specific Threat Types
  10. Documentation and Reporting

Incident Response Process

9 concepts · 56 questions
  1. Incident Response Lifecycle
  2. Incident Classification and Triage
  3. Evidence Handling and Chain of Custody
  4. Forensic Imaging and Data Acquisition
  5. Memory and Disk Forensics
  6. Log Analysis and Correlation
  7. Containment, Eradication, and Recovery
  8. Post-Incident Activities and Reporting
  9. Cloud-Specific Incident Response
  1. Forensic Investigation Fundamentals
  2. Evidence Collection and Preservation
  3. Disk and Memory Forensics
  4. Network Forensics
  5. Malware Analysis Types and Process
  6. Static Malware Analysis
  7. Dynamic Malware Analysis
  8. Malware Evasion Techniques
  9. Cloud Forensics
  10. Cloud Incident Response

SOC for Cloud Environments

7 concepts · 50 questions
  1. Cloud SOC Fundamentals
  2. Cloud Logging and Monitoring
  3. Cloud Threat Detection
  4. Cloud Incident Response
  5. Cloud Forensics
  6. Cloud Security Tools and Automation
  7. Cloud Compliance and Governance
Ready to practice?Test your knowledge with exam-style questions or take an intelligent quiz tailored to your level.

Percentages reflect share of the current practice bank, not official exam weightings — no structured per-skill weight is published for CSA, so none is invented.