
EC-Council Certified SOC Analyst
The EC-Council Certified SOC Analyst (CSA) certification validates your ability to detect, investigate, and respond to security threats in a Security Operations Center. It covers SOC operations, SIEM deployment, log management, incident triage, and threat intelligence. Earning CSA demonstrates you have the hands-on skills to monitor, analyze, and escalate alerts effectively, making you a valuable asset to any security team.
701 practice questions · Updated 2026-07-30
6Domains
15Objectives
130Concepts
701Questions
CSA Curriculum
Every domain, objective, and concept the CSA exam measures.
- SOC Definition and Purpose
- SOC Roles and Responsibilities
- SOC Organizational Models
- SOC Processes and Procedures
- SOC Technologies and Tools
- SOC Metrics and KPIs
- SOC Maturity Models
- SOC Challenges and Best Practices
- SOC Components
- SOC Workflow
- SOC Metrics
- Cyber Threat Landscape
- Attack Vectors and Surfaces
- Malware Types and Behaviors
- Social Engineering Techniques
- Network Attacks
- Web Application Attacks
- Insider Threats
- Advanced Persistent Threats (APTs)
- Attack Lifecycle and Kill Chain
- Threat Intelligence
- Definition of IoCs
- Types of IoCs
- IoCs vs. TTPs
- Sources of IoCs
- IoCs in the Attack Lifecycle
- Collecting IoCs
- Analyzing IoCs
- Using IoCs for Detection
- Limitations of IoCs
- IoCs in Incident Response
- Attacker Methodology Overview
- Cyber Kill Chain Phases
- Reconnaissance
- Weaponization
- Delivery
- Exploitation
- Installation
- Command and Control (C2)
- Actions on Objectives
- Mapping to MITRE ATT&CK
- Indicators of Compromise (IoCs)
- Log Management Fundamentals
- Log Sources and Types
- Log Collection and Aggregation
- Log Normalization and Parsing
- Log Retention and Archival
- Correlation Concepts
- Correlation Rules and Techniques
- Correlation Engines and SIEM Integration
- Use Cases for Correlation
- Correlation Challenges and Best Practices
- SIEM Architecture Components
- Data Collection Methods
- Log Normalization and Parsing
- Correlation Rules and Use Cases
- SIEM Deployment Models
- Scalability and Performance Tuning
- High Availability and Redundancy
- Integration with Other Security Tools
- SIEM Administration and Maintenance
- SIEM Fundamentals
- Log Sources and Collection
- Normalization and Parsing
- Correlation Rules and Use Cases
- Threat Intelligence Integration
- Alert Triage and Prioritization
- Investigation and Hunting
- Dashboards and Reporting
- Use Case Development Fundamentals
- Correlation Rule Basics
- Data Source Identification
- Rule Logic and Conditions
- False Positive and Negative Management
- Rule Testing and Validation
- Use Case Documentation
- Correlation Rule Lifecycle Management
- Alert Triaging Fundamentals
- Alert Categorization and Prioritization
- Alert Enrichment and Contextualization
- False Positive and True Positive Identification
- Alert Correlation and Aggregation
- Alert Escalation and Response Decision-Making
- Alert Documentation and Reporting
- Threat Intelligence Fundamentals
- Threat Intelligence Lifecycle
- Threat Intelligence Sources
- Threat Intelligence Types
- Indicators of Compromise (IoCs)
- Threat Intelligence Feeds
- Threat Intelligence Integration
- Threat Intelligence Analysis
- Threat Intelligence Sharing
- Threat Intelligence in Detection
- Threat Hunting Fundamentals
- Threat Hunting Process
- Hypothesis-Driven Hunting
- Data Sources and Collection
- Indicators of Compromise (IOCs)
- Indicators of Attack (IOAs)
- Tactics, Techniques, and Procedures (TTPs)
- Threat Hunting Tools and Techniques
- Hunting for Specific Threat Types
- Documentation and Reporting
- Incident Response Lifecycle
- Incident Classification and Triage
- Evidence Handling and Chain of Custody
- Forensic Imaging and Data Acquisition
- Memory and Disk Forensics
- Log Analysis and Correlation
- Containment, Eradication, and Recovery
- Post-Incident Activities and Reporting
- Cloud-Specific Incident Response
- Forensic Investigation Fundamentals
- Evidence Collection and Preservation
- Disk and Memory Forensics
- Network Forensics
- Malware Analysis Types and Process
- Static Malware Analysis
- Dynamic Malware Analysis
- Malware Evasion Techniques
- Cloud Forensics
- Cloud Incident Response
- Cloud SOC Fundamentals
- Cloud Logging and Monitoring
- Cloud Threat Detection
- Cloud Incident Response
- Cloud Forensics
- Cloud Security Tools and Automation
- Cloud Compliance and Governance
Ready to practice?Test your knowledge with exam-style questions or take an intelligent quiz tailored to your level.
Percentages reflect share of the current practice bank, not official exam weightings — no structured per-skill weight is published for CSA, so none is invented.