Our accelerated courses are available online
Join Now!

EC-Council - Certified SOC Analyst (CSA)



Only 2 Days



Classroom / Online / Hybrid

Next date

Next date:

7.2.2022 (Monday)


On this accelerated EC-Council Certified SOC Analyst (CSA) course, you'll learn to identify, monitor and analyse cyber-attacks, and use the information to quickly respond to security incidents.

In just 2 days, you'll build the skill-set you need to work effectively within a security operations centre (SOC). You'll also learn about security information and event management (SIEM), deployment and architecture.

At the end of your course, you'll sit Exam 312-39 and return to the office an EC-Council Certified SOC Analyst (CSA).

On this accelerated course, you'll learn how to:

  • Recognise attacker tools, behaviours, tools and procedures
  • Use the Centralised Log Management (CLM) process
  • Make use of constantly changing threat information

If you're an aspiring SOC analyst or already are one at a Tier 1 and Tier 2 level, this course is ideal for you.

This course is also designed for security professionals who handle and manage network security operations, like network and security administrators or engineers, or network security operators.

You’ll train at twice the speed with Firebrand's unique Lecture | Lab | Review methodology. Learn in a distraction-free environment and become an EC-Council Certified SOC Analyst (CSA) in just 2 days.

Four reasons why you should sit your EC-Council CSA course with Firebrand Training

  1. You'll be EC-Council CSA trained and certified faster. Learn more on this 2-day accelerated course. You'll get at least 12 hours a day of quality learning time in a distraction-free environment
  2. Your EC-Council CSA course is all-inclusive. One simple price covers all course materials, exams, accommodation and meals – so you can focus on learning
  3. Pass EC-Council CSA first time or train again for free. Your expert instructor will deliver our unique accelerated learning methods, allowing you to learn faster and be in the best possible position to pass first time. In the unlikely event that you don't, it's covered by your Certification Guarantee
  4. Study EC-Council CSA with an award-winning training provider. We've won the Learning and Performance Institute's "Training Company of the Year" three times. Firebrand is your fastest way to learn, with 111679 students saving more than one million hours since 2001


Benefits of Training with Firebrand

  • Two options of training - Residential classroom-based, or online courses
  • A purpose-built training centre – get access to dedicated Pearson VUE Select facilities.
  • Certification Guarantee – pass first time or train again free (just pay for accommodation, exams and incidental costs)
  • Everything you need to certify – you’ll sit your exam at the earliest available opportunity after the course - either immediately after your classroom course, or as soon as there are slots available, if you've taken it online
  • No hidden extras – one cost covers everything you need to certify


Module 1: Security operations and management

  • Understand the SOC Fundamentals
  • Discuss the components of SOC: People, processes and technology
  • Understand the implementation of SOC

Module 2: Understanding cyber threats, IoCs, and attack methodology

  • 2.1 Describe the term cyber threats and attacks
  • 2.2 Understand the Network Level attacks
  • 2.3 Understand the Host Level attacks
  • 2.4 Understand the Application Level attacks
  • 2.5 Understand the Indicators of Compromise (IoCs)
  • 2.6 Discuss the attacker’s Hacking Methodology

Module 3: Incidents, events and logging

  • 3.1 Understand the fundamentals of incidents, events, and logging
  • 3.2 Explain the concepts of local logging
  • 3.3 Explain the concepts of centralised logging

Module 4: Incident detection with Security Information and Event Management (SIEM)

  • 4.1 Understand the basic concepts of Security Information and Event Management (SIEM)
  • 4.2 Discuss the different SIEM Solutions
  • 4.3 Understand the SIEM Deployment
  • 4.4 Learn different use case examples for Application Level Incident Detection
  • 4.5 Learn different use case examples for Insider Incident Detection
  • 4.6 Learn different use case examples for Network Level Incident Detection
  • 4.7 Learn different use case examples for Host Level Incident Detection
  • 4.8 Learn different use case examples for Compliance
  • 4.9 Understand the concept of handling alert triaging and analysis

Module 5: Enhanced incident detection with threat intelligence

  • 5.1 Learn fundamental concepts on threat intelligence
  • 5.2 Learn different types of threat intelligence
  • 5.3 Understand how threat intelligence strategy is developed
  • 5.4 Learn different threat intelligence sources from which intelligence can be obtained
  • 5.5 Learn different Threat Intelligence Platform (TIP)
  • 5.6 Understand the need of threat intelligence-driven SOC

Module 6: Incident response

  • 6.1 Understand the fundamental concepts of incident response
  • 6.2 Learn various phases in Incident Response Process
  • 6.3 Learn how to respond to Network Security Incidents
  • 6.4 Learn how to respond to Application Security Incidents
  • 6.5 Learn how to respond to Email Security Incidents
  • 6.6 Learn how to respond to Insider Incidents
  • 6.7 Learn how to respond to Malware Incidents

Exam Track

You'll sit the following exam at the Firebrand Training centre, covered by your Certification Guarantee:

  • EC-Council Certified SOC Analyst (CSA) - Exam 312-39
    • Exam format: Multiple-choice
    • Exam duration: 120 minutes
    • Number of questions: 100
    • Passing score: 70%
    • Language: English
    • Domains:
      • 1: Security operations and management (5%)
      • 2: Understanding cyber threats, IoCs, and attack methodology (11%)
      • 3: Incidents, events and logging (21%)
      • 4: Incident detection with Security Information and Event Management (SIEM) (26%)
      • 5: Enhanced incident detection with threat intelligence (8%)
      • 6: Incident response (29%)

What's Included

Your accelerated course includes:

  • Accommodation *
  • Meals, unlimited snacks, beverages, tea and coffee *
  • On-site exams **
  • Exam vouchers **
  • Practice tests **
  • Certification Guarantee ***
  • Courseware
  • Up-to 12 hours of instructor-led training each day
  • 24-hour lab access
  • Digital courseware **
  • * For residential training only. Doesn't apply for online courses
  • ** Some exceptions apply. Please refer to the Exam Track or speak with our experts
  • *** Pass first time or train again free (just pay for accommodation, exams and incidental costs)


Before attending this accelerated course, you should have 1 year of work experience in network admin or security.

Unsure whether you meet the prerequisites? Don’t worry. Your training consultant will discuss your background with you to understand if this course is right for you.


Here's the Firebrand Training review section. Since 2001 we've trained exactly 111679 students and asked them all to review our Accelerated Learning. Currently, 96.66% have said Firebrand exceeded their expectations.

Read reviews from recent accelerated courses below or visit Firebrand Stories for written and video interviews from our alumni.

"Trainer was very good and had a deep knowledge, which he transported very well."
Anonymous, Gothaer Systems GmbH (4.5.2020 (Monday) to 8.5.2020 (Friday))

"Good training also for people without much experience."
Anonymous (24.7.2018 (Tuesday) to 25.7.2018 (Wednesday))

"Extraordinary good trainer! He was skilled, well educated and made course material a lot more understandable by giving examples from his own professional experience. The training itself was well prepared and well organized."
Malte Fiedler , T-Systems. (28.5.2018 (Monday) to 31.5.2018 (Thursday))

"Courses are given in an interactive way by a highly qualified trainer which makes the courses very lively and interesting to follow."
Anonymous (28.5.2018 (Monday) to 31.5.2018 (Thursday))

"Firebrand recommended! Good enviroment, good instruction."
Anonymous (15.5.2017 (Monday) to 19.5.2017 (Friday))

Course Dates





Book now

23.8.2021 (Monday)

24.8.2021 (Tuesday)

Finished - Leave feedback




7.2.2022 (Monday)

8.2.2022 (Tuesday)

Limited availability



21.3.2022 (Monday)

22.3.2022 (Tuesday)




2.5.2022 (Monday)

3.5.2022 (Tuesday)




13.6.2022 (Monday)

14.6.2022 (Tuesday)




Latest Reviews from our students