- The CND Exam Blueprint v4.0: What Changed
- Domain 1: Network Defense Management
- Domain 2: Network Perimeter Protection
- Domain 3: Endpoint Protection
- Domain 4: Application and Data Protection
- Domain 5: Enterprise Virtual, Cloud, and Wireless Network Protection
- Domain 6: Incident Detection
- Domain 7: Incident Response
- Domain 8: Incident Prediction
- How Domain Weighting Should Drive Your Study Plan
- Exam Format and Question Style
- Who Actually Hires for These Domains
- FAQs
- The CND 312-38 exam is built on 8 domains from Exam Blueprint v4.0, not the 20 training modules.
- Endpoint Protection is the single largest domain at 20% of the exam.
- Enterprise Virtual, Cloud, and Wireless Network Protection and Incident Prediction tie for second at 15% each.
- The exam is 100 multiple-choice questions with a four-hour limit, delivered via ECC Exam Portal or RPS.
The CND Exam Blueprint v4.0: What Changed
If you've looked at the CND v3 training syllabus and then opened the certification exam blueprint, you may have noticed something confusing: the numbers don't match. Official CND training is organized into 20 modules, and EC-Council's broader security messaging often references a Protect/Detect/Respond/Predict framework. But the actual 312-38 certification exam is scored against a completely separate structure: the CND Exam Blueprint v4.0, hosted by EC-Council in April 2024 and linked directly from the official certification page.
That blueprint defines exactly 8 domains, each with its own percentage weight. This is the document that determines what you're actually tested on, and it's the framework this guide follows. If you've been studying purely from training module numbering without cross-referencing the blueprint, you may be misallocating your review time. For a broader walkthrough of how to structure preparation around this blueprint, see our CND Study Guide 2026.
Domain 1: Network Defense Management (10%)
Network Defense Management
This domain covers the governance layer of network defense: policies, security controls, risk management processes, and the organizational structures that make a defense program function. It's less about a specific tool and more about how a network security team is organized, how policies get enforced, and how defense-in-depth is planned at a program level.
- Security policy design and enforcement frameworks
- Network security controls: administrative, physical, and technical
- Risk assessment and management methodologies as applied to network environments
- Regulatory and compliance considerations relevant to network defense programs
Candidates sometimes underrate this domain because it feels "soft" compared to technical hands-on topics. Don't. At 10% of a 100-question exam, that's roughly ten questions built entirely around management concepts, not packet captures.
Domain 2: Network Perimeter Protection (10%)
Network Perimeter Protection
This domain focuses on the traditional edge of the network: firewalls, IDS/IPS, VPNs, and the architecture decisions that determine how traffic is filtered before it reaches internal assets.
- Firewall types, rule design, and deployment topologies
- Intrusion detection and prevention system configuration and tuning
- VPN technologies and secure remote access architecture
- Router and perimeter device hardening
Expect scenario-based questions here that ask you to identify the correct perimeter control for a described network problem, rather than pure definition recall.
Domain 3: Endpoint Protection (20%)
Endpoint Protection
This is the largest domain on the entire exam, worth double most other domains. Endpoint Protection covers securing the devices that connect to the network: workstations, servers, mobile devices, and the operating systems and applications running on them.
- OS-level hardening for Windows and Linux endpoints
- Endpoint detection and protection technologies (antivirus, EDR concepts, host firewalls)
- Mobile device and removable media security controls
- Patch management and configuration management for endpoint hygiene
Key Takeaway
Because Endpoint Protection carries 20% weight, roughly one in five exam questions touches this domain. It deserves proportionally more review sessions than any other single domain, and it's the domain most likely to determine whether you clear a higher-end cut score.
Domain 4: Application and Data Protection (10%)
Application and Data Protection
This domain shifts focus from infrastructure to the applications and data that run on top of it. It covers secure application design principles and the data-protection mechanisms needed to keep sensitive information safe in transit and at rest.
- Application-layer security concepts and common weaknesses
- Data encryption, classification, and data loss prevention approaches
- Database security fundamentals as they relate to network-connected data stores
- Email and web application protection considerations
Domain 5: Enterprise Virtual, Cloud, and Wireless Network Protection (15%)
Enterprise Virtual, Cloud, and Wireless Network Protection
This domain bundles three distinct environments - virtualization, cloud, and wireless - into a single high-weight domain. Because it ties for second-highest weight at 15%, it deserves dedicated study blocks rather than being treated as a minor add-on to perimeter protection.
- Virtual network architecture and hypervisor-level security controls
- Cloud security models and shared-responsibility considerations across service types
- Wireless network standards, encryption protocols, and common wireless attack vectors
- Enterprise-scale considerations when securing hybrid virtual/cloud/wireless environments
This is one of the domains most likely to trip up candidates whose hands-on experience skews toward traditional on-premises networking. If your background is light on cloud or virtualization, allocate extra time here.
Domain 6: Incident Detection (10%)
Incident Detection
Incident Detection covers the monitoring and analysis capabilities that let a defender identify that something has gone wrong: log analysis, SIEM concepts, and network traffic monitoring for anomalies.
- Log management and correlation for detecting suspicious activity
- SIEM fundamentals and alert triage concepts
- Network traffic analysis for identifying indicators of compromise
- Baseline establishment and anomaly identification
Domain 7: Incident Response (10%)
Incident Response
Where Incident Detection is about noticing a problem, Incident Response is about what happens next: containment, eradication, recovery, and the forensic handling needed to preserve evidence and restore operations.
- Incident response process phases and team roles
- Containment and eradication strategies for common incident types
- Business continuity and disaster recovery integration with incident response
- Basic forensic evidence handling principles relevant to network defenders
Domain 8: Incident Prediction (15%)
Incident Prediction
Tied with Domain 5 as the second-highest-weighted domain, Incident Prediction is about proactive defense: threat intelligence, vulnerability assessment, and risk forecasting that let a defender anticipate attacks before they happen rather than only reacting to them.
- Threat intelligence sources and how they inform defensive posture
- Vulnerability assessment methodologies and prioritization
- Attack surface analysis and threat modeling basics
- Risk forecasting concepts applied to network environments
Because this domain carries the same weight as the cloud/virtual/wireless domain, candidates who focus heavily on reactive skills (detection and response) while skipping predictive concepts leave a meaningful chunk of the exam under-covered.
How Domain Weighting Should Drive Your Study Plan
With 100 questions distributed across 8 domains at uneven weights, not all study hours are equal. A simple way to think about it: Domain 3 alone (20%) carries as much weight as Domains 1, 2, and 6 combined. Domains 5 and 8 (15% each) together outweigh any three of the 10% domains combined.
| Domain | Weight | Approx. Questions (of 100) |
|---|---|---|
| Endpoint Protection | 20% | ~20 |
| Enterprise Virtual, Cloud, and Wireless Network Protection | 15% | ~15 |
| Incident Prediction | 15% | ~15 |
| Network Defense Management | 10% | ~10 |
| Network Perimeter Protection | 10% | ~10 |
| Application and Data Protection | 10% | ~10 |
| Incident Detection | 10% | ~10 |
| Incident Response | 10% | ~10 |
A practical weekly structure might allocate proportionally more time to the heavier domains early, while still cycling through every domain before test day:
Endpoint Protection deep dive
- Cover OS hardening, EDR concepts, and mobile/removable media controls given this domain's 20% weight
Cloud, virtual, and wireless protection
- Work through shared-responsibility models and wireless attack vectors
Incident Prediction and Detection
- Pair threat intelligence concepts with SIEM/log analysis to reinforce overlap
Remaining 10% domains plus full review
- Cover Management, Perimeter, Application/Data, and Response, then run timed practice sets
For a full breakdown of pacing across a longer runway, our CND Study Guide 2026 lays out a complete first-attempt strategy, and our CND Cheat Sheet 2026 is useful for last-week review across all 8 domains.
Exam Format and Question Style
The 312-38 exam consists of 100 multiple-choice questions delivered under a four-hour time limit, through the ECC Exam Center/EC-Council Exam Portal at an authorized testing center or via EC-Council Remote Proctoring Services (RPS). Unlike the hands-on training labs in CND v3, the certification exam itself is entirely multiple choice - it does not require you to perform live configuration tasks during the test.
One detail candidates frequently overlook: passing cut scores are form-specific and range from 60% to 85%. This is not a pass rate - it's the threshold you personally need to clear on your specific exam form. Because you won't know your form's exact cut score in advance, the safest strategy is to prepare as though you need to hit the higher end of that range, especially on Endpoint Protection, Domain 5, and Domain 8 given their weight. Our CND Passing Score 2026 guide breaks this down in more detail, and How Hard Is the CND Exam? covers what makes the question style challenging beyond raw content knowledge.
Who Actually Hires for These Domains
The 8-domain structure maps fairly directly to real network defense job responsibilities. Employers hiring for SOC analyst, network security administrator, and network defense technician roles tend to value exactly the skill clusters these domains represent: perimeter and endpoint hardening, cloud/wireless security awareness, and the detect-respond-predict cycle that keeps a network resilient.
If you're evaluating whether this certification aligns with your career goals, our CND Jobs guide covers typical roles, and CND Salary Guide 2026 and Is the CND Certification Worth It? examine the broader ROI question. For newcomers still deciding whether this is the right credential, What Is CND Certification? and CND Certification provide foundational context, and if you've landed here confused by naming overlap with other "CND" acronyms, CND Meaning and What Does CND Stand For? clarify which credential this article covers.
Once you're ready to test your domain-by-domain readiness, practicing with realistic questions on our CND practice test platform is one of the most direct ways to see which of the 8 domains still need work before you book your exam slot. Many candidates run through several timed sets on the practice site specifically to stress-test their Endpoint Protection and Domain 5 knowledge, given how heavily those two areas are weighted.
Frequently Asked Questions
No. The certification exam is scored against the 8 domains defined in CND Exam Blueprint v4.0, while CND v3 training content is organized into 20 separate modules. They cover overlapping material but use different structures.
Endpoint Protection at 20% is the single largest domain, followed by Enterprise Virtual, Cloud, and Wireless Network Protection and Incident Prediction, each at 15%. Together these three domains account for half the exam's weight.
No. The 312-38 certification exam is 100 multiple-choice questions with a four-hour limit. The hands-on labs are part of the separate CND v3 training program, not the certification exam.
Passing cut scores are form-specific and range from 60% to 85% depending on which exam form you receive. This is a threshold, not a published pass rate, so aim to prepare toward the higher end of that range across all 8 domains.
EC-Council's certification page links directly to CND Exam Blueprint v4.0, hosted in April 2024, which lists all 8 domains and their exact weightings used to build the 312-38 exam.