CND logo
Focused certification exam prep
Start practice

CND Exam Domains 2026: Complete Guide to All 8 Content Areas

TL;DR
  • The CND 312-38 exam is built on 8 domains from Exam Blueprint v4.0, not the 20 training modules.
  • Endpoint Protection is the single largest domain at 20% of the exam.
  • Enterprise Virtual, Cloud, and Wireless Network Protection and Incident Prediction tie for second at 15% each.
  • The exam is 100 multiple-choice questions with a four-hour limit, delivered via ECC Exam Portal or RPS.

The CND Exam Blueprint v4.0: What Changed

If you've looked at the CND v3 training syllabus and then opened the certification exam blueprint, you may have noticed something confusing: the numbers don't match. Official CND training is organized into 20 modules, and EC-Council's broader security messaging often references a Protect/Detect/Respond/Predict framework. But the actual 312-38 certification exam is scored against a completely separate structure: the CND Exam Blueprint v4.0, hosted by EC-Council in April 2024 and linked directly from the official certification page.

That blueprint defines exactly 8 domains, each with its own percentage weight. This is the document that determines what you're actually tested on, and it's the framework this guide follows. If you've been studying purely from training module numbering without cross-referencing the blueprint, you may be misallocating your review time. For a broader walkthrough of how to structure preparation around this blueprint, see our CND Study Guide 2026.

Why This Matters: Training modules and exam domains are not the same taxonomy. Candidates who study module-by-module without mapping content back to the 8 blueprint domains often over-prepare on low-weight areas and under-prepare on Endpoint Protection, the largest single domain.

Domain 1: Network Defense Management (10%)

Network Defense Management

This domain covers the governance layer of network defense: policies, security controls, risk management processes, and the organizational structures that make a defense program function. It's less about a specific tool and more about how a network security team is organized, how policies get enforced, and how defense-in-depth is planned at a program level.

  • Security policy design and enforcement frameworks
  • Network security controls: administrative, physical, and technical
  • Risk assessment and management methodologies as applied to network environments
  • Regulatory and compliance considerations relevant to network defense programs

Candidates sometimes underrate this domain because it feels "soft" compared to technical hands-on topics. Don't. At 10% of a 100-question exam, that's roughly ten questions built entirely around management concepts, not packet captures.

Domain 2: Network Perimeter Protection (10%)

Network Perimeter Protection

This domain focuses on the traditional edge of the network: firewalls, IDS/IPS, VPNs, and the architecture decisions that determine how traffic is filtered before it reaches internal assets.

  • Firewall types, rule design, and deployment topologies
  • Intrusion detection and prevention system configuration and tuning
  • VPN technologies and secure remote access architecture
  • Router and perimeter device hardening

Expect scenario-based questions here that ask you to identify the correct perimeter control for a described network problem, rather than pure definition recall.

Domain 3: Endpoint Protection (20%)

Endpoint Protection

This is the largest domain on the entire exam, worth double most other domains. Endpoint Protection covers securing the devices that connect to the network: workstations, servers, mobile devices, and the operating systems and applications running on them.

  • OS-level hardening for Windows and Linux endpoints
  • Endpoint detection and protection technologies (antivirus, EDR concepts, host firewalls)
  • Mobile device and removable media security controls
  • Patch management and configuration management for endpoint hygiene

Key Takeaway

Because Endpoint Protection carries 20% weight, roughly one in five exam questions touches this domain. It deserves proportionally more review sessions than any other single domain, and it's the domain most likely to determine whether you clear a higher-end cut score.

Domain 4: Application and Data Protection (10%)

Application and Data Protection

This domain shifts focus from infrastructure to the applications and data that run on top of it. It covers secure application design principles and the data-protection mechanisms needed to keep sensitive information safe in transit and at rest.

  • Application-layer security concepts and common weaknesses
  • Data encryption, classification, and data loss prevention approaches
  • Database security fundamentals as they relate to network-connected data stores
  • Email and web application protection considerations

Domain 5: Enterprise Virtual, Cloud, and Wireless Network Protection (15%)

Enterprise Virtual, Cloud, and Wireless Network Protection

This domain bundles three distinct environments - virtualization, cloud, and wireless - into a single high-weight domain. Because it ties for second-highest weight at 15%, it deserves dedicated study blocks rather than being treated as a minor add-on to perimeter protection.

  • Virtual network architecture and hypervisor-level security controls
  • Cloud security models and shared-responsibility considerations across service types
  • Wireless network standards, encryption protocols, and common wireless attack vectors
  • Enterprise-scale considerations when securing hybrid virtual/cloud/wireless environments

This is one of the domains most likely to trip up candidates whose hands-on experience skews toward traditional on-premises networking. If your background is light on cloud or virtualization, allocate extra time here.

Domain 6: Incident Detection (10%)

Incident Detection

Incident Detection covers the monitoring and analysis capabilities that let a defender identify that something has gone wrong: log analysis, SIEM concepts, and network traffic monitoring for anomalies.

  • Log management and correlation for detecting suspicious activity
  • SIEM fundamentals and alert triage concepts
  • Network traffic analysis for identifying indicators of compromise
  • Baseline establishment and anomaly identification

Domain 7: Incident Response (10%)

Incident Response

Where Incident Detection is about noticing a problem, Incident Response is about what happens next: containment, eradication, recovery, and the forensic handling needed to preserve evidence and restore operations.

  • Incident response process phases and team roles
  • Containment and eradication strategies for common incident types
  • Business continuity and disaster recovery integration with incident response
  • Basic forensic evidence handling principles relevant to network defenders

Domain 8: Incident Prediction (15%)

Incident Prediction

Tied with Domain 5 as the second-highest-weighted domain, Incident Prediction is about proactive defense: threat intelligence, vulnerability assessment, and risk forecasting that let a defender anticipate attacks before they happen rather than only reacting to them.

  • Threat intelligence sources and how they inform defensive posture
  • Vulnerability assessment methodologies and prioritization
  • Attack surface analysis and threat modeling basics
  • Risk forecasting concepts applied to network environments

Because this domain carries the same weight as the cloud/virtual/wireless domain, candidates who focus heavily on reactive skills (detection and response) while skipping predictive concepts leave a meaningful chunk of the exam under-covered.

How Domain Weighting Should Drive Your Study Plan

With 100 questions distributed across 8 domains at uneven weights, not all study hours are equal. A simple way to think about it: Domain 3 alone (20%) carries as much weight as Domains 1, 2, and 6 combined. Domains 5 and 8 (15% each) together outweigh any three of the 10% domains combined.

DomainWeightApprox. Questions (of 100)
Endpoint Protection20%~20
Enterprise Virtual, Cloud, and Wireless Network Protection15%~15
Incident Prediction15%~15
Network Defense Management10%~10
Network Perimeter Protection10%~10
Application and Data Protection10%~10
Incident Detection10%~10
Incident Response10%~10

A practical weekly structure might allocate proportionally more time to the heavier domains early, while still cycling through every domain before test day:

Week 1

Endpoint Protection deep dive

  • Cover OS hardening, EDR concepts, and mobile/removable media controls given this domain's 20% weight
Week 2

Cloud, virtual, and wireless protection

  • Work through shared-responsibility models and wireless attack vectors
Week 3

Incident Prediction and Detection

  • Pair threat intelligence concepts with SIEM/log analysis to reinforce overlap
Week 4

Remaining 10% domains plus full review

  • Cover Management, Perimeter, Application/Data, and Response, then run timed practice sets

For a full breakdown of pacing across a longer runway, our CND Study Guide 2026 lays out a complete first-attempt strategy, and our CND Cheat Sheet 2026 is useful for last-week review across all 8 domains.

Exam Format and Question Style

The 312-38 exam consists of 100 multiple-choice questions delivered under a four-hour time limit, through the ECC Exam Center/EC-Council Exam Portal at an authorized testing center or via EC-Council Remote Proctoring Services (RPS). Unlike the hands-on training labs in CND v3, the certification exam itself is entirely multiple choice - it does not require you to perform live configuration tasks during the test.

One detail candidates frequently overlook: passing cut scores are form-specific and range from 60% to 85%. This is not a pass rate - it's the threshold you personally need to clear on your specific exam form. Because you won't know your form's exact cut score in advance, the safest strategy is to prepare as though you need to hit the higher end of that range, especially on Endpoint Protection, Domain 5, and Domain 8 given their weight. Our CND Passing Score 2026 guide breaks this down in more detail, and How Hard Is the CND Exam? covers what makes the question style challenging beyond raw content knowledge.

Registration Reality Check: Self-study candidates pay a $100 nonrefundable eligibility-application fee plus a $550 RPS exam voucher (valid one year), totaling $650 before study materials, and must document two years of information-security work experience for approval. The alternative path is official training, whose price already incorporates the eligibility fee. See CND Certification Cost 2026 and CND Requirements 2026 for the full mechanics.

Who Actually Hires for These Domains

The 8-domain structure maps fairly directly to real network defense job responsibilities. Employers hiring for SOC analyst, network security administrator, and network defense technician roles tend to value exactly the skill clusters these domains represent: perimeter and endpoint hardening, cloud/wireless security awareness, and the detect-respond-predict cycle that keeps a network resilient.

If you're evaluating whether this certification aligns with your career goals, our CND Jobs guide covers typical roles, and CND Salary Guide 2026 and Is the CND Certification Worth It? examine the broader ROI question. For newcomers still deciding whether this is the right credential, What Is CND Certification? and CND Certification provide foundational context, and if you've landed here confused by naming overlap with other "CND" acronyms, CND Meaning and What Does CND Stand For? clarify which credential this article covers.

Once you're ready to test your domain-by-domain readiness, practicing with realistic questions on our CND practice test platform is one of the most direct ways to see which of the 8 domains still need work before you book your exam slot. Many candidates run through several timed sets on the practice site specifically to stress-test their Endpoint Protection and Domain 5 knowledge, given how heavily those two areas are weighted.

Frequently Asked Questions

Are the 8 exam domains the same as the 20 CND v3 training modules?

No. The certification exam is scored against the 8 domains defined in CND Exam Blueprint v4.0, while CND v3 training content is organized into 20 separate modules. They cover overlapping material but use different structures.

Which domain should I prioritize if I'm short on study time?

Endpoint Protection at 20% is the single largest domain, followed by Enterprise Virtual, Cloud, and Wireless Network Protection and Incident Prediction, each at 15%. Together these three domains account for half the exam's weight.

Is the CND exam itself hands-on, like the training labs?

No. The 312-38 certification exam is 100 multiple-choice questions with a four-hour limit. The hands-on labs are part of the separate CND v3 training program, not the certification exam.

What score do I need to pass?

Passing cut scores are form-specific and range from 60% to 85% depending on which exam form you receive. This is a threshold, not a published pass rate, so aim to prepare toward the higher end of that range across all 8 domains.

Where can I find the official domain breakdown?

EC-Council's certification page links directly to CND Exam Blueprint v4.0, hosted in April 2024, which lists all 8 domains and their exact weightings used to build the 312-38 exam.

Ready to pass your CND exam?

Put this into practice with free CND questions across every exam domain.