- CND job titles cluster around network security administration, SOC analysis, and incident handling roles tied to the 8 blueprint domains.
- Endpoint Protection is 20% of the exam, the single largest domain, mirroring how much endpoint work shows up in defender job postings.
- Exam 312-38 is 100 multiple-choice questions in four hours, delivered via ECC Exam Center or EC-Council RPS.
- Self-study eligibility costs $100 plus the $550 RPS voucher, totaling $650, and requires two years of documented infosec experience.
What "CND Jobs" Actually Means
When people search "CND jobs," they're usually asking one of two questions: what roles hire candidates who hold the Certified Network Defender credential, and what does the day-to-day work of a network defender actually involve. Both questions trace back to the same source - the eight domains of the CND Exam Blueprint v4.0 published by EC-Council. Unlike training-only curricula, the exam domains are the blueprint hiring managers implicitly reference when they write job descriptions for network security roles, because they describe measurable, testable skill areas rather than vague responsibilities.
If you're evaluating whether to pursue this credential for career purposes, it helps to separate two things: the certification itself (exam 312-38, administered by EC-Council) and the job market that values it. This article focuses on the latter - where CND-holders actually work, what roles list the credential, and how the domain weighting predicts what you'll be doing once hired.
Who Hires Certified Network Defender Professionals
Certified Network Defender sits at the intersection of network administration and security operations. Employers who post roles referencing this certification are typically looking to fill positions where someone needs to both configure and defend infrastructure - not just monitor alerts from a distance. That combination is a byproduct of the exam's domain structure, which blends perimeter and endpoint configuration work (Domains 1-5) with detection, response, and prediction work (Domains 6-8).
In practice, this makes the credential relevant to:
- Network administrators moving toward a security-focused track without abandoning infrastructure duties.
- SOC analysts (Tier 1-2) who need to demonstrate familiarity with detection and incident-response fundamentals covered in Domains 6 and 7.
- Security operations and network security engineers responsible for endpoint hardening, wireless and cloud network protection, and virtualization security - the subject matter of Domain 5.
- IT staff transitioning into cybersecurity who want a credential that maps directly to hands-on defensive work rather than purely managerial or auditing content.
Because the exam requires either two years of documented information-security experience (self-study route) or completion of official training, employers reading a CND credential on a résumé can reasonably assume the candidate has already cleared one of those two eligibility bars - a useful signal in screening.
Job Roles Mapped to the 8 CND Exam Domains
The clearest way to understand what CND-related jobs actually require is to walk through the blueprint domains and connect each to real job tasks. For the full breakdown of weighting and content, see the CND Exam Domains 2026 guide.
Domain 1: Network Defense Management (10%)
Covers governance, policy, and risk-management fundamentals a defender needs before touching technical controls.
- Relevant to roles with "security administrator" or "IT security coordinator" titles that blend policy with hands-on work.
Domain 2: Network Perimeter Protection (10%)
Firewalls, IDS/IPS, and perimeter device configuration - core content for network security engineer roles.
- Expect job postings mentioning firewall rule management and perimeter device hardening.
Domain 3: Endpoint Protection (20%)
The largest domain on the exam, and correspondingly one of the most common day-to-day responsibilities in defender roles - hardening workstations, servers, and mobile endpoints.
- Roles emphasizing endpoint security tooling and configuration weigh this domain heavily.
Domain 4: Application and Data Protection (10%)
Data security controls and application-layer protection relevant to roles overlapping with data-loss-prevention responsibilities.
Domain 5: Enterprise Virtual, Cloud, and Wireless Network Protection (15%)
One of three domains tied for second-largest weight, reflecting how much modern defender work now touches cloud and virtualized environments alongside traditional wireless security.
Domain 6: Incident Detection (10%)
Maps closely to SOC analyst responsibilities - log review, alert triage, and detection tooling.
Domain 7: Incident Response (10%)
Covers the handoff from detection to containment and remediation, relevant to incident responder and SOC Tier 2 roles.
Domain 8: Incident Prediction (15%)
Tied with Domain 5 for second-highest weight; threat intelligence and proactive risk assessment content that appears in more senior defender and threat-hunting-adjacent roles.
Skills Employers Actually Screen For
Because the exam is 100 multiple-choice questions delivered under a four-hour limit, it tests breadth of knowledge rather than a portfolio of projects. That means the credential alone signals conceptual coverage across all eight domains - but hiring managers typically still probe for practical fluency in interviews. Based on the domain weighting, the areas most worth being able to speak to concretely are:
- Endpoint hardening techniques and tooling (Domain 3 - the single heaviest area on the exam)
- Cloud, virtualization, and wireless network security configuration (Domain 5)
- Threat intelligence and proactive risk indicators used in incident prediction (Domain 8)
- Perimeter device configuration and firewall/IDS management (Domain 2)
- The practical difference between detection workflows and response workflows (Domains 6 and 7)
If you're unsure how difficult mastering all eight areas actually is relative to other security certifications, the How Hard Is the CND Exam? guide walks through the format and content load in more detail, and the CND Pass Rate guide covers what the passing-threshold data actually shows rather than relying on invented numbers.
Key Takeaway
Don't just memorize domain names - be ready to explain, in an interview, how you'd harden an endpoint, segment a wireless network, or triage a detection alert. The exam tests the same conceptual ground employers ask about.
Getting Job-Ready: Eligibility, Cost, and Exam Mechanics
Before a CND credential can appear on a résumé, candidates have to clear EC-Council's eligibility and exam process. There are two paths:
- Self-study route: Pay a $100 nonrefundable eligibility-application fee and document two years of information-security work experience for approval. Once approved, the exam voucher through EC-Council Remote Proctoring Services costs $550, bringing the total to $650 before any preparation materials.
- Official training route: Completing EC-Council's official training (currently branded CND v3) satisfies eligibility directly - the training price incorporates the eligibility-application fee, so this path skips the separate $100 charge. Standalone courseware, by contrast, is sold separately from both official training and the exam voucher, so it does not by itself satisfy the eligibility requirement.
The exam itself - 312-38 - consists of 100 multiple-choice questions with a four-hour time limit, delivered through the ECC Exam Center or an authorized testing center. Passing cut scores are form-specific and range from 60% to 85%, which are thresholds set per exam form rather than a fixed pass rate. For a full cost comparison across both eligibility routes, see the CND Certification Cost breakdown, and for eligibility documentation specifics, review the CND Requirements guide.
| Item | Detail |
|---|---|
| Exam code | 312-38 |
| Format | 100 multiple-choice questions, 4-hour limit |
| Delivery | ECC Exam Center / authorized test center or EC-Council RPS |
| RPS voucher cost | $550 (valid 1 year) |
| Self-study eligibility fee | $100 (nonrefundable) |
| Total self-study path cost | $650 before study materials |
| Alternative eligibility | Official training (CND v3), fee bundled in |
| Passing cut score | 60%-85%, form-specific |
| Certificate validity | 1 year initially; renewed annually |
| Maintenance | 120 CE credits per 3-year cycle; $80/year ($240/cycle) |
Once certified, the credential isn't permanent by default - it carries one-year validity, extended through annual fee payment and continuing-education compliance, totaling 120 CE credits and $240 across a three-year cycle. That maintenance cadence matters for anyone using the credential to stay competitive in a defender role over multiple years, not just to pass a single hiring screen. For exact scoring mechanics, see the CND Passing Score guide, and for scheduling logistics around vouchers and testing windows, check the CND Exam Dates guide.
Scheduling Prep Around the Job You Want
If your goal is a specific role - say, a SOC analyst position versus a network security engineer position - it makes sense to weight your study time toward the domains that role actually touches daily, not just toward domain size. Endpoint Protection is worth the most exam points (20%), but if you're targeting a detection-focused SOC role, spending extra time on Domains 6 and 7 pays off in interviews even though they're each only 10% of the exam.
Foundational domains
- Network Defense Management (Domain 1) and Network Perimeter Protection (Domain 2)
- Build baseline policy and firewall/IDS vocabulary before moving into heavier technical domains
Heaviest exam weight
- Endpoint Protection (Domain 3) - allocate the most hours here given its 20% weighting
- Application and Data Protection (Domain 4)
Modern infrastructure
- Enterprise Virtual, Cloud, and Wireless Network Protection (Domain 5) - especially valuable if targeting cloud-heavy environments
Detection, response, prediction
- Incident Detection (Domain 6), Incident Response (Domain 7), and Incident Prediction (Domain 8)
- Prioritize Domain 8 given its 15% weight alongside Domain 5
For a more detailed week-by-week study framework and first-attempt strategy, see the CND Study Guide 2026. If you want a fast reference while reviewing, the CND Cheat Sheet 2026 condenses domain weights and exam mechanics onto one page. And when you're ready to test recall under exam-like conditions, practicing with timed questions on the main practice test platform can help you get comfortable with the four-hour, 100-question format before test day.
Domain-to-Job-Task Comparison
The table below maps each blueprint domain to the kind of job task it most directly supports, useful when tailoring a résumé or preparing for role-specific interview questions.
| Domain | Weight | Typical Job Task |
|---|---|---|
| 1. Network Defense Management | 10% | Policy drafting, risk assessment coordination |
| 2. Network Perimeter Protection | 10% | Firewall/IDS-IPS configuration and rule tuning |
| 3. Endpoint Protection | 20% | Workstation/server hardening, endpoint tooling management |
| 4. Application and Data Protection | 10% | Data-loss-prevention configuration, app-layer controls |
| 5. Enterprise Virtual, Cloud, and Wireless Protection | 15% | Cloud/virtualization security, wireless network segmentation |
| 6. Incident Detection | 10% | Log review, SOC alert triage |
| 7. Incident Response | 10% | Containment, remediation, post-incident reporting |
| 8. Incident Prediction | 15% | Threat intelligence review, proactive risk indicators |
Whether this credential is worth pursuing for your particular career stage depends on how closely your target roles match this domain distribution. The Is the CND Certification Worth It? ROI Analysis weighs the cost and maintenance obligations against the career signal it provides, and the CND Salary Guide 2026 looks at how the credential factors into compensation conversations without relying on guesswork.
Frequently Asked Questions
No. It signals coverage of the eight blueprint domains and, depending on eligibility route, either two years of documented information-security experience or completion of official EC-Council training. Job titles and hiring decisions still depend on the employer.
Incident Detection (Domain 6) and Incident Response (Domain 7) map most directly to SOC responsibilities, though both are weighted at 10% each on the exam, so don't neglect the higher-weighted domains like Endpoint Protection.
No. Standalone courseware is sold separately from official training and the exam voucher, and it does not by itself satisfy eligibility. You need either the self-study application (with documented experience and the $100 fee) or completion of official training.
The certificate initially carries one-year validity, extended annually through continuing-education compliance and fee payment - 120 CE credits per three-year cycle plus an $80 annual fee, totaling $240 per cycle.
The certification exam (312-38) is a 100-question multiple-choice test with a four-hour limit, separate from the hands-on training labs offered in official CND v3 training. The labs build practical skill; the exam measures domain knowledge.