- CND training is EC-Council's official prep path for exam 312-38, distinct from standalone courseware.
- Official training satisfies the eligibility requirement and folds in the application fee - a shortcut around the two-year experience documentation route.
- Self-study candidates pay a $100 eligibility fee plus a $550 RPS voucher, totaling $650 before study materials.
- The exam has 100 multiple-choice questions in four hours, scored against the CND Exam Blueprint v4.0's eight domains.
What CND Training Actually Covers
"CND Training" refers to the official instructional path EC-Council designed around the Certified Network Defender program, currently branded CND v3. It is built as hands-on, lab-driven instruction covering defensive network administration: firewall and router configuration, endpoint hardening, virtualization and cloud protection, wireless security, and the incident handling lifecycle. This is not a lecture-only course - the value proposition is lab time practicing the actual defensive tasks a network administrator or SOC-adjacent analyst performs.
It's important to separate three things that get conflated in search results: the training (instructor-led or self-paced course content and labs), the standalone courseware (self-study materials sold independently of any instructor-led program or exam voucher), and the exam voucher itself (the $550 RPS voucher purchased separately for the 312-38 exam). None of these three purchases automatically includes the others. If you're mapping out what is or isn't required, our CND Certification Cost 2026: Complete Pricing Breakdown guide itemizes each line item so nothing gets double-counted or missed.
Official Training vs. Self-Study Eligibility
EC-Council requires candidates to establish eligibility before sitting the 312-38 exam, and training is one of the two recognized routes to get there.
- Self-study route: You document two years of information-security work experience and pay a nonrefundable $100 eligibility-application fee. Combined with the $550 RPS exam voucher, this totals $650 before you've purchased any study materials.
- Official training route: Completing recognized official training satisfies the eligibility requirement directly, and the training price already incorporates the eligibility-application fee - so you're not paying that $100 separately on top of the course.
Which route makes sense depends on your current experience level and whether you value structured labs over independent study. Candidates without two years of documented experience effectively need the training route to qualify at all. For a full breakdown of what "eligible" means and how the application process works, see CND Requirements 2026: Eligibility, Prerequisites & How to Qualify.
Key Takeaway
If you can't document two years of infosec work experience, official training isn't just helpful - it's your eligibility pathway to sit for 312-38 at all.
20 Training Modules vs. 8 Exam Domains
One of the more confusing aspects of preparing for CND is that the training curriculum and the exam blueprint aren't organized identically. CND v3 training is structured around 20 modules, and EC-Council's marketing also references a Protect/Detect/Respond/Predict framework for conceptual grouping. Neither of those is what the exam scores you against.
The actual exam - 312-38 - is scored against the CND Exam Blueprint v4.0, published on EC-Council's certification site in April 2024, which organizes content into eight weighted domains. When you're deciding how to allocate training hours, weight your effort against the blueprint domains, not the module count or the four-word framework, since those don't carry the same emphasis.
Domain 3: Endpoint Protection (20%)
The single largest domain on the blueprint. Training time here should cover host-based hardening, OS-level security controls, endpoint detection concepts, and device-level policy enforcement.
- Windows/Linux endpoint hardening baselines
- Host-based firewall and antivirus configuration
- Device and USB control policies
Domains 5 & 8: Enterprise Virtual/Cloud/Wireless Protection and Incident Prediction (15% each)
These two domains tie for second-largest weight. One is technical (virtualization, cloud, and wireless architecture defense), the other is largely process-oriented (threat intelligence, risk assessment, attack surface reduction to anticipate incidents before they occur).
- Cloud security shared-responsibility concepts
- Wireless encryption and rogue access point defense
- Threat intelligence feeds and predictive risk indicators
The remaining five domains - Network Defense Management, Network Perimeter Protection, Application and Data Protection, Incident Detection, and Incident Response - each carry 10% and round out the blueprint. For a domain-by-domain breakdown with study priorities for each, our companion piece CND Exam Domains 2026: Complete Guide to All 8 Content Areas goes deeper than a training syllabus typically will.
| Domain | Weight |
|---|---|
| Network Defense Management | 10% |
| Network Perimeter Protection | 10% |
| Endpoint Protection | 20% |
| Application and Data Protection | 10% |
| Enterprise Virtual, Cloud, and Wireless Network Protection | 15% |
| Incident Detection | 10% |
| Incident Response | 10% |
| Incident Prediction | 15% |
Exam Format, Delivery, and Costs
CND training exists to prepare you for one specific outcome: passing exam 312-38. Understanding the exam mechanics helps you know what "training completion" is actually training you toward.
- Format: 100 multiple-choice questions, four-hour time limit.
- Delivery: Through the ECC Exam Center/EC-Council Exam Portal, at an authorized testing center or via EC-Council Remote Proctoring Services (RPS).
- Cost: The official RPS exam voucher is $550 USD, valid for one year from purchase.
- Passing score: Cut scores are form-specific and range from 60% to 85% depending on the exam form you receive - these are passing thresholds, not indications of how many candidates pass. Details are in CND Passing Score 2026: Exactly What You Need to Pass.
Because the exam is purely multiple choice - separate from the hands-on labs that make up the bulk of training time - there's a disconnect worth planning for: your training builds practical, lab-based muscle memory, but the exam tests conceptual and procedural knowledge in a written-question format. Good training programs bridge this by including knowledge checks that mirror the multiple-choice style, not just lab walkthroughs. If you want a sense of how demanding that written format actually is relative to the lab work, How Hard Is the CND Exam? Complete Difficulty Guide 2026 covers this gap directly, and CND Pass Rate 2026: What the Data Shows looks at what's publicly known about outcomes.
Who Takes CND Training
CND training draws a specific audience: network administrators, network engineers, and security operations staff who are responsible for defensive infrastructure rather than penetration testing or red-team offense. Because the domains emphasize perimeter protection, endpoint hardening, virtualization/cloud defense, and incident response/prediction, the training content maps closely to blue-team and network operations job functions.
Typical training audiences include:
- Network administrators moving into a security-focused role
- SOC analysts who need structured coverage of network-layer defense, not just alert triage
- IT professionals pursuing a credential that validates defensive network administration skills specifically, rather than a broad security management certification
If you're trying to figure out whether the training and certification translate into hiring demand and compensation in your market, see CND Jobs and CND Salary Guide 2026: Complete Earnings Analysis. And if you're still weighing whether the investment in training and the exam is worth it relative to other paths, Is the CND Certification Worth It? Complete ROI Analysis 2026 walks through that decision without inflating numbers that aren't publicly documented.
Building a Training Schedule Around the Domains
Generic study techniques like spaced repetition or timed practice blocks are useful, but only when they're mapped to CND's actual weight distribution. Since Endpoint Protection alone accounts for a fifth of the exam, and Enterprise Virtual/Cloud/Wireless Protection plus Incident Prediction together make up another 30%, more than half your scored content sits in just three domains. A training schedule that spreads equal time across all eight domains is misallocating effort.
Foundational Domains
- Network Defense Management and Network Perimeter Protection labs
- Firewall, router, and IDS/IPS configuration exercises
Endpoint Protection (heaviest weight)
- Host hardening across Windows and Linux endpoints
- Application and Data Protection overlap topics
Virtual, Cloud, and Wireless Protection
- Cloud shared-responsibility labs
- Wireless encryption and rogue AP detection
Incident Detection, Response, and Prediction
- SIEM/log review exercises for detection
- Threat intelligence workflows for prediction
- Timed multiple-choice practice across all eight domains
For a more granular week-by-week plan with review checkpoints, our CND Study Guide 2026: How to Pass on Your First Attempt expands on this structure, and running full-length timed sets on our practice test platform before exam day is the closest simulation you'll get to the real 100-question, four-hour format.
Key Takeaway
Allocate training and review time proportionally to domain weight - Endpoint Protection, Enterprise Virtual/Cloud/Wireless Protection, and Incident Prediction together represent half the exam.
After Training: Certification and Renewal
Passing the exam earns the certification, but the CND credential isn't a one-time achievement. The certificate initially carries one-year validity, extended annually through fee payment and continuing-education compliance. Over a full three-year cycle, certified professionals must accumulate 120 continuing-education credits and pay an $80 annual continuing-education fee, totaling $240 per cycle.
This matters when you're evaluating training options, because some official training providers bundle continuing-education credit opportunities into refresher content, while standalone courseware typically does not. If long-term cost of ownership factors into your decision, revisit CND Certification Cost 2026: Complete Pricing Breakdown for the full lifecycle math, not just the upfront training and exam spend.
Before you get to renewal, though, focus needs to stay on the exam itself. For quick-reference review once your training is complete, our CND Cheat Sheet 2026: One-Page Review of Must-Know Facts condenses the eight domains, format details, and eligibility mechanics onto a single page, and checking CND Exam Dates 2026: Testing Windows, Deadlines & Scheduling ensures your training completion lines up with your voucher's one-year validity window.
Frequently Asked Questions
Not exclusively - you can qualify through the self-study route by documenting two years of information-security experience and paying the $100 eligibility-application fee. Official training is the alternative eligibility path, and its price already includes that application fee.
No. Training, standalone courseware, and the $550 RPS exam voucher are three separate purchases. Completing training satisfies eligibility; it does not automatically grant exam access.
Prioritize the eight domains from the CND Exam Blueprint v4.0 when allocating review time, since that's what the 312-38 exam is scored against. The 20 modules and the Protect/Detect/Respond/Predict framework are organizational tools within the training itself, not the scoring structure.
Endpoint Protection, at 20% of the blueprint, is the single largest domain. Enterprise Virtual, Cloud, and Wireless Network Protection and Incident Prediction each follow at 15%.
The certificate starts with one-year validity, renewed annually through fee payment and continuing-education compliance. Over a three-year cycle, you need 120 continuing-education credits and pay an $80 annual fee, totaling $240 per cycle.