Exam Facts
| Attribute | Details |
|---|---|
| Exam Code | 312-38 |
| Exam Name | Certified Network Defender v3 (CND v3) |
| Vendor | EC-Council (Ethical Hacking and Countermeasures Council) |
| Level | Intermediate / Professional (between associate and senior) |
| Prerequisites | None (recommended: network or security fundamentals, CompTIA Network+ or equivalent) |
| Exam Format | Interactive multiple-choice questions (MCQ) |
| Exam Duration | 4 hours (240 minutes) |
| Number of Questions | 100 questions |
| Passing Score | 60% (60 out of 100 correct) |
| Exam Cost | USD $300–$450 (varies by region and retake policy) |
| Delivery Method | Online, proctored; testing centers available worldwide |
| Course Duration | Official training: 40–48 hours (3–5 day bootcamp or 6–8 week self-paced) |
| Attempts Allowed | Typically 1–2 attempts per exam registration; additional attempts require new registration |
| Validity Period | 3 years from date of issuance |
| Recertification | Renewal exam or continuing education credits required after 3 years |
| DoD Compliance | Aligns with US DoD Directive 8570.01-M and NIST standards |
| Status as of May 2026 | Active; v3 is the current version (v2 deprecated) |
Vendor source — EC-Council Certified Network Defender v3 ↗
About
The Certified Network Defender v3 (CND v3) is a vendor-neutral, intermediate-level cybersecurity certification offered by EC-Council. It is designed for IT professionals and network administrators responsible for securing networks, detecting threats, and responding to security incidents across on-premises, cloud, and hybrid environments.
CND v3 validates expertise in:
- Network security fundamentals and defense-in-depth strategies
- Threat detection and analysis
- Intrusion Detection Systems (IDS) and Intrusion Prevention Systems (IPS)
- Firewalls, proxies, and network segmentation
- VPN and encryption technologies
- DDoS detection and mitigation
- Wireless security and mobile security
- Cloud infrastructure security
- IoT and operational technology (OT) security
- Log analysis and network forensics
- Business continuity and disaster recovery (BCDR)
- Compliance and regulatory frameworks (HIPAA, PCI-DSS, SOC 2)
The CND v3 is an evolution from CND v2, introducing coverage of:
- IoT security and OT (operational technology) modules
- Cloud infrastructure security
- Threat intelligence and attack surface analysis
- Advanced malware analysis concepts
- Zero Trust and modern security architectures
- Mobile and endpoint security
The certification is recognized by:
- US DoD: Under Directive 8570/8140 for government IT security roles
- ANSI: Accredited by the ANSI National Accreditation Board (ANSI ISO/IEC 17024)
- Industry: Valued by enterprises, government agencies, and service providers
Domain Context
EC-Council is a global cybersecurity education organization offering certifications across multiple domains: ethical hacking (CEH), network defense (CND), incident handling (ECIH), and specialized credentials. The CND v3 sits in the organization's defensive security track, complementing offensive certifications like CEH (Certified Ethical Hacker).
The CND v3 emphasizes:
- Defender Mindset: Proactive threat detection, prevention, and response
- Vendor-Neutral Approach: Applicable across multi-vendor environments
- Practical Skills: Real-world scenarios, log analysis, and incident response
- Adaptive Security Strategy: First major certification update to include AI-driven threat detection
- Regulatory Alignment: NIST, HIPAA, PCI-DSS, GDPR compliance considerations
The CND v3 is positioned for professionals transitioning from junior admin roles to senior network and security engineer positions, or for security specialists broadening their defensive expertise.
Topics Covered
Core Areas
-
Network Security Foundations
- OSI and TCP/IP models
- Network protocols and services
- IP addressing, routing, and switching
- Network design principles (DMZ, segmentation)
- Defense-in-depth strategies
-
Intrusion Detection & Prevention (IDS/IPS)
- IDS/IPS technologies and architectures
- Signature-based vs. anomaly-based detection
- False positives and tuning
- NIDS (Network IDS) and HIDS (Host-based IDS)
- IDS/IPS evasion techniques and countermeasures
- Tools: Snort, Suricata, Zeek
-
Firewalls & Proxies
- Firewall types (stateful, UTM, next-generation)
- Access control lists (ACLs) and policies
- NAT and PAT configuration
- Proxy servers and application-level gateways
- Web proxies and SSL inspection
- Firewall rule optimization and troubleshooting
-
VPN & Encryption Technologies
- VPN protocols (IPSec, SSL/TLS, WireGuard)
- Tunneling and encapsulation
- Encryption algorithms and key management
- Virtual Private LAN Services (VPLS)
- VPN security considerations and best practices
-
DDoS Detection & Mitigation
- DDoS attack types and vectors
- Volumetric, protocol, and application-layer attacks
- Detection techniques and tools
- Mitigation strategies (rate limiting, traffic scrubbing)
- Anycast and CDN-based DDoS protection
-
Wireless Network Security
- Wi-Fi security protocols (WEP, WPA, WPA3)
- Rogue AP detection and prevention
- Wireless intrusion detection
- Mobile device security
- Bluetooth and NFC security
-
Log Analysis & Network Forensics
- Log sources and aggregation (syslog, SIEM)
- Log analysis for threat detection
- Network traffic analysis (packet analysis)
- Forensics investigation techniques
- Evidence preservation and chain of custody
- Tools: Wireshark, tcpdump, ELK Stack
-
Cloud & Virtualization Security (new in v3)
- Cloud service models (IaaS, PaaS, SaaS) security
- Cloud network isolation and segmentation
- Hypervisor security
- Container and Kubernetes security
- Cloud-native threat detection
-
IoT & OT Security (new in v3)
- IoT architecture and protocols
- IoT threat landscape
- Operational Technology (OT) network security
- SCADA and critical infrastructure protection
- IoT device management and monitoring
-
Threat Intelligence & Attack Surface Analysis (new in v3)
- Threat intelligence sources and feeds
- Vulnerability assessment and management
- Penetration testing concepts (offensive)
- Threat modeling and risk analysis
- Indicators of Compromise (IoCs)
-
Business Continuity & Disaster Recovery (BCDR)
- BCDR planning and strategies
- Recovery Time Objective (RTO) and Recovery Point Objective (RPO)
- Backup and restore technologies
- Failover and redundancy
- Business continuity testing
-
Compliance & Regulatory Frameworks
- HIPAA (healthcare data protection)
- PCI-DSS (payment card security)
- SOC 2 (service organization controls)
- GDPR (European data privacy)
- NIST Cybersecurity Framework
- Audit and compliance reporting
Common Job-Ready Skills
- Threat Detection & Analysis: Monitor networks, identify anomalies, and investigate security events
- Firewall & Network Defense: Configure and manage firewalls, IDS/IPS, and access controls
- Incident Response: Respond to security incidents, perform forensic analysis, and document findings
- Log Management: Aggregate, analyze, and correlate logs to detect threats
- Vulnerability Assessment: Identify and prioritize network vulnerabilities
- Security Hardening: Implement security best practices and defense-in-depth strategies
- Compliance Management: Ensure networks meet regulatory and compliance requirements
- Network Troubleshooting: Diagnose and resolve network performance and security issues
- Team Collaboration: Work with SOC teams, incident response, and IT operations
- Continuous Learning: Stay current with emerging threats and security technologies
Recommended Courses
- EC-Council Official CND v3 Course: 40–48 hours of training (in-person, live online, or self-paced via iLabs)
- Includes 4 volumes of eBooks and interactive labs (iLabs)
- Hands-on exercises with real-world scenarios
- Bootcamp Format: Intensive 5-day courses from authorized training centers
- Self-Paced Online: 6–8 week self-study with video lectures and lab access
- CompTIA Network+ or Cisco CCNA: Prerequisite or complementary foundational training
- Cisco Certified Network Associate (CCNA): Advanced routing and switching skills
- Wireshark & Tcpdump Labs: Network traffic analysis tools
- SIEM & Log Analysis Training: Splunk, ELK, or similar platforms
- Third-Party Study Guides: Exam prep books and video courses on Udemy, Linux Academy, etc.
Practice Exams
- EC-Council Practice Exams: Included with official course enrollment
- iLabs (Interactive Labs): Hands-on simulations bundled with CND course
- ExamTopics & StudyKey: Community-contributed practice questions
- Udemy CND v3 Prep Courses: Third-party practice exams and study materials
- LinkedIn Learning: CND v3 preparation courses
- Third-Party Test Engines: Various exam prep platforms (VCE, MindDump, etc.)
Books
- CND v3 Official eBooks (Volumes 1–4) — Included with EC-Council training
- CompTIA Network+ Study Guide — Foundational networking (Sybex or similar)
- NIST Cybersecurity Framework Guide — Government standard (free, NIST)
- The Defensive Security Handbook — Lee, Martin & Vines (O'Reilly)
- Network Security Through Data Analysis — Michael Collins (O'Reilly) — Log analysis and forensics
- Wireshark Network Analysis — Dedier, Smith & Callanan (SybexPress) — Packet analysis deep dive
- Incident Response & Disaster Recovery — Waxman (Apress)
- HIPAA and HITECH Act Compliance — Regulatory compliance guide
- PCI-DSS Compliance Guide — Payment card security standards
Job Titles
- Network Security Engineer
- Security Operations Center (SOC) Analyst (Level II/III)
- Network Defender
- Incident Response Analyst
- Firewall Administrator / Engineer
- Network Administrator (Security-focused)
- Security Systems Administrator
- Vulnerability Analyst
- Network Security Specialist
- Security Operations Manager
- Senior Network Administrator
- Threat Intelligence Analyst
Salary (USD / ZAR × 18 / GBP / EUR / AUD)
Based on intermediate network security roles:
| Currency | Annual Salary |
|---|---|
| USD | $65,000–$110,000 |
| ZAR (×18) | ZAR 1,170,000–1,980,000 |
| GBP | £50,000–£85,000 |
| EUR | €58,000–€100,000 |
| AUD | AUD 100,000–$165,000 |
Varies by region, company size, years of experience, and specialization (SOC, incident response, firewall engineering).
Skills Validated
✓ Network security architecture and defense-in-depth ✓ Intrusion Detection/Prevention (IDS/IPS) deployment and tuning ✓ Firewall configuration and access control management ✓ VPN and encryption technology implementation ✓ DDoS detection and mitigation strategies ✓ Wireless network security and rogue AP detection ✓ Log analysis and security information management ✓ Network forensics and incident investigation ✓ Cloud and virtualization security ✓ IoT and OT security fundamentals ✓ Threat intelligence and attack surface analysis ✓ Business continuity and disaster recovery planning ✓ HIPAA, PCI-DSS, and SOC 2 compliance ✓ Network troubleshooting and optimization ✓ Security monitoring and threat detection
Related Certs
Within EC-Council Ecosystem:
- Certified Ethical Hacker (CEH) v12 — offensive security (attacker perspective)
- Certified Incident Handler (ECIH) — incident response specialization
- Certified Network Defender (CND) v2 — earlier version (deprecated)
- EC-Council Master (ECM) — advanced specializations
Complementary Industry Certs:
- CompTIA Security+ (SY0-601) — foundational security concepts
- CompTIA Network+ (N10-008) — networking fundamentals
- Certified Information Systems Security Professional (CISSP) — senior-level security
- Certified Information Security Manager (CISM) — security management
- GIAC Certified Network Defender (GND) — SANS/GIAC alternative
- Cisco Certified Network Associate (CCNA) — routing and switching
- Certified Ethical Hacker (CEH) — offensive security skills
Sources
- EC-Council CND v3 Official Course
- EC-Council CND v3 - NetCom Learning
- EC-Council Certified Network Defender v3 - Firebrand Training
- NICCS - EC-Council CND v3 Training
- EC-Council CND on NICCS - New Horizons
- CND v3 eBook and iLabs - EC-Council
- CND v3 Training - Learning Tree
- CND v3 Training - Global Knowledge
- QA - EC-Council CND v3 elearning