Why Study with PlanetCert?
The Latest Questions
Practice questions and exam topics aligned with the current exam objectives.
Detailed Explanations
Go beyond the answer. Master the material with comprehensive learning and professional explanations for every concept.

AI-Powered Insights
Personalized preparation guidance that adapts to your performance and identifies weak spots automatically.
Exam Information
Official specifications published by EC-Council
Exam Format
Registration
Validity
312-38 Exam Topics and Domains
312-38 is organized into 8 weighted domains. Expect to work with AWS IAM, AWS KMS, Azure MFA, Capsa, and more.
Network Defense Management
Network Attacks and Defense Strategies
- Explain essential terminologies related to network security attacks
- Describe various attack techniques at different levels
- Understand fundamental goals, benefits, and challenges in network defense
- Explain continual/adaptive security strategy
- Explain defense-in-depth security strategy
Administrative Network Security
- Obtain compliance with regulatory frameworks
- Design and develop security policies
- Conduct security awareness training
- Understand IT Asset Management
- Learn how to stay up-to-date on security trends and threats
Network Perimeter Protection
Technical Network Security
- Discuss access control principles, terminologies, and models
- Discuss Identity and Access Management (IAM) concepts
- Discuss cryptographic security techniques
- Discuss security benefits of network segmentation techniques
Network Perimeter Security
- Understand firewall security concerns, capabilities, and limitations
- Understand different types of firewall technologies and their usage
- Discuss firewall implementation and deployment process
- Understand role, capabilities, limitations, and concerns in IDS deployment
- Discuss router and switch security measures
- Leverage Zero Trust Model Security using Software-Defined Perimeter
Endpoint Protection
Endpoint Security - Windows Systems
- Understand Windows OS and security concerns
- Discuss Windows security components and features
- Discuss Windows security baseline configurations
- Discuss Windows patch management
- Discuss Windows Active Directory security best practices
Endpoint Security - Linux Systems
- Understand Linux OS and security concerns
- Discuss Linux installation and patching
- Discuss Linux OS hardening techniques
- Discuss Linux network and remote access security
Endpoint Security - Mobile Devices
- Discuss common mobile usage policies in enterprises
- Discuss security risks and challenges with enterprise mobile usage
- Discuss enterprise-level mobile security management solutions
Endpoint Security - IoT Devices
- Understand IoT devices, their need, and application areas
- Understand IoT ecosystem and communication models
- Discuss security measures for IoT-enabled environments
Application and Data Protection
Administrative Application Security
- Discuss and implement application whitelisting and blacklisting
- Discuss and implement application sandboxing
- Discuss and implement application patch management
- Discuss and implement Web Application Firewall (WAF)
Data Security
- Understand data security and its importance
- Discuss implementation of data access controls
- Discuss implementation of encryption for data at rest and in transit
- Discuss data backup, retention, and destruction concepts
- Discuss Data Loss Prevention (DLP) concepts
Enterprise Virtual, Cloud, and Wireless Network Protection
Enterprise Virtual Network Security
- Understand virtualization essential concepts
- Discuss Network Virtualization (NV) security
- Discuss Software-Defined Network (SDN) security
- Discuss container and Docker security
Enterprise Cloud Security
- Understand cloud computing fundamentals
- Evaluate CSP for security before consuming cloud service
- Discuss security in Amazon Cloud (AWS)
- Discuss security in Microsoft Azure Cloud
- Discuss security in Google Cloud Platform (GCP)
Enterprise Wireless Network Security
- Understand wireless network security fundamentals
- Understand wireless network encryption mechanisms
- Discuss and implement wireless network security measures
Network Traffic Monitoring and Analysis
Network Traffic Monitoring
- Understand the need and advantages of network traffic monitoring
- Discuss network performance and bandwidth monitoring concepts
- Understand network anomaly detection with behavior analysis
Network Logs Monitoring and Analysis
- Understand logging concepts
- Discuss log monitoring and analysis on various systems
- Discuss centralized log monitoring and analysis
Incident Response
Incident Response and Forensic Investigation
- Understand the incident response concept
- Understand the role of first responder
- Describe incident handling and response process
- Understand how to automate incident response with SOAR
- Understand EDR, MDR, and XDR
- Describe the forensics investigation process
Business Continuity and Disaster Recovery
- Introduction to Business Continuity and Disaster Recovery
- Discuss BC/DR activities
- Explain Business Continuity Plan and Disaster Recovery Plan
- Discuss various BC/DR standards
Incident Prediction
Risk Anticipation with Risk Management
- Understand risk management concepts
- Learn to manage risk through risk management program
- Learn different Risk Management Frameworks
- Learn vulnerability assessment and scanning
Threat Assessment with Attack Surface Analysis
- Understand the attack surface analysis
- Understand and visualize your attack surface
- Learn to identify Indicators of Exposures
- Learn to reduce the attack surface
Threat Prediction with Cyber Threat Intelligence
- Understand role of cyber threat intelligence in network defense
- Understand different types of threat intelligence
- Understand Indicators of Compromise and Indicators of Attack
- Discuss threat hunting
How do I earn this certification?
Passing 312-38 earns the Certified Network Defender certification. It sits in the Blue Team / Defense track.
- 312-76 - CDA - Certified Defense Architect
- 312-85 - CTIA - Certified Threat Intelligence Analyst
- 312-50 - CEH - Certified Ethical Hacker
- 212-82 - CCSP - Certified Cloud Security Professional
- 312-49 - CHFI - Computer Hacking Forensic Investigator Complementary forensics and investigation skills
- 212-81 - ECIH - EC-Council Certified Incident HandlerAdvanced incident response capabilities
- 312-39 - CSA - Certified SOC AnalystSOC-specific skills and operations
- CompTIA Security+ - Security+Broader security foundation
Practice with Precision
The PlanetCert Simulator mirrors the real exam environment with authentic questions and timed pressure.
How to study for this exam?
The most effective way to prepare for 312-38 is by using the PlanetCert Simulator to practice questions and review detailed explanations.
What's changed on this exam?
- ACTIVE
- Last content update: 2024-04-01
- Container Security Docker/Kubernetes latest Expanded coverage in virtualization domain • Release date: 2024-01-01
- Zero Trust Architecture NIST SP 800-207 New focus area in perimeter security • Release date: 2023-08-01
- SOAR Platforms Various Enhanced incident response automation coverage • Release date: 2024-01-01
- Extended Detection and Response (XDR) Industry standard New topic in incident response domain • Release date: 2024-01-01
Who should take this exam?
This exam is typically taken by Network Administrators and Network Security Administrators.
- Fundamental knowledge of networking concepts
- Basic understanding of TCP/IP
- Familiarity with network components and topology
- Experience with network administration