CCSP Training Course

Training course

This is a free, self-paced reading course for the ISC2 CCSP. Certified Cloud Security Professional, the credential for people who have to secure data, applications, and infrastructure running in someone else’s data center. The CCSP is not a console exam. It does not ask which button provisions a key vault; it asks who holds the key, which jurisdiction’s law reaches the ciphertext, and what your contract says happens when the provider is subpoenaed. This course is written to build that vocabulary and that habit of judgment before you start drilling questions, so a wrong practice answer becomes a gap you can name rather than a fact to memorize.

The course is organized as one module per official exam domain, in the order ISC2 publishes them, and each module carries the domain’s published weight. That matters more on the CCSP than on most exams, because the weights are not flat: Cloud Data Security alone carries 20%, and it is the domain most candidates underestimate. Reading in proportion to the outline keeps you from spending three evenings on virtualization escape scenarios and twenty minutes on crypto-shredding and legal hold. Every lesson ends with its key terms and suggested further reading, so the material works as a reference after the first pass as well as a syllabus during it.

CCSP Professional level 6 modules Domain-weighted Self-paced Free account

What the course covers

Cloud Concepts, Architecture and Design

Module 1 · 17%

The vocabulary and blueprints everything else stands on, service categories and deployment models, the ISO cloud role cast of customer, provider, partner, and broker, the essential characteristics, and the shared responsibility line as it moves across IaaS, PaaS, SaaS, and AI-as-a-Service. The design half covers zero trust, the secure data lifecycle, business continuity and disaster recovery strategy, cost-benefit reasoning, and evaluating providers against ISO/IEC 27017, PCI DSS, Common Criteria, and FIPS 140 validation.

Cloud Data Security

Module 2 · 20%

The heaviest domain, and the one that decides most results. It follows data through its whole cloud lifecycle: discovery and classification, encryption architectures including BYOK, HYOK, and envelope encryption, tokenization and masking, where to place DLP, Information Rights Management, retention and legal hold, crypto-shredding, and the logging attributes that make a data event accountable and non-repudiable.

Cloud Platform and Infrastructure Security

Module 3 · 17%

The layer beneath the workloads: physical and environmental data center design, compute, storage, virtualization, and the management plane, the single most consequential thing to protect in any cloud estate. Also risk analysis of multi-tenant infrastructure including side channels and VM escape, security control planning, audit mechanisms such as packet capture, and BC/DR engineering against RTO, RPO, and recovery service level targets.

Cloud Application Security

Module 4 · 17%

Secure software delivery at cloud speed: the secure SDLC, threat modeling with STRIDE, DREAD, PASTA, and ATASM, the testing alphabet of SAST, DAST, IAST, and SCA, abuse-case thinking, and supply-chain assurance for third-party code, including pre-trained ML models treated as software components. The architecture half covers API gateways, WAFs, sandboxing, microservices trust boundaries, and the identity stack: federation, identity providers, SSO, MFA, CASB, and secrets management.

Cloud Security Operations

Module 5 · 16%

Running the environment day to day: hardware roots of trust such as TPM and HSM, bastion-mediated remote access, OS baselining and drift remediation, patching, infrastructure-as-code strategy, clustered-host availability mechanics, and monitoring across network, compute, storage, and response time. The ITIL and ISO 20000-1 process set (change, incident, problem, release, deployment, configuration) is tested directly, alongside cloud digital forensics, SOC operations, and SIEM/SOAR.

Legal, Risk and Compliance

Module 6 · 13%

The lightest domain by weight and the one that most separates the CCSP from purely technical cloud certifications: conflicting international legislation, GDPR roles and breach notification, contractual versus regulated data, eDiscovery under ISO/IEC 27050, privacy impact assessments, and the audit report taxonomy of SOC 1, 2, and 3, Type I versus Type II, SSAE and ISAE, and carve-out scopes. Contract design closes it out, right to audit, SLAs and MSAs, vendor viability, escrow, and supply-chain security under ISO/IEC 27036.

How to use it

Read a module, then take the matching portion of the CCSP practice exam rather than saving all the questions for the end. The CCSP is a best-answer exam: its distractors are defensible rather than dismissible, and the gap between recognizing a term and choosing between four reasonable-looking responses only shows up under question pressure. Domain 2 deserves a second pass on its own. Reading the CCSP wrapper here costs nothing and needs no account, but the course lessons themselves open once you are signed in to a free Certifym account.

For exam logistics, the adaptive format, the 100 to 150 item range, the three-hour clock, the 700-of-1000 scaled pass mark, the five-year experience requirement and the CISSP waiver, see the CCSP certification guide.

CCSP Training

Cloud security across service and deployment models for the ISC2 CCSP exam, one lesson at a time.

A domain-by-domain guide to the CCSP exam, jointly maintained by ISC2 and the Cloud Security Alliance. Covers cloud concepts and architecture, data security, platform and infrastructure security, application security, security operations, and legal, risk and compliance. Written for practitioners who architect, secure, and operate cloud environments across AWS, Azure, GCP, and SaaS platforms.

Module 1: Cloud Concepts, Architecture and Design 17% of exam

The foundation: NIST cloud definition and five essential characteristics, SPI service models, four deployment models, virtualization and orchestration building blocks, the shared responsibility model (data/identity/endpoints always customer), reference architectures (NIST 500-292, CSA EA, ISO 17789), zero trust (NIST SP 800-207), design principles, and the cross-cutting aspects.

  • 1.1 What CCSP Is: The Cloud Security Practitioner Role 8 min Free preview
  • 1.2 Cloud Computing Definitions and Service Models 6 min πŸ”’
  • 1.3 Cloud Deployment Models 5 min πŸ”’
  • 1.4 Cloud Characteristics and Building Blocks 5 min πŸ”’
  • 1.5 The Shared Responsibility Model 6 min πŸ”’
  • 1.6 Cloud Reference Architectures: NIST, CSA, ISO 5 min πŸ”’
  • 1.7 Trust Boundaries and Zero Trust 6 min πŸ”’
  • 1.8 Design Principles for Secure Cloud Computing 6 min πŸ”’
  • 1.9 Cross-Cutting Aspects: Interoperability, Portability, Reversibility, Availability 5 min πŸ”’

Module 2: Cloud Data Security 20% of exam

The largest domain: six-phase data lifecycle (Create/Store/Use/Share/Archive/Destroy), classification and discovery, storage types across service models, encryption at rest / in transit / in use (AES-GCM, envelope, confidential computing), key management (KMS/HSM/BYOK/HYOK), IRM/DRM/DLP/CASB, retention and cryptographic erasure, sovereignty and CLOUD Act / Schrems II, anonymization vs. pseudonymization vs. tokenization, and auditability with chain of custody.

  • 2.1 The Cloud Data Lifecycle 6 min πŸ”’
  • 2.2 Data Classification and Discovery in the Cloud 6 min πŸ”’
  • 2.3 Data Storage Types Across Service Models 5 min πŸ”’
  • 2.4 Encryption in the Cloud: At Rest, In Transit, In Use 6 min πŸ”’
  • 2.5 Key Management: KMS, HSM, BYOK, HYOK 6 min πŸ”’
  • 2.6 Data Rights Management and Data Loss Prevention 5 min πŸ”’
  • 2.7 Data Retention, Deletion, and Archiving 5 min πŸ”’
  • 2.8 Data Sovereignty and Residency 5 min πŸ”’
  • 2.9 Data Anonymization and Tokenization 5 min πŸ”’
  • 2.10 Cloud Data Auditability and Chain of Custody 5 min πŸ”’

Module 3: Cloud Platform and Infrastructure Security 17% of exam

Infrastructure components (physical / virtualization / compute / storage / network / identity / management plane / API), virtualization security (VM vs. container escape, side channels, IMDSv2), network security (VPC, security groups vs. NACLs, private endpoints, VPC flow logs), cloud IAM (identity types, federation, workload identity, PAM), CSA CCM and ISO 27017/27018, BCDR with RPO/RTO patterns, physical security via attestation, management plane discipline, and infrastructure-layer threats.

  • 3.1 Cloud Infrastructure Components 5 min πŸ”’
  • 3.2 Virtualization Security 5 min πŸ”’
  • 3.3 Network Security in the Cloud 6 min πŸ”’
  • 3.4 Cloud Identity and Access Management 6 min πŸ”’
  • 3.5 Cloud Security Controls Frameworks: CSA CCM and ISO 27017 5 min πŸ”’
  • 3.6 Business Continuity and Disaster Recovery in the Cloud 6 min πŸ”’
  • 3.7 Physical and Environmental Security 5 min πŸ”’
  • 3.8 Management Plane Security 5 min πŸ”’
  • 3.9 Threats and Countermeasures at the Infrastructure Layer 5 min πŸ”’

Module 4: Cloud Application Security 17% of exam

Cloud-aware secure SDLC and threat modeling, architecture patterns (microservices, service mesh, serverless, event-driven, multi-tenant SaaS), testing techniques (SAST/DAST/IAST/SCA/IaC scanning), API security and OWASP API Top 10, cloud-native threats and OWASP Cloud-Native Top 10, application IAM standards (OAuth/OIDC/SAML/JWT/SCIM), DevSecOps with pipeline security, and software supply chain (SBOM, SLSA, VEX).

  • 4.1 Cloud-Aware Secure Software Development Lifecycle 5 min πŸ”’
  • 4.2 Cloud Application Architecture Patterns 5 min πŸ”’
  • 4.3 Application Security Testing in the Cloud 5 min πŸ”’
  • 4.4 API Security in the Cloud 5 min πŸ”’
  • 4.5 Cloud-Specific Application Threats 5 min πŸ”’
  • 4.6 Identity and Access Management for Applications 5 min πŸ”’
  • 4.7 DevSecOps and CI/CD in the Cloud 5 min πŸ”’
  • 4.8 Supply Chain Security for Cloud Applications 5 min πŸ”’

Module 5: Cloud Security Operations 16% of exam

Data center operations shifts, logging and monitoring architecture with SIEM/SOAR/XDR and MITRE ATT&CK for cloud, incident response following NIST SP 800-61 with cloud containment options and notification timelines, digital forensics with snapshot imaging and ISO 27037, configuration management and IaC-driven change control, BC testing including chaos engineering and game days, capacity management and FinOps, and communications across providers/customers/regulators.

  • 5.1 Data Center Operations Overview 5 min πŸ”’
  • 5.2 Logging, Monitoring, and SIEM in the Cloud 6 min πŸ”’
  • 5.3 Incident Response in Cloud Environments 6 min πŸ”’
  • 5.4 Digital Forensics in the Cloud 5 min πŸ”’
  • 5.5 Configuration Management and Change Control 5 min πŸ”’
  • 5.6 Business Continuity Testing 5 min πŸ”’
  • 5.7 Capacity Management and Scaling 4 min πŸ”’
  • 5.8 Communications with Providers, Customers, and Regulators 5 min πŸ”’

Module 6: Legal, Risk and Compliance 13% of exam

International legal frameworks and jurisdictional issues, privacy laws (GDPR with principles/rights/DPO/DPIA, CCPA/CPRA, US sectoral, international), cloud contracts and SLAs with DPA/BAA/SCCs, cloud risk management including concentration and fourth-party risk, compliance frameworks (FedRAMP, SOC 2, ISO 27001/17/18/27701, PCI DSS, HITRUST, CMMC), cloud auditing and continuous assurance, and vendor management with lock-in strategies and exit planning.

  • 6.1 International Legal Frameworks and Jurisdictional Issues 5 min πŸ”’
  • 6.2 Privacy Laws and Cloud 6 min πŸ”’
  • 6.3 Cloud Contracts and SLAs 5 min πŸ”’
  • 6.4 Cloud Risk Management and Third-Party Risk 5 min πŸ”’
  • 6.5 Cloud-Specific Compliance Frameworks 5 min πŸ”’
  • 6.6 Cloud Auditing and Assurance 5 min πŸ”’
  • 6.7 Vendor Management and Provider Lock-in 5 min πŸ”’

Frequently asked questions about the CCSP training course

Is the CCSP training course free?

Yes. The course costs nothing to read. Opening the lessons requires a free Certifym account, and nothing beyond that, no payment, no trial. It is funded by the practice-exam catalogue it sits alongside.

How is the course structured?

One module per official CCSP domain, in ISC2’s published order, with each module weighted to the domain’s published percentage. Within each module the material is broken into short lessons, followed by key terms and further reading.

Does this replace ISC2’s official training?

No. ISC2 publishes the authoritative exam outline and sells its own official training; this course is an independent study companion, written to be read quickly and to slot alongside practice questions. Download the current outline from isc2.org and treat it as the source of truth.

Do I need to meet the CCSP experience requirement before studying?

No, the experience requirement applies to certification, not to study. ISC2 asks for five years of cumulative IT experience, three of them in information security and one in cloud, and a CISSP in good standing waives it entirely. You can read the course at any point; candidates who pass without the experience are recorded as Associates of ISC2 until they earn it.

What should I do after finishing the course?

Move to the CCSP practice exam and work until you are clearing 70% consistently across all six domains rather than leaning on your strong ones, the adaptive live exam will not let you coast on a favorite domain. Then book with Pearson VUE.

Is the course current?

The course follows the six-domain outline and the weights published on the CCSP certification guide: 17%, 20%, 17%, 17%, 16%, and 13%. Effective August 1, 2026, ISC2 moved the CCSP to a refreshed outline from its latest Job Task Analysis, which folds deeper AI and ML security coverage into the same six domains and may shift the weights. The domains themselves are unchanged; download the current outline PDF from isc2.org before you schedule.

Trademark notice & independence. Certifym.net is operated by Certifym Exam Services, LLC and is not affiliated with, endorsed by, or sponsored by ISC2, Inc. ISC2®, CCSP®, CISSP®, CGRC®, and CBK® are registered marks of ISC2, Inc. Certification names and marks are used solely to identify the certification for which these independent study materials are designed. The CCSP exam outline and its domain structure are the property of ISC2, Inc.; candidates should download the official, current exam outline directly from isc2.org.

All course content, questions, answers, and explanations on Certifym are original content created for study purposes. They are not actual ISC2 training materials or examination questions and are not represented as such. Studying with these materials does not guarantee a passing result on any live certification exam. Exam format, domain weights, and eligibility criteria are set by ISC2 and may change, including the refreshed exam outline effective August 1, 2026; always verify current details at isc2.org before scheduling your exam.