Training course
This is a free, self-paced reading course for the ISC2 CCSP. Certified Cloud Security Professional, the credential for people who have to secure data, applications, and infrastructure running in someone else’s data center. The CCSP is not a console exam. It does not ask which button provisions a key vault; it asks who holds the key, which jurisdiction’s law reaches the ciphertext, and what your contract says happens when the provider is subpoenaed. This course is written to build that vocabulary and that habit of judgment before you start drilling questions, so a wrong practice answer becomes a gap you can name rather than a fact to memorize.
The course is organized as one module per official exam domain, in the order ISC2 publishes them, and each module carries the domain’s published weight. That matters more on the CCSP than on most exams, because the weights are not flat: Cloud Data Security alone carries 20%, and it is the domain most candidates underestimate. Reading in proportion to the outline keeps you from spending three evenings on virtualization escape scenarios and twenty minutes on crypto-shredding and legal hold. Every lesson ends with its key terms and suggested further reading, so the material works as a reference after the first pass as well as a syllabus during it.
What the course covers
Cloud Concepts, Architecture and Design
Module 1 · 17%The vocabulary and blueprints everything else stands on, service categories and deployment models, the ISO cloud role cast of customer, provider, partner, and broker, the essential characteristics, and the shared responsibility line as it moves across IaaS, PaaS, SaaS, and AI-as-a-Service. The design half covers zero trust, the secure data lifecycle, business continuity and disaster recovery strategy, cost-benefit reasoning, and evaluating providers against ISO/IEC 27017, PCI DSS, Common Criteria, and FIPS 140 validation.
Cloud Data Security
Module 2 · 20%The heaviest domain, and the one that decides most results. It follows data through its whole cloud lifecycle: discovery and classification, encryption architectures including BYOK, HYOK, and envelope encryption, tokenization and masking, where to place DLP, Information Rights Management, retention and legal hold, crypto-shredding, and the logging attributes that make a data event accountable and non-repudiable.
Cloud Platform and Infrastructure Security
Module 3 · 17%The layer beneath the workloads: physical and environmental data center design, compute, storage, virtualization, and the management plane, the single most consequential thing to protect in any cloud estate. Also risk analysis of multi-tenant infrastructure including side channels and VM escape, security control planning, audit mechanisms such as packet capture, and BC/DR engineering against RTO, RPO, and recovery service level targets.
Cloud Application Security
Module 4 · 17%Secure software delivery at cloud speed: the secure SDLC, threat modeling with STRIDE, DREAD, PASTA, and ATASM, the testing alphabet of SAST, DAST, IAST, and SCA, abuse-case thinking, and supply-chain assurance for third-party code, including pre-trained ML models treated as software components. The architecture half covers API gateways, WAFs, sandboxing, microservices trust boundaries, and the identity stack: federation, identity providers, SSO, MFA, CASB, and secrets management.
Cloud Security Operations
Module 5 · 16%Running the environment day to day: hardware roots of trust such as TPM and HSM, bastion-mediated remote access, OS baselining and drift remediation, patching, infrastructure-as-code strategy, clustered-host availability mechanics, and monitoring across network, compute, storage, and response time. The ITIL and ISO 20000-1 process set (change, incident, problem, release, deployment, configuration) is tested directly, alongside cloud digital forensics, SOC operations, and SIEM/SOAR.
Legal, Risk and Compliance
Module 6 · 13%The lightest domain by weight and the one that most separates the CCSP from purely technical cloud certifications: conflicting international legislation, GDPR roles and breach notification, contractual versus regulated data, eDiscovery under ISO/IEC 27050, privacy impact assessments, and the audit report taxonomy of SOC 1, 2, and 3, Type I versus Type II, SSAE and ISAE, and carve-out scopes. Contract design closes it out, right to audit, SLAs and MSAs, vendor viability, escrow, and supply-chain security under ISO/IEC 27036.
How to use it
Read a module, then take the matching portion of the CCSP practice exam rather than saving all the questions for the end. The CCSP is a best-answer exam: its distractors are defensible rather than dismissible, and the gap between recognizing a term and choosing between four reasonable-looking responses only shows up under question pressure. Domain 2 deserves a second pass on its own. Reading the CCSP wrapper here costs nothing and needs no account, but the course lessons themselves open once you are signed in to a free Certifym account.
For exam logistics, the adaptive format, the 100 to 150 item range, the three-hour clock, the 700-of-1000 scaled pass mark, the five-year experience requirement and the CISSP waiver, see the CCSP certification guide.
CCSP Training
Cloud security across service and deployment models for the ISC2 CCSP exam, one lesson at a time.
A domain-by-domain guide to the CCSP exam, jointly maintained by ISC2 and the Cloud Security Alliance. Covers cloud concepts and architecture, data security, platform and infrastructure security, application security, security operations, and legal, risk and compliance. Written for practitioners who architect, secure, and operate cloud environments across AWS, Azure, GCP, and SaaS platforms.
Module 1: Cloud Concepts, Architecture and Design 17% of exam
The foundation: NIST cloud definition and five essential characteristics, SPI service models, four deployment models, virtualization and orchestration building blocks, the shared responsibility model (data/identity/endpoints always customer), reference architectures (NIST 500-292, CSA EA, ISO 17789), zero trust (NIST SP 800-207), design principles, and the cross-cutting aspects.
- 1.1 What CCSP Is: The Cloud Security Practitioner Role 8 min Free preview
- 1.2 Cloud Computing Definitions and Service Models 6 min π
- 1.3 Cloud Deployment Models 5 min π
- 1.4 Cloud Characteristics and Building Blocks 5 min π
- 1.5 The Shared Responsibility Model 6 min π
- 1.6 Cloud Reference Architectures: NIST, CSA, ISO 5 min π
- 1.7 Trust Boundaries and Zero Trust 6 min π
- 1.8 Design Principles for Secure Cloud Computing 6 min π
- 1.9 Cross-Cutting Aspects: Interoperability, Portability, Reversibility, Availability 5 min π
Module 2: Cloud Data Security 20% of exam
The largest domain: six-phase data lifecycle (Create/Store/Use/Share/Archive/Destroy), classification and discovery, storage types across service models, encryption at rest / in transit / in use (AES-GCM, envelope, confidential computing), key management (KMS/HSM/BYOK/HYOK), IRM/DRM/DLP/CASB, retention and cryptographic erasure, sovereignty and CLOUD Act / Schrems II, anonymization vs. pseudonymization vs. tokenization, and auditability with chain of custody.
- 2.1 The Cloud Data Lifecycle 6 min π
- 2.2 Data Classification and Discovery in the Cloud 6 min π
- 2.3 Data Storage Types Across Service Models 5 min π
- 2.4 Encryption in the Cloud: At Rest, In Transit, In Use 6 min π
- 2.5 Key Management: KMS, HSM, BYOK, HYOK 6 min π
- 2.6 Data Rights Management and Data Loss Prevention 5 min π
- 2.7 Data Retention, Deletion, and Archiving 5 min π
- 2.8 Data Sovereignty and Residency 5 min π
- 2.9 Data Anonymization and Tokenization 5 min π
- 2.10 Cloud Data Auditability and Chain of Custody 5 min π
Module 3: Cloud Platform and Infrastructure Security 17% of exam
Infrastructure components (physical / virtualization / compute / storage / network / identity / management plane / API), virtualization security (VM vs. container escape, side channels, IMDSv2), network security (VPC, security groups vs. NACLs, private endpoints, VPC flow logs), cloud IAM (identity types, federation, workload identity, PAM), CSA CCM and ISO 27017/27018, BCDR with RPO/RTO patterns, physical security via attestation, management plane discipline, and infrastructure-layer threats.
- 3.1 Cloud Infrastructure Components 5 min π
- 3.2 Virtualization Security 5 min π
- 3.3 Network Security in the Cloud 6 min π
- 3.4 Cloud Identity and Access Management 6 min π
- 3.5 Cloud Security Controls Frameworks: CSA CCM and ISO 27017 5 min π
- 3.6 Business Continuity and Disaster Recovery in the Cloud 6 min π
- 3.7 Physical and Environmental Security 5 min π
- 3.8 Management Plane Security 5 min π
- 3.9 Threats and Countermeasures at the Infrastructure Layer 5 min π
Module 4: Cloud Application Security 17% of exam
Cloud-aware secure SDLC and threat modeling, architecture patterns (microservices, service mesh, serverless, event-driven, multi-tenant SaaS), testing techniques (SAST/DAST/IAST/SCA/IaC scanning), API security and OWASP API Top 10, cloud-native threats and OWASP Cloud-Native Top 10, application IAM standards (OAuth/OIDC/SAML/JWT/SCIM), DevSecOps with pipeline security, and software supply chain (SBOM, SLSA, VEX).
- 4.1 Cloud-Aware Secure Software Development Lifecycle 5 min π
- 4.2 Cloud Application Architecture Patterns 5 min π
- 4.3 Application Security Testing in the Cloud 5 min π
- 4.4 API Security in the Cloud 5 min π
- 4.5 Cloud-Specific Application Threats 5 min π
- 4.6 Identity and Access Management for Applications 5 min π
- 4.7 DevSecOps and CI/CD in the Cloud 5 min π
- 4.8 Supply Chain Security for Cloud Applications 5 min π
Module 5: Cloud Security Operations 16% of exam
Data center operations shifts, logging and monitoring architecture with SIEM/SOAR/XDR and MITRE ATT&CK for cloud, incident response following NIST SP 800-61 with cloud containment options and notification timelines, digital forensics with snapshot imaging and ISO 27037, configuration management and IaC-driven change control, BC testing including chaos engineering and game days, capacity management and FinOps, and communications across providers/customers/regulators.
- 5.1 Data Center Operations Overview 5 min π
- 5.2 Logging, Monitoring, and SIEM in the Cloud 6 min π
- 5.3 Incident Response in Cloud Environments 6 min π
- 5.4 Digital Forensics in the Cloud 5 min π
- 5.5 Configuration Management and Change Control 5 min π
- 5.6 Business Continuity Testing 5 min π
- 5.7 Capacity Management and Scaling 4 min π
- 5.8 Communications with Providers, Customers, and Regulators 5 min π
Module 6: Legal, Risk and Compliance 13% of exam
International legal frameworks and jurisdictional issues, privacy laws (GDPR with principles/rights/DPO/DPIA, CCPA/CPRA, US sectoral, international), cloud contracts and SLAs with DPA/BAA/SCCs, cloud risk management including concentration and fourth-party risk, compliance frameworks (FedRAMP, SOC 2, ISO 27001/17/18/27701, PCI DSS, HITRUST, CMMC), cloud auditing and continuous assurance, and vendor management with lock-in strategies and exit planning.
- 6.1 International Legal Frameworks and Jurisdictional Issues 5 min π
- 6.2 Privacy Laws and Cloud 6 min π
- 6.3 Cloud Contracts and SLAs 5 min π
- 6.4 Cloud Risk Management and Third-Party Risk 5 min π
- 6.5 Cloud-Specific Compliance Frameworks 5 min π
- 6.6 Cloud Auditing and Assurance 5 min π
- 6.7 Vendor Management and Provider Lock-in 5 min π
Frequently asked questions about the CCSP training course
Is the CCSP training course free?
Yes. The course costs nothing to read. Opening the lessons requires a free Certifym account, and nothing beyond that, no payment, no trial. It is funded by the practice-exam catalogue it sits alongside.
How is the course structured?
One module per official CCSP domain, in ISC2’s published order, with each module weighted to the domain’s published percentage. Within each module the material is broken into short lessons, followed by key terms and further reading.
Does this replace ISC2’s official training?
No. ISC2 publishes the authoritative exam outline and sells its own official training; this course is an independent study companion, written to be read quickly and to slot alongside practice questions. Download the current outline from isc2.org and treat it as the source of truth.
Do I need to meet the CCSP experience requirement before studying?
No, the experience requirement applies to certification, not to study. ISC2 asks for five years of cumulative IT experience, three of them in information security and one in cloud, and a CISSP in good standing waives it entirely. You can read the course at any point; candidates who pass without the experience are recorded as Associates of ISC2 until they earn it.
What should I do after finishing the course?
Move to the CCSP practice exam and work until you are clearing 70% consistently across all six domains rather than leaning on your strong ones, the adaptive live exam will not let you coast on a favorite domain. Then book with Pearson VUE.
Is the course current?
The course follows the six-domain outline and the weights published on the CCSP certification guide: 17%, 20%, 17%, 17%, 16%, and 13%. Effective August 1, 2026, ISC2 moved the CCSP to a refreshed outline from its latest Job Task Analysis, which folds deeper AI and ML security coverage into the same six domains and may shift the weights. The domains themselves are unchanged; download the current outline PDF from isc2.org before you schedule.
Trademark notice & independence. Certifym.net is operated by Certifym Exam Services, LLC and is not affiliated with, endorsed by, or sponsored by ISC2, Inc. ISC2®, CCSP®, CISSP®, CGRC®, and CBK® are registered marks of ISC2, Inc. Certification names and marks are used solely to identify the certification for which these independent study materials are designed. The CCSP exam outline and its domain structure are the property of ISC2, Inc.; candidates should download the official, current exam outline directly from isc2.org.
All course content, questions, answers, and explanations on Certifym are original content created for study purposes. They are not actual ISC2 training materials or examination questions and are not represented as such. Studying with these materials does not guarantee a passing result on any live certification exam. Exam format, domain weights, and eligibility criteria are set by ISC2 and may change, including the refreshed exam outline effective August 1, 2026; always verify current details at isc2.org before scheduling your exam.
