Training course
This is a free, self-paced reading course for the ISC2 CCSP. Certified Cloud Security Professional, the credential for people who have to secure data, applications, and infrastructure running in someone else’s data center. The CCSP is not a console exam. It does not ask which button provisions a key vault; it asks who holds the key, which jurisdiction’s law reaches the ciphertext, and what your contract says happens when the provider is subpoenaed. This course is written to build that vocabulary and that habit of judgment before you start drilling questions, so a wrong practice answer becomes a gap you can name rather than a fact to memorize.
The course is organized as one module per official exam domain, in the order ISC2 publishes them, and each module carries the domain’s published weight. That matters more on the CCSP than on most exams, because the weights are not flat: Cloud Data Security alone carries 20%, and it is the domain most candidates underestimate. Reading in proportion to the outline keeps you from spending three evenings on virtualization escape scenarios and twenty minutes on crypto-shredding and legal hold. Every lesson ends with its key terms and suggested further reading, so the material works as a reference after the first pass as well as a syllabus during it.
What the course covers
Cloud Concepts, Architecture and Design
Module 1 · 17%The vocabulary and blueprints everything else stands on, service categories and deployment models, the ISO cloud role cast of customer, provider, partner, and broker, the essential characteristics, and the shared responsibility line as it moves across IaaS, PaaS, SaaS, and AI-as-a-Service. The design half covers zero trust, the secure data lifecycle, business continuity and disaster recovery strategy, cost-benefit reasoning, and evaluating providers against ISO/IEC 27017, PCI DSS, Common Criteria, and FIPS 140 validation.
Cloud Data Security
Module 2 · 20%The heaviest domain, and the one that decides most results. It follows data through its whole cloud lifecycle: discovery and classification, encryption architectures including BYOK, HYOK, and envelope encryption, tokenization and masking, where to place DLP, Information Rights Management, retention and legal hold, crypto-shredding, and the logging attributes that make a data event accountable and non-repudiable.
Cloud Platform and Infrastructure Security
Module 3 · 17%The layer beneath the workloads: physical and environmental data center design, compute, storage, virtualization, and the management plane, the single most consequential thing to protect in any cloud estate. Also risk analysis of multi-tenant infrastructure including side channels and VM escape, security control planning, audit mechanisms such as packet capture, and BC/DR engineering against RTO, RPO, and recovery service level targets.
Cloud Application Security
Module 4 · 17%Secure software delivery at cloud speed: the secure SDLC, threat modeling with STRIDE, DREAD, PASTA, and ATASM, the testing alphabet of SAST, DAST, IAST, and SCA, abuse-case thinking, and supply-chain assurance for third-party code, including pre-trained ML models treated as software components. The architecture half covers API gateways, WAFs, sandboxing, microservices trust boundaries, and the identity stack: federation, identity providers, SSO, MFA, CASB, and secrets management.
Cloud Security Operations
Module 5 · 16%Running the environment day to day: hardware roots of trust such as TPM and HSM, bastion-mediated remote access, OS baselining and drift remediation, patching, infrastructure-as-code strategy, clustered-host availability mechanics, and monitoring across network, compute, storage, and response time. The ITIL and ISO 20000-1 process set (change, incident, problem, release, deployment, configuration) is tested directly, alongside cloud digital forensics, SOC operations, and SIEM/SOAR.
Legal, Risk and Compliance
Module 6 · 13%The lightest domain by weight and the one that most separates the CCSP from purely technical cloud certifications: conflicting international legislation, GDPR roles and breach notification, contractual versus regulated data, eDiscovery under ISO/IEC 27050, privacy impact assessments, and the audit report taxonomy of SOC 1, 2, and 3, Type I versus Type II, SSAE and ISAE, and carve-out scopes. Contract design closes it out, right to audit, SLAs and MSAs, vendor viability, escrow, and supply-chain security under ISO/IEC 27036.
How to use it
Read a module, then take the matching portion of the CCSP practice exam rather than saving all the questions for the end. The CCSP is a best-answer exam: its distractors are defensible rather than dismissible, and the gap between recognizing a term and choosing between four reasonable-looking responses only shows up under question pressure. Domain 2 deserves a second pass on its own. Reading the CCSP wrapper here costs nothing and needs no account, but the course lessons themselves open once you are signed in to a free Certifym account.
For exam logistics, the adaptive format, the 100 to 150 item range, the three-hour clock, the 700-of-1000 scaled pass mark, the five-year experience requirement and the CISSP waiver, see the CCSP certification guide.
What CCSP Is: The Cloud Security Practitioner Role
The Certified Cloud Security Professional (CCSP) credential validates deep working knowledge of cloud security across every service and deployment model, jointly maintained by ISC2 and the Cloud Security Alliance (CSA). Where CISSP covers information security broadly and vendor certifications (AWS, Azure, GCP) go deep on one provider, CCSP occupies the middle ground: cloud-fluent security across providers, aligned to standards rather than any single platform.
The practitioner it targets
CCSP is aimed at security professionals with substantial cloud responsibility: cloud security architects, cloud security engineers, security operations engineers running cloud SOCs, GRC practitioners assessing cloud services, and consultants who guide cloud programs. Candidates need five years of paid work experience in IT, with at least three years in information security and one year in one or more of the six CCSP domains. Holding a CISSP substitutes for the entire CCSP experience requirement; holding the CSA CCSK substitutes for one year in a domain.
The six-domain structure
The exam is organized around the cloud life cycle:
- Cloud Concepts, Architecture and Design (17%) — the foundation: service and deployment models, shared responsibility, reference architectures.
- Cloud Data Security (20%) — the largest domain: data lifecycle, encryption, key management, DLP, tokenization, retention, sovereignty.
- Cloud Platform and Infrastructure Security (17%) — virtualization, networks, IAM, physical security, management plane.
- Cloud Application Security (17%) — secure SDLC in the cloud, API security, serverless and container security, DevSecOps.
- Cloud Security Operations (16%) — running the cloud securely: logging, monitoring, incident response, forensics, change management.
- Legal, Risk and Compliance (13%) — the frameworks, contracts, jurisdictional issues, and audit programs that surround cloud services.
The domains interlock: an encryption decision (Domain 2) affects key management (Domain 2), which affects incident response evidence (Domain 5), which affects contract requirements (Domain 6). Exam scenarios frequently cross domains, so learning them in isolation misses the point.
What makes cloud security different
The recurring theme across all six domains: the abstractions the cloud provides are also its security surface. In an on-premises data center, the network cable is a physical thing you can trace; in the cloud, the same functionality is a set of API calls against a virtualized network. This changes:
- Who controls what. The shared responsibility model formalizes what the provider handles versus what the customer must handle. Getting the boundary wrong is the most common source of cloud breaches.
- How you assess. You cannot walk the data center; you consume third-party attestations and configure per shared-responsibility inheritance.
- How fast things move. A misconfiguration in the cloud can expose data to the world in seconds. Compensating slowness with human review does not scale.
- Where evidence lives. Logs are provider APIs, snapshots are storage objects, and forensic images are a matter of provider policy.
Exam format
CCSP is a 150-question, four-hour exam using multiple-choice and advanced-innovative item types. The pass mark is 700 out of 1000 scaled. Endorsement by an existing ISC2 member is required after passing. Recertification is triennial through 90 CPE credits or reassessment.
What this course covers
Each of the six domains gets its own module. The course:
- Builds the shared vocabulary the exam tests (SPI service models, deployment models, ISO 27017 vs. 27018, NIST vs. CSA reference architectures).
- Grounds every concept in specific practices: which key-management pattern for which threat, which log source for which forensic question, which contract term for which risk.
- Distinguishes near-miss options the exam pairs together (BYOK vs. HYOK, tokenization vs. encryption, IaaS vs. PaaS boundaries, provider vs. customer responsibility).
- Points to primary sources — CSA guidance, NIST publications, ISO standards, provider documentation — you should recognize.
How to use this course
Domain 2 (Data Security) is the largest weight and has the most detail; expect Module 2 to take longer than the others. Domains 3, 4, and 5 are technical middle ground. Domain 6 is compact but broad. Read modules in order; the shared responsibility model from Module 1 recurs everywhere.
Pair the course with the Certifym CCSP practice-exam bank once you have covered the whole curriculum. The banks are calibrated to the same domain weights and vocabulary this course establishes.
Frequently asked questions about the CCSP training course
Is the CCSP training course free?
Yes. The course costs nothing to read. Opening the lessons requires a free Certifym account, and nothing beyond that, no payment, no trial. It is funded by the practice-exam catalogue it sits alongside.
How is the course structured?
One module per official CCSP domain, in ISC2’s published order, with each module weighted to the domain’s published percentage. Within each module the material is broken into short lessons, followed by key terms and further reading.
Does this replace ISC2’s official training?
No. ISC2 publishes the authoritative exam outline and sells its own official training; this course is an independent study companion, written to be read quickly and to slot alongside practice questions. Download the current outline from isc2.org and treat it as the source of truth.
Do I need to meet the CCSP experience requirement before studying?
No, the experience requirement applies to certification, not to study. ISC2 asks for five years of cumulative IT experience, three of them in information security and one in cloud, and a CISSP in good standing waives it entirely. You can read the course at any point; candidates who pass without the experience are recorded as Associates of ISC2 until they earn it.
What should I do after finishing the course?
Move to the CCSP practice exam and work until you are clearing 70% consistently across all six domains rather than leaning on your strong ones, the adaptive live exam will not let you coast on a favorite domain. Then book with Pearson VUE.
Is the course current?
The course follows the six-domain outline and the weights published on the CCSP certification guide: 17%, 20%, 17%, 17%, 16%, and 13%. Effective August 1, 2026, ISC2 moved the CCSP to a refreshed outline from its latest Job Task Analysis, which folds deeper AI and ML security coverage into the same six domains and may shift the weights. The domains themselves are unchanged; download the current outline PDF from isc2.org before you schedule.
Trademark notice & independence. Certifym.net is operated by Certifym Exam Services, LLC and is not affiliated with, endorsed by, or sponsored by ISC2, Inc. ISC2®, CCSP®, CISSP®, CGRC®, and CBK® are registered marks of ISC2, Inc. Certification names and marks are used solely to identify the certification for which these independent study materials are designed. The CCSP exam outline and its domain structure are the property of ISC2, Inc.; candidates should download the official, current exam outline directly from isc2.org.
All course content, questions, answers, and explanations on Certifym are original content created for study purposes. They are not actual ISC2 training materials or examination questions and are not represented as such. Studying with these materials does not guarantee a passing result on any live certification exam. Exam format, domain weights, and eligibility criteria are set by ISC2 and may change, including the refreshed exam outline effective August 1, 2026; always verify current details at isc2.org before scheduling your exam.
