certification guide
The CCSP is ISC2’s flagship cloud security credential, the certification that says you can secure data, applications, and infrastructure in someone else’s data center, where you control the configuration but not the concrete. It sits a tier above vendor cloud certs: instead of testing which console button to click, it tests whether you understand shared responsibility, data sovereignty, cryptographic custody, and the legal machinery that follows data across borders. Most candidates arrive with CISSP-level security experience and real cloud scars; the exam rewards exactly that kind of judgment.
Two logistics notes worth knowing before you book. Since October 1, 2025 the CCSP is delivered as a Computerized Adaptive Test, the exam adjusts item difficulty to your performance, so the question count varies between 100 and 150 and there is no going back to review earlier answers. And since August 1, 2026 the exam has run on a refreshed outline from ISC2’s latest Job Task Analysis, with deeper AI/ML security coverage folded into the existing six domains. The weights barely moved: Cloud Application Security slipped from 17% to 16%, Cloud Security Operations rose from 16% to 17%, and the other four domains held. The domain guide below reflects the current outline.
Cloud Concepts, Architecture and Design
The vocabulary and blueprints everything else stands on: service categories and deployment models, the ISO cloud role cast (customer, provider, partner, broker), essential characteristics, and the shared responsibility line as it moves across IaaS, PaaS, SaaS, and now AI-as-a-Service. Expect design-principle questions on zero trust, secure data lifecycle, BC/DR strategy, cost-benefit thinking, and evaluating providers against ISO/IEC 27017, PCI DSS, Common Criteria, and FIPS 140 validation. The refreshed outline also asks you to comprehend AI/ML itself: machine learning in threat detection, validating the data that trains it, SOAR, and the ethical concerns that follow.
Cloud Data Security
The heaviest domain, and for most candidates the hardest. It covers the full data lifecycle in the cloud: discovery and classification, encryption architectures (BYOK vs. HYOK, envelope encryption), tokenization and masking, DLP placement, Information Rights Management, retention and legal hold, crypto-shredding, and the logging attributes that make data events accountable and non-repudiable. The refreshed outline adds the data protection of AI and ML: keeping training datasets and models both private and secure. If you only over-prepare one domain, make it this one.
Cloud Platform and Infrastructure Security
The layer beneath the workloads: physical and environmental data center design, compute, storage, virtualization, and the management plane, the single most consequential thing to protect in any cloud estate. Risk analysis of multi-tenant infrastructure (side channels, VM escape), security control planning, audit mechanisms including packet capture, and BC/DR engineering against RTO, RPO, and recovery service level targets all live here.
Cloud Application Security
Secure software delivery at cloud speed: the secure SDLC, threat modeling methodologies (STRIDE, DREAD, PASTA, ATASM), the testing alphabet (SAST, DAST, IAST, SCA), abuse-case thinking, and supply-chain assurance for third-party code, including pre-trained ML models treated as software components. Architecture topics cover API gateways, WAFs, sandboxing, microservices trust boundaries, and the IAM stack: federation, IdPs, SSO, MFA, CASB, and secrets management.
Cloud Security Operations
Running the environment day to day: hardware roots of trust (TPM, HSM), bastion-mediated remote access, OS baselining and drift remediation, patching, IaC strategy, clustered-host availability mechanics, and monitoring across network, compute, storage, and response time. The ITIL/ISO 20000-1 process set (change, incident, problem, release, deployment, configuration) is tested directly, alongside cloud digital forensics, SOC operations, and SIEM/SOAR.
Legal, Risk and Compliance
The lightest domain by weight but the one that separates the CCSP from purely technical cloud certs: conflicting international legislation, GDPR roles and breach notification, contractual versus regulated data, eDiscovery under ISO/IEC 27050, PIAs, and the audit report taxonomy (SOC 1/2/3, Type I vs. II, SSAE/ISAE, carve-out scopes). Contract design closes it out, right to audit, SLAs and MSAs, vendor viability, escrow, and supply-chain security under ISO/IEC 27036.
Our practice exam mirrors the live experience where it matters: 125 scenario-driven questions weighted to the official six-domain blueprint, a three-hour clock, and, in keeping with how ISC2 actually writes items, distractors that are defensible, not dismissible. Most questions ask for the best answer among several plausible ones, and every explanation tells you why the winner beats the near-miss. ISC2 scores the live exam on a 700-out-of-1000 scale; we set the pass mark at 70% as the honest raw-score equivalent, so a passing run here means genuine coverage across all six domains, not luck in the heavy ones.
ISC2 CCSP - Practice Exam
125 original questions modeled on the ISC2 CCSP exam outline (effective October 1, 2025) and weighted to the official domain percentages: Cloud Concepts, Architecture and Design…
Subscribe to startFrequently asked questions about CCSP
What is the ISC2 CCSP certification?
The CCSP, Certified Cloud Security Professional, is ISC2’s flagship cloud security credential. It validates that you can secure data, applications, and infrastructure running in someone else’s data center, where you control the configuration but not the concrete. Rather than testing which console button to click, it tests whether you understand shared responsibility, data sovereignty, cryptographic custody, and the legal machinery that follows data across borders.
How many questions are on the CCSP exam?
Since October 1, 2025 the CCSP has been delivered as a Computerized Adaptive Test, so the question count varies between 100 and 150. The exam adjusts item difficulty to your performance as you go, and there is no going back to review earlier answers.
What is the passing score for the CCSP?
ISC2 scores the live CCSP on a scale of 1000, with 700 required to pass. Because that is a scaled score rather than a raw percentage, Certifym sets the pass mark on its practice exam at 70% as the honest raw-score equivalent.
How long is the CCSP exam, and how is it delivered?
The exam runs three hours and is delivered in person at Pearson VUE test centers. It is available in English, Chinese, Japanese, and German.
What experience do I need before taking the CCSP?
ISC2 asks for five years of cumulative IT experience, of which three years must be in cybersecurity and one year in one or more of the six CCSP domains. Holding a CISSP in good standing waives the experience requirement entirely.
How hard is the CCSP exam?
It is a demanding exam that rewards judgment over recall. Most candidates arrive with CISSP-level security experience and real cloud scars, and the item writing reflects that: distractors are defensible rather than dismissible, and most questions ask for the best answer among several plausible ones. The adaptive format adds pressure, since you cannot return to an earlier question once you have answered it.
What domains does the CCSP cover, and how are they weighted?
Six domains: Cloud Concepts, Architecture and Design (17%), Cloud Data Security (20%), Cloud Platform and Infrastructure Security (17%), Cloud Application Security (16%), Cloud Security Operations (17%), and Legal, Risk and Compliance (13%). Those are the weights of the outline in force since August 1, 2026. Cloud Data Security is the heaviest and, for most candidates, the hardest; if you over-prepare only one domain, make it that one.
What changed on August 1, 2026?
ISC2 moved the CCSP to a refreshed exam outline drawn from its latest Job Task Analysis. The six domains kept their names, AI/ML security coverage was folded into them (comprehending AI/ML in Domain 1, protecting training data and models in Domain 2), and the weights shifted by a single point: Cloud Application Security from 17% to 16% and Cloud Security Operations from 16% to 17%. Format, length, passing score, and experience requirements did not change. The outline above is the current one; the official PDF is on isc2.org.
How should I prepare for the CCSP?
Work the domains in proportion to their weights and drill scenarios rather than definitions, because the exam is built around best-answer judgment. Certifym’s practice exam mirrors the live experience where it matters: 125 scenario-driven questions weighted to the official six-domain blueprint, a three-hour clock, and explanations that tell you why the winning answer beats the near-miss. Always confirm the current outline and logistics at isc2.org before you schedule.
How does the CCSP compare with the CISSP?
The CISSP is ISC2’s broad information security credential; the CCSP narrows the lens to cloud, shared responsibility, data sovereignty, cryptographic custody, and cross-border legal exposure. The two are closely linked in practice: most CCSP candidates arrive with CISSP-level security experience, and a CISSP in good standing waives the CCSP’s five-year experience requirement outright.
Trademark notice & independence. Certifym.net is operated by Certifym Exam Services, LLC and is not affiliated with, endorsed by, or sponsored by ISC2, Inc. ISC2®, CCSP®, CISSP®, CGRC®, and CBK® are registered marks of ISC2, Inc. Certification names and marks are used solely to identify the certifications for which our independent practice materials are designed. The CCSP exam outline and its domain structure are the property of ISC2, Inc.; candidates should download the official, current exam outline directly from isc2.org.
All questions, answers, and explanations on Certifym are original content created for practice purposes. They are not actual ISC2 examination questions and are not represented as such. Practicing with these materials does not guarantee a passing result on any live certification exam. Exam format, domain weights, and eligibility criteria are set by ISC2 and may change; the current exam outline took effect August 1, 2026. Always verify current details at isc2.org before scheduling your exam.
