How to pass ISC2 Certified Cloud Security Professional (CCSP)
25 min read6 domains coveredFree practice, no sign-up
CCSP is the senior cloud-security credential, and it tests whether you can make the right security decision once the workload lives on infrastructure someone else owns. The six domains span cloud architecture and design, data security, platform and infrastructure security, application security, security operations, and legal, risk and compliance. You are rarely asked to recall a definition. You are asked what a cloud security professional should do when a control that works on-premises no longer applies, when a responsibility has quietly shifted to the provider, or when a regulation and a service model pull in different directions. The role it certifies is the person who secures the cloud estate and owns the risk of doing so.
It suits experienced practitioners who already work in or around cloud security: security architects, engineers, consultants, and managers who design, assess, or govern cloud environments. The exam runs 100 to 150 questions in three hours, scored out of 1000, and the questions are scenarios where two or three options are all reasonable and only one is best. CCSP requires five years of paid work experience including one year in a CCSP domain, though you can sit the exam first and become an Associate of ISC2 while you accrue it.
One fact matters more than any other for this exam right now. The outline was revised effective 1 August 2026: the six domain weights changed and two brand-new subdomains were added, one on comprehending AI and ML in the cloud and one on protecting AI and ML data. Almost every third-party prep bank still reflects the older outline and does not cover the AI/ML material at all. This guide and its question bank are built to the current outline, so you study what the exam now tests rather than what it used to.
CCSP rewards the cloud architect's judgement - the best control at the right layer, assigned to the correct party under the shared responsibility model, and proportionate to the stated risk - not a textbook definition, so train on scenarios where several controls look right and only one fits.
Difficulty
Advanced
Best for
Experienced practitioners who design, build, assess, or govern cloud environments: security architects, cloud engineers, consultants, and security managers who own cloud risk.
Prerequisites
Five years of cumulative paid work experience in information technology, of which three years must be in information security and one year in one or more of the six CCSP domains. Holding CISSP satisfies the full experience requirement. You can sit the exam first and become an Associate of ISC2 while you accrue the experience.
100 to 150
Questions
180 min
Time allowed
700 / 1000
Pass mark
$599
Exam cost (USD)
291
Practice questions
How this exam thinks
CCSP is written from the chair of a cloud security professional advising a business, not a console operator, and that shift explains most of the answers. The best option is usually the control that sits at the correct architectural layer, is assigned to the party who actually holds it under the shared responsibility model, and is proportionate to the risk the scenario states. The single most-tested idea in the whole exam is that responsibility moves as you go from IaaS to PaaS to SaaS: the customer owns the most in IaaS and the least in SaaS, and a favourite distractor hands the customer a duty the provider holds under SaaS, or hands the provider a duty the customer keeps under IaaS. Fix the service model in your head before you choose.
The core difficulty is that several options are defensible and you must pick the best. The wrong answers are rarely false; they are the right control at the wrong layer, the right action in the wrong order, or a measure proportionate to a different risk than the one described. Respect the sequences the discipline insists on: classify data before you choose its protection, assess risk before selecting a control, run a business impact analysis before designing recovery. Watch the data-protection vocabulary, which the exam probes relentlessly - encryption and tokenisation are not interchangeable, anonymisation is not reversible, masking preserves format, and crypto-shredding is the deletion method that works when you cannot physically destroy shared media. Treat absolutes such as always and never with suspicion; the cloud answer is the risk-proportionate one.
Two currency notes. First, the outline changed on 1 August 2026, so any item keyed to the old weights or missing the AI/ML subdomains is out of date - this material targets the current outline. Second, references matter: a genuine, correctly attributed standard is worth knowing by name, but the exam and good prep never rely on a fabricated control number, and neither should you.
What each domain tests and how to study it
The CCSP blueprint is split across 6 domains. Weights are the official share of the exam; see the official exam guide for the authoritative breakdown.
What you must be able to do. Read an architecture or service-model scenario and choose the design decision or responsibility assignment a cloud security professional should make, correctly placing who owns what as the model moves from IaaS to SaaS.
In one sentenceThe conceptual foundation: cloud definitions and roles, the service and deployment models, the shared responsibility model, secure-design principles, evaluating providers, and the new AI/ML subdomain.
Recall check: answer these from memory first
Draw the shared responsibility stack and state who owns the operating system, the application, and the data under IaaS, PaaS, and SaaS.
List the five essential characteristics of cloud computing from the NIST definition.
Name what a SOC 2 report, the CSA STAR programme, and FedRAMP each assure, in one line each.
What it tests. Cloud as a set of definitions, roles, and design decisions. The NIST definition and its essential characteristics; the roles of customer, provider, partner, broker, and regulator; the service categories (IaaS, PaaS, SaaS) and deployment models (public, private, hybrid, community, multi-cloud); the shared responsibility model and how the boundary moves by service model; secure cloud design principles including the secure data lifecycle, business continuity, and vendor lock-in and portability; evaluating cloud service providers against certifications such as the CSA STAR programme, SOC reporting, FedRAMP, and Common Criteria; and the new subdomain on comprehending AI and ML in cloud environments, including how AI services change the responsibility picture.
How to study it. Anchor everything on the shared responsibility model, because it recurs across all six domains. Draw the stack (physical, virtualisation, operating system, application, data) and shade who owns each layer under IaaS, PaaS, and SaaS until you can do it from memory. Learn the NIST essential characteristics as a checklist, and the deployment models by their trade-offs rather than their names. Get the provider-evaluation programmes straight: SOC reports assure controls, CSA STAR is the cloud-specific assurance registry, FedRAMP is the US government authorisation. For the AI/ML subdomain, focus on how hosting a model changes the responsibility split and introduces training and inference risks that classic cloud controls do not fully cover - this is new outline material that older banks omit entirely.
Easy to confuse
IaaS versus PaaS versus SaaS responsibility. The lower the service model, the more the customer owns: under IaaS the customer secures the operating system upward, under PaaS the provider takes the OS and runtime and the customer keeps the application and data, under SaaS the customer is left mainly with data, access, and configuration. Fix the model before assigning any duty.
Private cloud versus community cloud. A private cloud serves a single organisation exclusively; a community cloud is shared by several organisations with a common concern (a regulator, a mission). Both restrict tenancy, but community spreads it across peer organisations, not one.
CSA STAR versus SOC 2. CSA STAR is a cloud-specific assurance programme built on the Cloud Controls Matrix and published in a public registry; SOC 2 is an AICPA attestation of a service organisation's controls against the trust services criteria. STAR is cloud-purpose-built and often self- or third-party-assessed on a registry; SOC 2 is a formal auditor attestation.
Worked example from the CCSP bank
lock_openFree sampleCloud Concepts, Architecture and Designeasy
A cloud provider allows tenants to view and adjust their allocated storage and compute through a self-service portal at any time, without contacting a sales or support representative. Which essential characteristic of cloud computing does this describe?
ABroad network access, where capabilities are available over the network and reached through standard client platforms such as browsers and mobile devices
BMeasured service, where resource use is monitored, controlled, and reported to give transparency for both the provider and the consumer
COn-demand self-service, where a consumer can provision computing capabilities unilaterally as needed without human interaction with the providercheck_circle Correct
DRapid elasticity, where capabilities can be scaled outward and inward automatically to match demand and appear effectively unlimited
Recognise on-demand self-service as unilateral consumer provisioning without provider interaction. On-demand self-service is defined by the consumer provisioning capabilities such as compute and storage unilaterally and automatically, without requiring any human interaction with the service provider.
Why A is wrong: Broad network access concerns reachability across varied devices; it is tempting because a portal runs over the network, but the scenario stresses provisioning without staff, not device reach.
Why B is wrong: Measured service covers metering and billing transparency; the tenant does see usage, but the defining point here is unattended self-provisioning, not metering.
Why C is correct: The portal lets the tenant provision and adjust resources unilaterally with no provider staff involved, which is exactly the on-demand self-service characteristic in the NIST definition.
Why D is wrong: Rapid elasticity is about automatic scaling to demand; a candidate may confuse manual portal adjustment with elasticity, but the scenario describes human-initiated self-service rather than automatic scaling.
What you must be able to do. Given data of a stated classification and a stated cloud storage architecture, choose the protection technique, key-management approach, or deletion method that fits, and apply the right controls to AI and ML data.
In one sentenceThe largest domain: the cloud data lifecycle, storage architectures, the data-protection techniques and where each fits, discovery and classification, rights management, retention and secure deletion, auditability, and the new AI/ML data subdomain.
Recall check: answer these from memory first
Define encryption, tokenisation, masking, anonymisation, and hashing, and state for each whether it is reversible and whether it preserves format.
Why is crypto-shredding the deletion method of choice in a multi-tenant cloud, and what exactly does it destroy?
Distinguish BYOK from HYOK by who holds and operates the keys.
What it tests. Protecting data across its cloud life. The cloud data lifecycle (create, store, use, share, archive, destroy) and data dispersion; storage architectures by service model and their threats; the data-protection techniques - encryption and key management, hashing, tokenisation, data loss prevention, masking, anonymisation, and emerging methods such as homomorphic encryption and bit splitting; data discovery and classification; Information Rights Management; retention, archiving, legal hold, and secure deletion including crypto-shredding; auditability, traceability, and accountability through logging and chain of custody; and the new subdomain on protecting AI and ML data, covering training-data provenance, poisoning, and leakage.
How to study it. This is the biggest domain and its marks hinge on precise vocabulary, so build a table of the data-protection techniques and never let two blur. Encryption is reversible with a key and protects confidentiality; hashing is one-way and proves integrity; tokenisation swaps a value for a format-matching surrogate held in a separate vault and removes the data from scope; masking hides part of a value while keeping its format for test or display; anonymisation strips identifiers so the data can no longer be tied to a person and is not reversible. Learn key custody as a spectrum from provider-managed to BYOK to HYOK. Learn crypto-shredding as the deletion method for multi-tenant cloud where you cannot physically destroy the media. For the AI/ML data subdomain, focus on training-data poisoning, model inversion leaking training data, and treating inference logs as personal data.
Easy to confuse
Tokenisation versus encryption. Encryption transforms the data with a key and is reversible by anyone holding that key; tokenisation replaces the value with an unrelated surrogate whose mapping lives in a separate vault, so the sensitive data leaves the processing environment entirely. Encryption protects the value in place; tokenisation removes it from scope.
Anonymisation versus masking. Anonymisation irreversibly removes the link between the data and an identifiable person; masking hides or obscures part of a value (often preserving its format) and can be reversible or role-based. If the question needs the data to be permanently non-identifiable it is anonymisation; if it needs a usable but hidden value it is masking.
BYOK versus HYOK versus provider-managed keys. Provider-managed keys are generated and held by the CSP; BYOK means the customer supplies the key material but the provider still operates it in the cloud key service; HYOK keeps the key held and operated by the customer, off the provider's platform, so the provider never has it. Control rises from provider-managed to BYOK to HYOK, and so does operational burden.
Worked example from the CCSP bank
lock_openFree sampleCloud Data Securitymedium
A cloud team must let a downstream analytics service keep processing customer card numbers in the same fixed length and character layout, while ensuring the stored values can be swapped back to the originals only by an authorised service holding a mapping. Which technique meets this requirement?
ATokenisation that replaces each card number with a surrogate of the same length and format, resolvable only through a protected token vaultcheck_circle Correct
BFormat-preserving encryption applied with a shared symmetric key printed in the application configuration
COne-way salted hashing of each card number before it is written to the analytics store
DStatic data masking that overwrites the middle digits with a fixed character while leaving the last four visible
Distinguish tokenisation from masking, hashing, and encryption by its format-preserving surrogate and vault-controlled reversibility. Tokenisation removes the sensitive value from the processing environment by storing a format-matching surrogate with no algorithmic link to the original; reversal is possible only through the separately protected token vault, which is exactly what a controlled swap-back with preserved layout demands.
Why A is correct: Tokenisation substitutes a format-matching surrogate that carries no mathematical relationship to the original, and only the vault holding the mapping can reverse it, satisfying both the format and controlled-reversal requirements.
Why B is wrong: Format-preserving encryption does keep the layout and is reversible, but storing the key in plaintext application config defeats the protection, so this is the weaker choice the requirement does not describe.
Why C is wrong: Hashing preserves neither the format in a useful way nor reversibility, so the originals could never be recovered, which contradicts the stated need to swap values back.
Why D is wrong: Masking is deliberately irreversible for the masked characters, so although it preserves the display format it cannot be swapped back to the original value as required.
What you must be able to do. Analyse a cloud infrastructure risk and choose the proportionate control, secure-design decision, or recovery objective the scenario justifies, distinguishing RTO from RPO when continuity is in play.
In one sentenceSecuring the platform beneath the workload: infrastructure and platform components, secure data-centre design, risk analysis, the control families, and business continuity and disaster recovery.
Recall check: answer these from memory first
State RTO, RPO, and recovery service level in one line each, and say which one frequent replication improves.
Why is the management plane the highest-value target in cloud infrastructure, and name two controls that protect it.
Name the four risk-treatment options and distinguish inherent risk from residual risk.
What it tests. Security of the cloud platform itself. The infrastructure and platform components - physical and network environment, compute, virtualisation, storage, and the management plane; secure data-centre design including logical, physical, and environmental controls and resilience tiering; analysing risks of cloud infrastructure through a risk-assessment methodology, the cloud vulnerabilities and attack vectors, and the risk treatment options; planning and implementing the security controls across physical, system, and communication protection and identification and authentication; and planning business continuity and disaster recovery, including business requirements such as RTO, RPO, and recovery service level, and plan creation and testing.
How to study it. Two areas carry this domain: protecting the management plane and getting the continuity metrics exact. Treat the management plane as the crown jewels of cloud infrastructure - compromise it and every tenant control is moot - so recognise the answers that harden and monitor it. For continuity, drill RTO against RPO until you never swap them: RTO is how quickly a service must be back, RPO is how much data loss (measured in time) is tolerable, and recovery service level is the degree of capability restored. Match a tight RTO to fast failover and a tight RPO to frequent replication. Learn the four risk-treatment options (accept, avoid, transfer, mitigate) and the difference between inherent and residual risk, because the domain frames controls as risk decisions, not defaults.
Easy to confuse
RTO versus RPO. Recovery time objective is the maximum tolerable time to restore a service after disruption; recovery point objective is the maximum tolerable amount of data loss, expressed as a period before the disruption. RTO is about speed of recovery, RPO is about how much data you can afford to lose; tight RPO means more frequent backups or replication.
Inherent risk versus residual risk. Inherent risk is the exposure before any control is applied; residual risk is what remains after controls are in place. The exam asks you to treat, transfer, or accept the residual, not the inherent - controls reduce inherent risk down to residual.
Type 1 versus Type 2 hypervisor. A Type 1 (bare-metal) hypervisor runs directly on the hardware and is the norm for cloud providers; a Type 2 hypervisor runs on top of a host operating system and carries that OS as extra attack surface. Cloud infrastructure risk questions assume Type 1 unless told otherwise.
Worked example from the CCSP bank
lock_openFree sampleCloud Platform and Infrastructure Securitymedium
In cloud infrastructure, which statement most accurately describes the management plane and why it is treated as a high-value target?
AIt is the aggregation of physical network switches and routers that carry east-west traffic between virtual machines within a single host.
BIt is the set of orchestration and administrative interfaces used to provision, configure and control the underlying compute, storage and network resources.check_circle Correct
CIt is the tenant-facing application layer where end users authenticate and consume the running workloads deployed on top of the platform.
DIt is the encrypted data-at-rest tier where tenant volumes and object stores are persisted across availability zones.
Identify the management plane as the orchestration and control layer whose compromise yields broad authority over cloud resources. The management plane exposes the administrative and orchestration APIs and consoles that create, configure and destroy compute, storage and network resources, so control of it means control of the entire environment, which is precisely why it is guarded so heavily.
Why A is wrong: This describes elements of the underlying physical network fabric, not the management plane; the fabric moves workload traffic but does not orchestrate provisioning or configuration.
Why B is correct: The management plane provides the administrative and orchestration control over the whole environment, so compromise of it grants broad authority over provisioning and configuration, making it a prime target.
Why C is wrong: This describes the application or workload layer that consumers interact with, whereas the management plane sits beneath it and controls the resources rather than serving the application to users.
Why D is wrong: This describes storage services, not the control interface; the management plane can configure storage but is not itself the persistence tier.
What you must be able to do. Build security into each phase of the cloud SDLC, choose the testing method or supplemental control that closes a named weakness, and design the identity and access solution a cloud application needs.
In one sentenceSecurity in cloud-hosted software: training and awareness, the secure SDLC and applying it, software assurance and testing, using verified secure software and the supply chain, application architecture components, and IAM.
Recall check: answer these from memory first
Distinguish SAST, DAST, and IAST by what each needs (source, a running app, or an instrumented app) and what each finds.
State what SAML, OpenID Connect, and OAuth are each for in one line.
What is the purpose of a cloud access security broker, and name one risk it addresses.
What it tests. Security shifted into how cloud applications are built and run. Training and awareness including common cloud vulnerabilities and the OWASP Top 10; describing and applying the secure SDLC, threat modelling, and secure coding; cloud software assurance and validation through the testing methodologies - SAST, DAST, IAST, penetration testing, and abuse-case testing; using verified secure software including API security, software supply-chain management, an SBOM, and open-source validation; the specifics of cloud application architecture such as WAF, API gateway, sandboxing, and application virtualisation; and designing IAM solutions including federated identity, single sign-on, multi-factor authentication, a cloud access security broker, and secrets management.
How to study it. Separate the application-testing methods crisply, because the exam contrasts them constantly. SAST reads source code without running it and finds flaws early; DAST tests the running application from the outside and finds runtime and configuration flaws; IAST instruments the running application from the inside to combine both views. Learn the identity protocols by purpose: SAML carries authentication assertions for browser SSO, OpenID Connect adds an identity layer on OAuth, and OAuth itself is delegated authorisation. Treat secrets management and a CASB as recurring cloud-specific answers - hardcoded secrets and shadow SaaS are classic cloud application failures. For the supply chain, treat third-party and open-source components as inherited risk you must assess and track with an SBOM, because you own the risk even in code you did not write.
Easy to confuse
SAST versus DAST versus IAST. Static testing (SAST) analyses source code without executing it; dynamic testing (DAST) probes the running application from the outside with no view of the code; interactive testing (IAST) instruments the running application from within to see both code and runtime. One needs the source, one needs the app running, one needs both.
SAML versus OAuth. SAML carries authentication assertions for browser single sign-on and enterprise federation; OAuth is an authorisation framework that grants an application limited access to a resource without sharing credentials. SAML says who you are, OAuth says what an app may do on your behalf; OpenID Connect adds identity on top of OAuth.
WAF versus API gateway. A web application firewall inspects and filters HTTP traffic to block application-layer attacks such as injection and cross-site scripting; an API gateway manages, authenticates, rate-limits, and routes API calls. Both sit in front of the application, but the WAF is a security filter and the gateway is an API management and control point.
A team lead wants developer training to focus on the most common categories of web application security risk. Which resource is specifically designed to catalogue those widespread risks for awareness and training?
AThe OWASP Top 10, a consensus list of the most critical web application security risks.check_circle Correct
BThe shared responsibility model, which allocates security duties between the cloud provider and the customer.
CA service level agreement, which defines the availability and performance commitments of a cloud service.
DA recovery time objective, which sets the maximum tolerable duration to restore a service after disruption.
The OWASP Top 10 is the standard awareness reference for the most common web application security risks used in developer training. The OWASP Top 10 exists precisely to raise awareness of the categories of web application weakness that appear most often and cause the most harm, such as injection and broken access control. It gives training programmes a shared, prioritised vocabulary, which is why it is the resource pointed to for application security awareness rather than contractual or continuity artefacts.
Why A is correct: Correct. The OWASP Top 10 is a widely used awareness document that ranks the most common and impactful web application security risks.
Why B is wrong: Tempting because it is central to cloud security, but it divides operational responsibility rather than cataloguing common application vulnerabilities.
Why C is wrong: Tempting because it governs the provider relationship, but an SLA sets service commitments and does not list web application risks.
Why D is wrong: Tempting because it is a familiar security metric, but an RTO is a continuity target and has nothing to do with cataloguing application risks.
What you must be able to do. Given a live operational, forensic, or communication scenario, take the next correct step in the right order, and choose the operational control or standard the situation calls for in a multi-tenant cloud.
In one sentenceRunning the cloud securely day to day: building and operating the infrastructure, operational controls and standards, digital forensics, stakeholder communication, and managing security operations.
Recall check: answer these from memory first
Why can you not physically seize evidence in a multi-tenant cloud, and how is digital evidence collected and preserved instead?
Distinguish incident management from problem management by what each is trying to resolve.
State the difference between a TPM and an HSM by role.
What it tests. Security as an operational discipline. Building and implementing the physical and logical infrastructure, including hardware roots of trust such as HSM and TPM and hardening baselines; operating and maintaining it through access controls, patch management, and management-plane availability; implementing operational controls and standards framed by ITIL and ISO/IEC 20000-1, covering change, incident, problem, configuration, and release management; supporting digital forensics with evidence collection and chain of custody where physical seizure is impossible; managing communication with vendors, customers, partners, and regulators; and managing security operations through a SOC, monitoring, log analysis, incident response, and vulnerability assessment.
How to study it. This domain is broad and procedural, so drill the sequences and the multi-tenant twist on each. Learn the incident-response lifecycle in order and be ready to place a scenario at the right phase, because the exam asks what to do next far more than what a term means. For forensics, internalise that in a multi-tenant cloud you cannot seize hardware, so evidence is collected logically through the provider under a defined process and chain of custody, guided by standards such as ISO/IEC 27037 for handling digital evidence. Separate the operational management processes (change, incident, problem, configuration) so you can match a scenario to the right one. Know the hardware roots of trust: a TPM anchors trust on a device, an HSM protects and manages keys as a dedicated appliance or service.
Easy to confuse
Incident management versus problem management. Incident management restores service as fast as possible after a disruption; problem management investigates the underlying cause so the incident does not recur. Incident is the firefight and speed of restoration; problem is the root-cause fix.
TPM versus HSM. A trusted platform module is a chip embedded in a device that anchors a hardware root of trust and stores keys for that device; a hardware security module is a dedicated appliance or service that generates, protects, and manages keys at scale. TPM secures one platform, HSM is centralised key management.
Crypto-shredding versus degaussing. Crypto-shredding destroys the encryption keys so the ciphertext on shared media becomes unrecoverable, and it is the cloud-appropriate method because you cannot touch the hardware; degaussing physically demagnetises magnetic media and requires possession of the drive, which a tenant never has. In the cloud the answer is crypto-shredding, not degaussing.
A security engineer is deciding between a trusted platform module (TPM) and a hardware security module (HSM) for a specific need on new hypervisor hosts. The requirement is to bind disk encryption keys to a known-good boot state so the volume unlocks only when firmware and boot components are unchanged. Which component fits this requirement, and why?
AThe TPM, because it stores platform configuration measurements and can seal keys so they release only when the measured boot state matches expected values.check_circle Correct
BThe HSM, because it is validated to a higher assurance level and therefore supersedes the TPM for any host-based key binding requirement.
CThe HSM, because it can attest to firmware integrity across the fleet and release keys centrally once each host reports a clean boot.
DThe TPM, because it performs high-volume network cryptographic operations for many tenants while keeping keys inside a shared boundary.
Distinguish that a TPM seals keys to a measured boot state on a host, whereas an HSM is a shared boundary for high-volume key operations. A TPM records boot component measurements in platform configuration registers and can seal a key so it is released only when those measurements match a known-good state, which directly meets a boot-bound disk encryption requirement that an HSM does not address.
Why A is correct: Sealing a key to platform configuration register values so it releases only under a known-good boot state is exactly what a TPM provides on a host.
Why B is wrong: Higher validation assurance does not give an HSM measured-boot sealing; that capability is specific to the TPM, so assurance level is the wrong basis for the choice.
Why C is wrong: Firmware measurement and boot-state sealing are TPM functions performed on the host itself; an HSM does not measure a server's boot sequence.
Why D is wrong: High-volume shared network crypto for tenants describes an HSM; a TPM is a low-throughput per-host root of trust, so the reasoning is inverted.
What you must be able to do. Resolve a jurisdiction, privacy, audit, contract, or enterprise-risk scenario by choosing the correct legal role, assurance report, or risk decision, and getting data controller versus processor right.
In one sentenceThe smallest domain but a dense one: legal requirements and jurisdiction, privacy, the audit process, cloud enterprise risk management, and outsourcing and contract design.
Recall check: answer these from memory first
State who the data controller and the data processor are, and which role the cloud provider and the cloud customer usually take.
Distinguish SOC 1, SOC 2, and SOC 3, and then Type I from Type II.
What is the difference between contractual and regulated private data?
What it tests. Cloud through a legal, regulatory, and contractual lens. Legal requirements and unique cloud risks including conflicting international legislation, eDiscovery, and data sovereignty; privacy issues including the difference between contractual and regulated data, jurisdictional differences, PII, and frameworks such as GDPR and ISO/IEC 27018; the audit process and its cloud adaptations, including SOC 2 Type I and Type II, gap analysis, and the ISMS; the implications of cloud to enterprise risk management, including the data controller and processor and data owner and custodian roles, risk treatment, and risk frameworks such as ISO 31000; and outsourcing and cloud contract design, including SLAs, MSAs, the right to audit, and vendor management.
How to study it. This domain is small but its subdomains overlap, so learn the distinctions that carry the marks rather than trying to cover everything. Get the four legal and stewardship roles exact: the data owner or controller decides why and how data is processed, the data custodian or processor acts on the controller's instructions, and the cloud provider is usually the processor while the customer is usually the controller. Nail the SOC reports: SOC 1 is financial-reporting controls, SOC 2 is the security and privacy trust criteria for a knowledgeable audience, SOC 3 is a public-facing summary; and Type I attests design at a point in time while Type II attests operating effectiveness over a period. For privacy, distinguish contractual data (protected by agreement) from regulated data (protected by law), and cite regulations and standards by name rather than guessing article or clause numbers.
Easy to confuse
Data controller versus data processor. The controller determines the purposes and means of processing personal data; the processor acts only on the controller's documented instructions. In cloud the customer is usually the controller and the provider is usually the processor, and accountability for the decision stays with the controller.
SOC 2 Type I versus Type II. A Type I report attests that controls are suitably designed at a single point in time; a Type II report attests that those controls operated effectively over a period (typically six to twelve months). Type I is a snapshot of design, Type II is evidence of sustained operation.
ISO/IEC 27017 versus ISO/IEC 27018. ISO/IEC 27017 gives cloud-specific security controls and guidance for both providers and customers; ISO/IEC 27018 gives a code of practice for protecting personally identifiable information in public clouds acting as processors. 27017 is cloud security controls, 27018 is PII in public clouds - they are constantly swapped, so read what the data is.
Worked example from the CCSP bank
lock_openFree sampleLegal, Risk and Compliancemedium
A security architect is distinguishing data sovereignty from data residency while planning a multi-region public cloud deployment for a regulated client. Which statement best captures data sovereignty?
AData must simply be stored and processed within a specified geographic boundary chosen by the customer.
BThe cloud customer, rather than the provider, must hold and manage the encryption keys protecting the data.
CData is subject to the laws and governance of the country in which it is physically located, regardless of who owns it.check_circle Correct
DData must be replicated across at least two national regions to guarantee availability during an outage.
Data sovereignty means data is governed by the laws of the country where it physically resides, distinct from mere residency. Sovereignty is a jurisdictional concept: once data sits in a country, that country's laws can reach it, which is why sovereignty drives transfer and disclosure risk rather than simple storage location.
Why A is wrong: Tempting because it sounds like a location rule, but this describes data residency, which is only about where data physically sits, not which laws govern it.
Why B is wrong: This describes customer-managed key control, a technical safeguard, not the legal concept of which nation's laws apply to the data.
Why C is correct: Correct. Data sovereignty is the principle that data falls under the legal jurisdiction of the nation where it resides, so local law can compel access or restrict transfer.
Why D is wrong: This describes a resilience or availability requirement, which is unrelated to the jurisdictional meaning of sovereignty.
A study plan that works
Map the six domains and book a date
Week 1
Read the current exam outline and the six domains with their weights, paying attention to the fact that the outline changed on 1 August 2026 and now includes the AI and ML subdomains. Book a provisional date now: a fixed date turns open-ended study into a plan and is the strongest predictor of actually sitting.
Master the shared responsibility model (Domain 1)
Weeks 1 to 2
Start here because the shared responsibility model underpins every other domain. Draw the stack and shade who owns each layer under IaaS, PaaS, and SaaS until it is automatic. Learn the NIST definition, the deployment models, and the provider-assurance programmes, and give the new AI/ML subdomain real attention because older material skips it.
Drill the data-protection techniques (Domain 2)
Weeks 2 to 4
The largest domain turns on precise vocabulary. Build the table of encryption, tokenisation, masking, anonymisation, and hashing and rehearse which are reversible and which preserve format. Learn the key-custody spectrum (provider-managed, BYOK, HYOK), crypto-shredding for cloud deletion, and how the new AI/ML data subdomain treats training and inference data.
Work platform, application, and operations (Domains 3, 4, and 5)
Weeks 4 to 7
These three are the technical core and together the largest share of the exam. Drill RTO against RPO, the application-testing methods (SAST, DAST, IAST), the identity protocols, the management plane, and the cloud twist on forensics and operational controls. Practise on scenario questions and read the explanation on every one, including those you got right.
Cover legal, risk and compliance (Domain 6)
Weeks 7 to 8
The smallest domain but a dense one where subdomains overlap. Nail the controller-versus-processor and owner-versus-custodian roles, the SOC report types and Type I versus Type II, and contractual versus regulated data. Learn the standards by name rather than guessing clause or article numbers.
Drill weak domains, then space the review
Weeks 8 to 10
Use your per-domain accuracy to attack the domains dragging you down rather than re-reading what you already know. Then space it: revisit each domain's recall prompts after a few days and again a week later. Spacing roughly doubles what sticks compared with cramming.
Sit timed mocks and calibrate judgement
Weeks 10 to 12
Take full timed mocks to rehearse the best-of-several-defensible-answers judgement and pacing across three hours. Treat the score as a per-domain readiness signal, not a single number, and review every missed question, focusing on why the wrong controls are at the wrong layer or the wrong party.
Know when you're ready
Readiness for CCSP is a measured score on questions you have not seen before, not a feeling that the material is familiar. Those are different things, and the gap between them is where people fail. Re-reading notes builds fluency, and fluency feels like knowledge, so confidence rises while real recall does not. The fix is to test yourself on fresh scenarios: if you can read a new cloud situation, fix the service model, pick the best of several reasonable controls, and explain why each wrong one is at the wrong layer, assigned to the wrong party, or proportionate to a different risk, you know it. If you can only nod along to an explanation, you do not yet.
Be especially wary of two things. First, the data-protection vocabulary - encryption, tokenisation, masking, anonymisation, hashing - because these are where confident-sounding wrong answers live, and the exam probes them hard. Second, currency: study material written before 1 August 2026 will teach the old weights and will not cover the AI and ML subdomains at all, so a bank that looks comprehensive may be testing the wrong exam. Trust your measured per-domain accuracy over your gut, and set the bar at clearing every domain comfortably on unseen questions across more than one session.
This guide gives you the map. The practice bank is where you find out whether you can navigate it, with an explanation of why the right answer is right and every wrong one is wrong on every question, built to the current outline. Readiness scoring tells you when you are there. Not before.
Ready to put this into practice?
Free CCSP questions, every answer explained. No sign-up.
Fix the service model first. Before assigning any responsibility, decide whether the scenario is IaaS, PaaS, or SaaS, because the shared responsibility boundary moves with it and the wrong assignment is the most common distractor.
Choose the best control, not merely a correct one. Two or three options are often defensible; the wrong ones are the right control at the wrong layer, in the wrong order, or proportionate to a different risk.
Respect the sequence. Classify data before protecting it, assess risk before selecting a control, and run a business impact analysis before designing recovery - an answer that skips a step that comes first is the distractor.
Keep the data-protection terms exact. Encryption is reversible with a key, tokenisation removes data from scope, anonymisation is not reversible, masking preserves format, and crypto-shredding is cloud deletion; the exam swaps these deliberately.
In the cloud, choose the cloud-appropriate control. Physical media destruction and hardware seizure are not available to a tenant, so crypto-shredding and logical, provider-mediated evidence collection are the answers.
Distrust absolutes. Options that say always, never, or the most extreme action are usually wrong, because the cloud answer is a proportionate response to the stated risk.
Mind the currency. This exam follows the outline effective 1 August 2026, so expect the AI and ML subdomains and the current domain weights, and discount anything that looks keyed to the older outline.
Frequently asked questions
Is CCSP hard?
It is genuinely demanding, but less because the facts are obscure and more because the questions ask for the best of several reasonable answers about how to secure infrastructure you do not fully control. The breadth across six domains and the constant shared-responsibility judgement are the real challenge, which is why scenario practice that explains every option beats memorising definitions.
How long should I study for CCSP?
Most candidates with cloud and security experience need three to four months of steady study. The right amount depends on how much of the six domains your day job already covers; budget the most time for the domains furthest from your daily work, and give extra attention to the new AI and ML material that older prep omits.
What is the pass mark for CCSP?
700 out of 1000 on a scaled score, shown in the facts panel above. The scale is not a straight percentage, so aim to clear every domain comfortably on unseen practice questions rather than targeting a raw figure.
Do I need five years of experience before I can take the exam?
No. You can sit the exam first and, on passing, become an Associate of ISC2 while you accrue the required experience: five years of cumulative paid IT work, including three years in information security and one year in a CCSP domain. Holding CISSP satisfies the full experience requirement.
Why does it matter that the CCSP outline changed in August 2026?
The revision effective 1 August 2026 changed the six domain weights and added two subdomains, one on comprehending AI and ML in the cloud and one on protecting AI and ML data. Almost all third-party prep still reflects the older outline and omits the AI/ML material, so studying from it means studying the wrong exam. This guide and bank are built to the current outline.
How is CCSP different from CISSP?
CISSP is a broad security-management credential across eight domains; CCSP goes deep on securing cloud environments specifically, and assumes you already understand core security. Many people hold both, and holding CISSP satisfies the CCSP experience requirement. If your work is cloud-focused, CCSP is the more targeted credential.
Which domains should I focus on?
Cloud Data Security is the largest domain and turns on precise data-protection vocabulary, so it rewards careful study. The shared responsibility model in the first domain underpins everything else, so master it early. That said, your weakest domain matters more than the largest one, so let your per-domain accuracy guide where the time goes.
How many practice questions should I do before booking?
Enough that every domain clears the pass line with margin on questions you have not seen, and a full timed mock feels comfortable on judgement and pacing. Quality of review beats raw volume: read the explanation on every question, including the ones you got right, and focus on why the wrong options are wrong.
Examworthy is not affiliated with or endorsed by ISC2. This guide is original study material based on the public exam blueprint. We never reproduce live exam items. CCSP and related marks belong to their respective owners.