Study Guide

CCSP study guide: Assign cloud security responsibilities

Prepare for the current CCSP exam with the six-domain map, an AWS responsibility exercise, practical study tasks and clear adaptive-test and experience rules.

Updated September 20266 min readStudy GuideCEH Exam
Gabrielle Wallace

Gabrielle Wallace

CEH Exam Editorial Team

Prepare for CCSP by identifying the service, the control and the party responsible for it. Use the six-domain map and the worked AWS example to practise distinguishing customer-managed tasks from provider-managed infrastructure, then check the current exam and experience requirements.

Which CCSP outline should you use?

Use the Certified Cloud Security Professional (CCSP) outline effective from 1 August 2026. It covers six domains across cloud design, data, infrastructure, applications, operations and legal, risk and compliance topics.

The current outline explicitly includes artificial intelligence and machine learning (AI/ML), including threat detection, data-source validation, automation and ethical or regulatory considerations. These topics sit within the existing domains; they do not create a separate weighted AI domain.

Official sources: CCSP official English exam outline (effective August 1, 2026) — ISC2 exam outline PDF; Review the ISC2 CCSP Certification Exam Outline — ISC2 exam outline page

What should you review in the six domains?

Use the complete outline alongside this map. The published average weights guide coverage; they are not fixed question counts or a mandatory study timetable.

DomainAverage weightA useful review task
Cloud Concepts, Architecture and Design17%Review service and deployment models, reference architecture, provider evaluation, shared responsibility and the listed AI/ML topics.
Cloud Data Security20%Trace data through its lifecycle; review storage, classification, protection, key management, retention and AI/ML datasets.
Cloud Platform and Infrastructure Security17%Review infrastructure components, risk analysis, data-center controls and business continuity and disaster recovery.
Cloud Application Security16%Review secure development, threat modeling, testing, application interfaces and software supply chains.
Cloud Security Operations17%Review operational controls, identity and access management, incident handling and forensics support.
Legal, Risk and Compliance13%Review cloud contracts, privacy considerations, audit evidence and enterprise risk implications.

Official sources: CCSP official English exam outline (effective August 1, 2026) — ISC2 exam outline PDF

Practise assigning responsibilities for two AWS services

AWS’s published model assigns the EC2 guest operating system to the customer and S3’s underlying managed infrastructure to AWS. Customers still control access to their data in both services.

This original practice uses Amazon EC2 and Amazon S3 as named vendor examples within a vendor-neutral syllabus. Apply AWS’s actual service boundary to these cases; confirm the service documentation and contract before applying a similar pattern elsewhere.

Practice exercise

For this original practice, Team A runs its own application on an Amazon EC2 virtual machine. Team B stores objects in Amazon S3. Use AWS’s published responsibility model to identify: (1) who patches Team A’s EC2 guest operating system; (2) who operates and patches the managed infrastructure operating system underlying Team B’s S3 service; (3) who protects the underlying AWS hosts and physical facilities for both; and (4) who configures customer data-access permissions for each team. Does S3 remove the customer’s data-access responsibilities?

Show answer

1) Team A, the customer, patches its EC2 guest operating system. 2) AWS operates the managed infrastructure underlying S3; Team B does not manage an S3 guest operating system. 3) AWS protects the underlying hosts and physical facilities for both services. 4) Each customer configures access to its own data, including the relevant identity and access management permissions. S3 does not remove that customer responsibility.

The two operating-system questions concern different layers. EC2 leaves the guest operating system and customer application configuration with Team A. S3 abstracts its underlying infrastructure from Team B, while customer decisions about data and access remain. Assign a specific task for a specific service rather than assuming that all cloud security moves to the provider. This example teaches the responsibility boundary; it is not a complete AWS hardening procedure.

Official sources: Shared Responsibility Model - Amazon Web Services (AWS) — AWS compliance documentation

Can you use older CCSP study materials?

Compare their actual coverage with the current outline and supplement the gaps. Neither an old publication date nor a new AI chapter tells you whether the full syllabus is covered.

Read the relevant chapters and explanations, not just the index. Check the detailed objectives across all six domains, including the current AI/ML topics. Mark what is covered, what is missing and what needs a current reference.

For each practice scenario, identify the service model, named service, control and responsible party before evaluating the options. Log errors by concept or assumption and return to the matching objective.

  • Use the domain map and your own practice gaps to plan study time.
  • Practise one-question-at-a-time decisions because finalized CAT answers cannot be changed.
  • Explain why each alternative fails under the stated facts instead of memorizing a provider-versus-customer slogan.

Official sources: CCSP official English exam outline (effective August 1, 2026) — ISC2 exam outline PDF; Review the ISC2 CCSP Certification Exam Outline — ISC2 exam outline page

What do you need to earn CCSP?

Passing the exam and completing certification are separate steps.

The experience baseline is five cumulative years of full-time IT work, including three in cybersecurity and one in a current CCSP domain. Qualifying part-time work and internships may also count under ISC2’s published rules.

A qualifying degree or the Cloud Security Alliance’s CCSK certificate may waive one year, with only one year waived in total. An active CISSP satisfies the entire experience requirement; it does not waive the CCSP exam.

If you pass without the required experience, you can pursue the Associate of ISC2 route, with six years to gain the required five years. Associate status is separate from full CCSP certification.

Submit the certification application within nine months of the exam date, after receiving official passing notification. Experience must be endorsed; an ISC2 professional in good standing can do this, or ISC2 can endorse with the required employment evidence. Complete the ethics and first annual maintenance fee requirements.

Official sources: Experience Needed for the ISC2 CCSP Certification — ISC2 CCSP experience requirements page; Endorsement | Online Endorsement Application | ISC2 — ISC2 endorsement page; What To Do After Your ISC2 Certification Exam — ISC2 after-your-exam page

What should you expect on the exam?

CCSP allows 180 minutes for 100–150 items at Pearson VUE testing centers. It uses computerized adaptive testing (CAT), which selects items as you respond.

Once you finalize an answer, you cannot return to review or change it. Content is not presented in separate domain sections. The minimum-length exam includes 25 unscored pretest items, which you cannot identify. Read each item carefully and practise committing to an answer.

The published passing grade is 700 out of 1000; it is not a raw 70% or a fixed correct-answer count. ISC2 does not report numerical scores. Unsuccessful candidates receive domain proficiency information.

An unofficial result is normally provided at checkout, followed by official notification. Results can be delayed, so avoid planning around a guaranteed email turnaround.

Official sources: CCSP official English exam outline (effective August 1, 2026) — ISC2 exam outline PDF; What To Do After Your ISC2 Certification Exam — ISC2 after-your-exam page; Computerized Adaptive Testing — ISC2 CAT FAQ page

What should you check before booking?

Use ISC2’s current exam policies and your appointment instructions to check identification, accommodations and testing-center requirements.

Check regional pricing when you book. If a retake is needed, the waiting periods are 30 test-free days after the first attempt, 60 after the second and 90 after the third and subsequent attempts, with no more than four attempts per certification program in 12 months.

  • Make sure your registration details match the required identification.
  • Arrange any testing accommodations through ISC2 before scheduling.
  • Review arrival instructions, permitted items and break rules; allowed breaks count against exam time.
  • After passing, keep the exam date and application deadline with your experience records.

Official sources: How to Get Ready, Prepare for Your ISC2 Certification Exam — ISC2 before-your-exam page; What To Do After Your ISC2 Certification Exam — ISC2 after-your-exam page

Official sources

Facts checked against official ISC2 pages:

Next steps

FAQ

Frequently Asked Questions

Practical answers to help you apply the guidance for ISC2 Certified Cloud Security Professional (CCSP).

Does the adaptive exam ending early mean you passed?
No. The exam can stop with either a passing or failing result. Read the actual result rather than inferring it from the number of items or how difficult the last question felt.
How do you maintain CCSP after certification?
Certified holders need 90 continuing professional education (CPE) credits over the three-year cycle, including at least 60 Group A credits; the remaining 30 may be Group A or B. Check the current policy for eligible activities and the annual maintenance fee. The policy’s annual CPE figures for certified holders are suggested pacing, not mandatory yearly minima. Associates follow separate annual requirements.

Keep Reading

Related Study Guides

Explore related guides and preparation topics.