The CCSP – Certified Cloud Security Professional training program is designed to equip professionals with the essential skills to become proficient in CCSP – Certified Cloud Security Professional.
Through hands-on labs, real-world simulations, and cutting-edge AI-driven tools, participants will become proficient in ethical hacking techniques and critical cybersecurity practices for defending against traditional and modern AI-powered threats.
| Certification Name | CCSP – Certified Cloud Security Professional |
|---|---|
| Exam Format | Multiple Choice Questions |
| Number of Questions | 100 - 150 |
| Exam Duration | 3 Hours |
| Passing Score | (Typically 700 out of 1000) |
| Exam Delivery | ISC2 Authorized PPC and PVTC Select Pearson VUE Testing Centers |
CCSP (Certified Cloud Security Professional) is designed for IT and security professionals who want to demonstrate advanced technical skills and knowledge of cloud security design, implementation, and compliance.
The CCSP (Certified Cloud Security Professional) certification by (ISC)² is an advanced-level credential, so it does have specific experience and eligibility requirements.
Domain 1: Cloud Concepts, Architecture, and Design (17%) Focuses on understanding cloud computing fundamentals and secure architecture design. Key Topics: Cloud computing concepts and definitions (IaaS, PaaS, SaaS, etc.) Cloud reference architecture and deployment models Key cloud computing roles (cloud provider, consumer, broker, etc.) Cloud service models and shared security responsibility Secure cloud design principles and components Cloud computing characteristics (elasticity, multi-tenancy, resource pooling) Cloud security concepts (threats, vulnerabilities, and risk) Goal: Understand the foundations of cloud systems and how to securely design them. Domain 2: Cloud Data Security (19%) Focuses on securing data throughout its lifecycle in the cloud environment. Key Topics: Cloud data lifecycle phases (creation, storage, use, sharing, archiving, destruction) Cloud data security controls and technologies Data classification, labeling, and handling Encryption and key management in cloud environments Data discovery and data loss prevention (DLP) Cloud storage architectures and access controls Cloud data privacy and protection standards (GDPR, HIPAA, etc.) Goal: Learn to protect and manage data in the cloud using encryption, privacy controls, and lifecycle management. Domain 3: Cloud Platform and Infrastructure Security (17%) Covers the security of virtual and physical infrastructure supporting cloud services. Key Topics: Cloud infrastructure components (network, compute, storage) Security risks in virtualization and containers Network security and segmentation in cloud environments Virtualization security controls (hypervisors, VM isolation, etc.) Cloud access security broker (CASB) Business continuity (BC) and disaster recovery (DR) planning Physical and environmental security for cloud data centers Goal: Understand and secure the underlying infrastructure that supports cloud services. Domain 4: Cloud Application Security (17%) Focuses on securing software and applications deployed in cloud environments. Key Topics: Secure software development lifecycle (SDLC) for cloud Cloud application architecture and APIs Application security testing and assessment Identity and access management (IAM) in applications Cloud-specific threats (insecure APIs, misconfigurations, etc.) DevOps and DevSecOps practices Secure CI/CD pipeline implementation Goal: Develop and maintain secure cloud-native and SaaS applications. Domain 5: Cloud Security Operations (17%) Focuses on running and maintaining secure cloud environments day-to-day. Key Topics: Cloud operational controls and processes Change management and patch management Incident detection, response, and recovery in cloud Logging, monitoring, and auditing Security operations automation and orchestration (SOAR) Continuous compliance and security assessments Backup, recovery, and resilience strategies Goal: Manage cloud security operations, incident response, and compliance monitoring effectively. Domain 6: Legal, Risk, and Compliance (13%) Covers the governance, legal, and regulatory aspects of cloud computing. Key Topics: Legal frameworks and cross-border data issues Risk management frameworks (ISO 27005, NIST SP 800-37, etc.) Privacy regulations (GDPR, HIPAA, PCI DSS) Cloud contract management (SLAs, audit rights, compliance clauses) Compliance programs and audit processes E-discovery and digital forensics in the cloud Vendor and third-party risk management Goal: Ensure compliance, manage risk, and understand legal implications in cloud environments.
Exam Name Certified Cloud Security Professional (CCSP) Exam Provider (ISC)² Exam Type Computer-Based Test (CBT) Exam Duration 3 hours (180 minutes) Number of Questions 125 multiple-choice questions Question Types Multiple Choice (single and scenario-based) Passing Score 700 out of 1000 points Language English (other languages may be added later) Delivery Method Pearson VUE Testing Centers (online or in-person)
No — the CCSP (Certified Cloud Security Professional) is not directly aligned with Splunk certification exams, but there is some conceptual overlap, especially in cloud security monitoring, logging, and incident response.
The CCSP (Certified Cloud Security Professional) exam is 3 hours (180 minutes) long.