Skip to content

CCSK v5 - Certificate of Cloud Security Knowledge

Exam Overview

The Certificate of Cloud Security Knowledge (CCSK) is the Cloud Security Alliance's foundational cloud security credential. Version 5, released in 2024, aligns with the CSA Security Guidance v5 and Cloud Controls Matrix v4. CCSK is the industry's first and most widely adopted vendor-neutral cloud security certification.

CCSK is not a work-experience-based certification. It is an online, open-book exam that validates knowledge of cloud security principles, architecture, governance, and the practical operation of cloud controls. Many security professionals earn CCSK early in their cloud career or as a bridge alongside provider-specific credentials.

Exam Details: - Exam Code: CCSK v5 - Duration: 120 minutes - Number of Questions: 60 - Question Types: Multiple choice - Passing Score: 80% (48 of 60 correct) - Cost: $395 USD (includes 2 attempts) - Language: English - Delivery: Online via CSA portal (no proctoring; open-book) - Validity: Does not expire; recommended to retake when major versions release - Prerequisites: None

Source Material

CCSK v5 is based entirely on two free, publicly-available documents:

  1. CSA Security Guidance for Critical Areas of Focus in Cloud Computing v5 (2024) - 12 domains, ~200 pages
  2. Cloud Controls Matrix (CCM) v4 - 197 controls across 17 domains

Additional supporting reference (not required but recommended): - ENISA Cloud Computing Risk Assessment (archived but still referenced)

All source materials are free PDF downloads from cloudsecurityalliance.org.

CSA Security Guidance v5 Domains (12 domains)

  1. Cloud Computing Concepts and Architectures - Definitions, service/deployment models, shared responsibility
  2. Cloud Governance - Cloud-aware governance, risk management in cloud context
  3. Risk, Audit, and Compliance - Risk management lifecycle, audits adapted for cloud, regulatory
  4. Organization Management - Cloud account/tenant organization, hierarchies, landing zones
  5. Identity and Access Management - Cloud IAM, federation, CIEM, workload identity
  6. Security Monitoring - Logging, monitoring, detection, SIEM/SOAR in cloud
  7. Infrastructure and Networking - Cloud network architecture, zero trust, segmentation
  8. Cloud Workload Security - VMs, containers, serverless, platform services
  9. Data Security - Classification, protection, encryption, lifecycle, residency
  10. Application Security - SDLC, DevSecOps, API security, serverless apps
  11. Incident Response and Resilience - Cloud IR, forensics, DR/BCP
  12. Related Technologies and Strategies - DevSecOps, zero trust, AI/ML security

Exam Domain Weighting (Approximate)

The exam does not publish strict weightings, but questions are distributed across Guidance domains. Typical observation:

Area Approximate Weight
Cloud concepts and architecture 10-15%
Governance, risk, compliance 15-20%
IAM 10-15%
Infrastructure and networking 10-15%
Data security 10-15%
Application security 5-10%
Security operations, monitoring, IR 10-15%
Related tech (DevSecOps, zero trust) 5-10%
CCM questions 10-15%

Study Materials

Notes

Study Resources

Audience and Career Profile

CCSK is valuable for:

  • Cloud security architects and engineers
  • Security professionals transitioning to cloud
  • Cloud architects and engineers wanting security validation
  • Consultants and auditors advising on cloud
  • Developers building cloud-native apps with security awareness
  • Compliance professionals working with cloud services
  • Anyone preparing for CCSP (CCSK is a stepping stone)

Official Resources

  • CCSK Page: https://cloudsecurityalliance.org/education/ccsk
  • Security Guidance v5 (free PDF): https://cloudsecurityalliance.org/research/guidance
  • Cloud Controls Matrix v4 (free): https://cloudsecurityalliance.org/research/cloud-controls-matrix
  • CAIQ (free): https://cloudsecurityalliance.org/research/cai/
  • STAR Registry: https://cloudsecurityalliance.org/star/registry
  • CSA Research: https://cloudsecurityalliance.org/research/
  • Sample exam question review: Provided on CCSK portal

Self-Study (most common path)

  1. CSA Security Guidance v5 - Read cover-to-cover (required)
  2. Cloud Controls Matrix v4 - Spreadsheet; review all 17 domains
  3. CSA Prep Kit ($) - Includes quiz questions
  4. Daniel Greer CCSK Prep Guide or similar third-party condensed guides

Instructor-Led Training

  1. CSA Authorized Training Providers offer CCSK Foundation and CCSK Plus courses
  2. CCSK Plus includes 2 days of hands-on cloud labs after the foundation course

Free Supplementary Resources

  1. CSA webinars and working group outputs
  2. Cloud provider security docs (AWS Security, Azure Security, GCP Security pillars) for context
  3. ENISA Cloud Computing Risk Assessment (historical but foundational)

After You Pass

  • Digital certificate issued immediately via CSA portal
  • Listed in optional CCSK Holder directory
  • No recurring fees
  • Certificate does not expire
  • When Guidance v6 releases, consider retaking to stay current
  • Next steps:
  • CCSK Plus for hands-on lab validation
  • CCSP if you have the experience (CCSK waives 1 year of CCSP-domain experience)
  • CCZT (CSA's zero trust cert)
  • CCAK (CSA + ISACA cloud auditing cert)
  • Provider-specific security certs (AWS Security Specialty, Azure SC-100/AZ-500, GCP Pro Cloud Security Engineer)

Unique Aspects of CCSK

Open-Book Exam

  • You may reference the Guidance v5 PDF, CCM spreadsheet, and other notes during the exam
  • However, 120 minutes for 60 questions = 2 minutes per question; you cannot look up every answer
  • Must know the material well enough to reference targeted sections quickly

Online Delivery

  • Taken from home/office via browser
  • No proctoring
  • Immediate results
  • 2 attempts included in $395 fee
  • Additional retakes $395 each

Vendor-Neutral

  • No specific cloud provider questions
  • Concepts apply to AWS, Azure, GCP, IBM Cloud, Oracle Cloud, and others

Mindset Tip

CCSK rewards the ability to locate and apply guidance, not memorize it. Prepare by: 1. Reading Guidance v5 cover-to-cover once 2. Building a searchable index (mental or written) of key concepts and which domain covers them 3. Reviewing CCM v4 to understand control categories 4. Taking practice questions to calibrate

On exam day, use open-book status strategically: answer what you know, flag what you need to look up, then return with targeted references.