C)CSA logo
Focused certification exam prep
Start practice

C)CSA Exam Domains 2026: Complete Guide to All 7 Content Areas

TL;DR
  • The Certified Cybersecurity Analyst from Mile2 is organized around seven official course modules, which this site uses as unweighted categories.
  • The exam is 100 multiple-choice questions in roughly 2 hours, with a 70% minimum passing score.
  • Delivery runs through the Mile2 LMS in a current Chrome browser, so test your connection before exam day.
  • The US Exam Combo is USD $550 and includes preparation components plus two attempts under the general combo policy.

How the 7 Modules Map to the Exam

The Certified Cybersecurity Analyst (C)CSA) credential from Mile2 is built on a blue-team curriculum. Its seven course modules cover defensive principles, forensics, malware, network traffic, defensive assessment, SIEM-driven analytics and purple-team collaboration. This guide walks through each one, what it asks of you, and how to prepare for it.

One point of honesty up front: the seven areas below are the official course modules, and we use them here as unweighted study categories. Mile2's public material does not publish a verified percentage weighting per domain, so any article that gives you precise domain percentages for this exam is guessing. Treat all seven as fair game and allocate study time according to your own gaps, not an imagined blueprint.

Why the weighting caveat matters: Several other credentials share the C)CSA acronym, and each has its own domain weights, fees and pass criteria. Those numbers do not apply here. When you research this exam, confirm that every source is describing Mile2's Certified Cybersecurity Analyst specifically.

If you are still orienting yourself on the credential itself, our explainers on what C)CSA certification is and what C)CSA stands for cover the basics before you dive into the modules.

Format, Fee and Delivery Mechanics

Before studying content, understand the container it arrives in. The verified facts are straightforward:

ItemWhat is documented
Certifying bodyMile2
Credential titleCertified Cybersecurity Analyst
Question format100 multiple-choice questions
DurationApproximately 2 hours
Minimum passing score70%
DeliveryOnline through the Mile2 LMS (not a verified third-party testing network)
Technical needsCurrent Chrome browser and reliable internet
US Exam Combo priceUSD $550, including preparation/simulator components and two attempts under the general combo policy

A few things are not verified, and you should confirm them with Mile2 rather than assume: whether the exam is open-book, whether a calculator is permitted, whether questions are adaptive, what proctoring rules apply, and how accommodations are handled. The $550 figure is a combo price, not a verified exam-only price, so budget accordingly. For a fuller cost picture, see our C)CSA certification cost breakdown, and for the score mechanics see what you need to pass.

On eligibility, Mile2 suggests prior knowledge in security, forensics, incident handling and testing, but no mandatory Mile2 course, degree, experience-hour requirement or reference requirement has been verified. Details are in our C)CSA requirements guide.

Domain 1: Blue Team Principles

This module establishes the defender's mindset that the rest of the course builds on. Expect questions that test whether you understand what a blue team actually does day to day, how defensive work is organized, and how monitoring, detection and response fit together.

Blue Team Principles

Foundational defensive concepts that frame every later module.

  • The role of a defender versus an attacker, and how defensive teams are structured
  • Detection and response as a continuous cycle rather than one-off events
  • Incident handling fundamentals, including preparation, identification, containment and recovery
  • How logging, monitoring and visibility underpin every defensive decision

Because this is the entry module, scenario questions here often ask for the best first action or the most appropriate next step in an incident. Practice reading each option as a sequencing problem: which step logically comes before the others?

Domain 2: Digital Forensics

Forensics is where analytical discipline is tested. The core idea is preserving evidence and reconstructing events without altering what you are examining. Candidates who have only done live-response work sometimes underestimate the procedural rigor expected here.

Digital Forensics

Evidence handling, acquisition and analysis.

  • Evidence preservation and chain-of-custody principles
  • Acquiring and examining disk, memory and log artifacts
  • Order of volatility: what to capture first before it disappears
  • Timeline reconstruction from multiple artifact sources
Exam-style thinking: When a question describes a compromised machine, ask what is most volatile and what must be preserved before any remediation. Wiping or rebooting too early is a classic wrong answer in forensic scenarios.

Domain 3: Malware Analysis

This module moves from evidence handling to understanding hostile code. At the analyst level, the emphasis is on recognizing malware behavior and classifying it, not on writing exploits. Know the difference between examining a sample without running it and observing it while it executes in a controlled environment.

Malware Analysis

Understanding what a sample does and how to contain the analysis safely.

  • Static versus dynamic analysis, and the strengths and limits of each
  • Common malware categories and their typical behaviors
  • Safe analysis environments and why isolation matters
  • Indicators of compromise you can extract and hand to the rest of the team

Questions here tend to hinge on choosing the right technique for a stated goal. If the goal is to avoid executing a sample, static methods apply; if the goal is to watch network calls or file changes, a controlled dynamic approach fits.

Domain 4: Traffic Analysis

Network traffic is often the ground truth during an investigation, and this module tests whether you can read it. Expect to interpret what normal looks like so you can spot what is not, and to understand how captured traffic supports detection and forensics.

Traffic Analysis

Reading packets and flows to find malicious or anomalous activity.

  • Packet capture concepts and interpreting common protocol behavior
  • Identifying anomalies such as unusual destinations, beaconing patterns and unexpected protocols
  • The difference between full packet capture and flow-level summaries
  • Using traffic evidence to confirm or rule out a suspected compromise

Solid protocol fundamentals pay off disproportionately here. If TCP handshakes, DNS behavior and common application protocols feel shaky, shore those up first, since later SIEM and detection topics assume them.

Domain 5: Assessing the Current State of Defense within an Organization

This module shifts from reactive analysis to evaluating how well an organization is protected right now. It asks you to think like an assessor: where are the gaps, how do you measure defensive maturity, and how do you communicate findings in a way that drives improvement.

Assessing the Current State of Defense

Measuring posture and identifying weaknesses.

  • Reviewing existing controls, coverage and detection capability
  • Identifying gaps in visibility, logging and response readiness
  • Prioritizing remediation based on risk rather than convenience
  • Reporting findings clearly to technical and non-technical audiences

Key Takeaway

Assessment questions reward prioritization. When several gaps are listed, the correct answer usually addresses the one with the greatest risk and broadest impact, not the easiest fix.

Domain 6: Leveraging SIEM for Advanced Analytics

A note on naming: Mile2's summary list spells this module's title as "Advances Analytics," which differs from its detailed heading. We use the module's listed name in our domain index, but the subject matter is advanced analytics with a SIEM. If you see both spellings in Mile2's own materials, they refer to the same module.

This is where data volume meets detection logic. The SIEM is the central platform that aggregates logs and events, and the module focuses on turning that raw telemetry into actionable detections.

Leveraging SIEM for Advanced Analytics

Using centralized log analysis to detect and investigate threats.

  • Log aggregation, normalization and correlation concepts
  • Building and tuning detection rules to reduce false positives
  • Using queries and dashboards to investigate suspicious activity
  • Connecting events across sources to tell a coherent attack story

Many candidates find this module the most practical because it ties together traffic, host and forensic evidence. Our difficulty guide for the C)CSA exam discusses why integrative modules like this one can feel harder than isolated-topic ones.

Domain 7: Defeating the Red Team with Purple Team Tactics

The final module brings offense and defense together. Purple teaming is the practice of red and blue teams collaborating so that attack simulations directly improve detection and response. Here you are tested on how adversary behavior informs defensive tuning.

Defeating the Red Team with Purple Team Tactics

Collaborative adversary emulation that strengthens defenses.

  • How red-team techniques map to detections the blue team should have
  • Using attack simulation results to close visibility gaps
  • The feedback loop between emulation, detection engineering and re-testing
  • Measuring whether a defensive improvement actually worked

Think of this module as the capstone: it assumes you can already analyze traffic, interpret SIEM data and assess defensive posture, and asks how to improve all of it through structured collaboration.

Sequencing Your Preparation Around the Modules

Because the modules build on one another, order matters more than raw hours. Here is one way to sequence study around the specific content, adjusted to your own background.

Weeks 1-2

Foundations first

  • Blue Team Principles and Digital Forensics, since evidence handling and incident cycles underlie everything else
  • Rebuild any weak protocol fundamentals before touching traffic
Weeks 3-4

Technical analysis

  • Malware Analysis and Traffic Analysis, the two most hands-on technical modules
  • Practice classifying behavior and reading captures
Weeks 5-6

Integration

  • Assessing Defensive State and SIEM analytics, where earlier skills combine
  • Work through correlation scenarios across sources
Week 7

Capstone and review

  • Purple Team Tactics, then mixed-domain practice under timed conditions

Adjust the pace to your experience; someone already working in a SOC may compress the early weeks. For a broader plan, see the C)CSA study guide, and keep the C)CSA cheat sheet handy for last-minute review. Finish with timed sets on our C)CSA practice test platform to get used to 100 questions in about two hours, roughly a minute and a bit per question.

Where These Skills Show Up in Hiring

The seven modules read like a job description for defensive security roles. Employers building monitoring and response capability tend to look for people who can triage alerts, investigate incidents, work with a SIEM and contribute to detection improvement. Titles you may see include SOC analyst, incident responder, threat hunter and security operations roles that blend monitoring with investigation.

Be cautious with salary claims. Mile2's brochure includes a salary figure, but it should not be read as current earnings for certification holders, and we do not publish it as such. For a realistic view of how to weigh pay and career value, read our salary guide, the worth-it ROI analysis, and our overview of C)CSA jobs.

Renewal and Keeping the Credential Active

The certification runs on a three-year renewal cycle. Mile2's central policy offers two routes: 60 documented CEUs over the three years, or taking the latest exam, along with any applicable fee and agreement to professional policy. One caution: the course PDF uses wording that reads as though both routes are required, which conflicts with the central policy. Verify the current rule with Mile2 before planning your renewal.

Plan for renewal early: Start logging relevant training, conferences and security work as soon as you pass. Documented CEUs are far easier to assemble continuously than to reconstruct in year three.

Frequently Asked Questions

Are the seven domains weighted on the C)CSA exam?

The seven areas are official course modules used here as unweighted categories. Mile2's public material does not give a verified percentage per domain, so prepare across all seven rather than targeting a presumed blueprint.

How many questions are on the exam and what score do I need?

The exam has 100 multiple-choice questions over approximately 2 hours, with a minimum passing score of 70%. See our pass rate article for what can and cannot be said about success rates.

Is there a confirmed 2026 version of the exam?

No. The current public outline is undated and no 2026 exam version has been confirmed. Check with Mile2 for the latest objectives before you register, and review scheduling details for timing guidance.

Where do I take the exam?

It is delivered online through the Mile2 LMS rather than a verified third-party testing network. You need a current version of Chrome and a reliable internet connection. Open-book, calculator, adaptive and proctoring rules should be confirmed with Mile2.

What is the best way to start preparing?

Begin with Blue Team Principles and Digital Forensics, then move through the technical modules toward SIEM and purple teaming. Reinforce each stage with targeted questions on our practice test site and the broader study guide.

Ready to pass your C)CSA exam?

Put this into practice with free C)CSA questions across every exam domain.