CCA logo
Focused certification exam prep
Start practice

CCA Study Guide 2026: How to Pass on Your First Attempt

TL;DR
  • The IIBA-CCA exam has 75 multiple-choice questions in 90 minutes across eight domains.
  • Data Security and User Access Control are the two heaviest domains, each worth 15%.
  • Member exam fee is $250; non-members pay $405, which includes first-year IIBA membership.
  • A purchased exam attempt must be used within 6 months, so schedule your test date early.

What the IIBA-CCA Actually Tests

The Certificate in Cybersecurity Analysis (CCA) is issued by the International Institute of Business Analysis (IIBA) in collaboration with the IEEE Computer Society, formally designated IIBA-CCA. It isn't a hands-on penetration testing credential or a compliance-audit certificate - it's a knowledge-based exam built for people who sit at the intersection of business analysis and cybersecurity: analysts, risk professionals, and technical staff who need to translate security requirements into business decisions and vice versa.

If you're still deciding whether this credential fits your career path, our companion piece on whether the CCA certification is worth it walks through the ROI case in detail. For a plain-language primer, see What Is CCA Certification? before diving into study strategy.

Why "study guide" matters here: Because the IIBA-CCA is knowledge-based rather than scenario-simulation heavy, disciplined domain-by-domain review pays off more than generic "test-taking tricks." Your first-attempt success hinges on mapping study hours to the official domain weights, not on guessing question formats.

Exam Format, Fees, and Registration Mechanics

Before you build a study plan, you need to understand exactly what you're preparing for. The IIBA-CCA exam:

  • Contains 75 knowledge-based multiple-choice questions
  • Runs for 90 minutes
  • Is delivered via PSI online remote proctoring
  • Reports results as a simple pass/fail - no scaled score
  • Must be completed within 6 months of purchase

Pricing depends on membership status. The exam fee is $250 for IIBA members and $405 for non-members (the non-member price bundles first-year IIBA membership). If you don't pass on the first try, retakes cost $195 for members and $350 for non-members. There's also an optional learning-and-exam bundle priced at $395 for members and $550 for non-members - worth considering if you want structured coursework, though it's not required to sit the exam.

For a full line-item breakdown of every fee scenario, read CCA Certification Cost 2026: Complete Pricing Breakdown. And if you're unclear on who can even register, CCA Requirements 2026 covers eligibility in detail.

Key Takeaway

Since your exam window is only 6 months from purchase, don't buy your exam voucher until you've already blocked out a realistic study calendar - otherwise the clock works against you.

Domain-by-Domain Breakdown

The 2026 IIBA-CCA Handbook defines eight examination domains - don't confuse these with the nine courses inside the optional learning program, which is a separate structure entirely. Here's how the exam weight is distributed:

DomainWeight
Data Security15%
User Access Control15%
Cybersecurity Overview and Basic Concepts14%
Enterprise Risk14%
Solution Delivery13%
Cybersecurity Risks and Controls12%
Operations12%
Securing the Layers5%

Notice that Data Security and User Access Control together account for 30% of the exam - nearly a third of your score comes from these two areas alone. For the full breakdown of subtopics inside each domain, our dedicated guide, CCA Exam Domains 2026: Complete Guide to All 8 Content Areas, goes deeper than we can here.

Data Security (15%)

Candidates need to understand how data is classified, encrypted, stored, and protected across its lifecycle, plus how business analysts should factor data protection into requirements gathering.

  • Data classification schemes and handling requirements
  • Encryption concepts at rest and in transit
  • Data loss prevention considerations in business processes

User Access Control (15%)

This domain tests your grasp of identity management, authentication models, and authorization structures - the mechanics of who gets access to what, and why that decision matters for risk.

  • Authentication vs. authorization concepts
  • Role-based and least-privilege access models
  • Identity lifecycle management in enterprise systems

Securing the Layers (5%)

The smallest domain by weight, but don't skip it - it covers network, application, and infrastructure layer security concepts that show up as connective tissue in other domain questions too.

  • Defense-in-depth thinking across technical layers
  • How layered controls reduce single points of failure

A Domain-Weighted Study Timeline

Rather than splitting study time evenly across eight domains, allocate hours proportional to exam weight. Below is a sample structure candidates can adapt; the goal is to hit the heaviest domains - Data Security and User Access Control - more than once before test day.

Week 1

Foundations

  • Review Cybersecurity Overview and Basic Concepts (14%)
  • Read the official IIBA-CCA Handbook domain outline end to end
Week 2

Risk Core

  • Study Enterprise Risk (14%) and Cybersecurity Risks and Controls (12%)
  • Map risk terminology to business analysis language
Week 3

Heaviest Domains, Round 1

  • Deep dive into Data Security (15%)
  • Deep dive into User Access Control (15%)
Week 4

Delivery and Operations

  • Cover Solution Delivery (13%) and Operations (12%)
  • Skim Securing the Layers (5%)
Week 5

Second Pass on Heavy Domains

Week 6

Final Review

  • Work through a condensed CCA cheat sheet for last-minute recall
  • Confirm remote-proctoring setup and schedule your exam window

This structure isn't about applying generic study science for its own sake - it's a scheduling logic where the two 15%-weighted domains each get two dedicated study passes, while the 5%-weighted domain gets a single lighter pass. If you want to know how tough this actually feels once you're inside the exam, How Hard Is the CCA Exam? Complete Difficulty Guide 2026 covers that from a candidate-experience angle.

Understanding the Question Style

All 75 questions are multiple-choice and knowledge-based - there are no simulations, drag-and-drop items, or scenario labs to navigate. That said, "knowledge-based" doesn't mean pure memorization. Expect questions that present a short business or technical scenario and ask you to identify the most appropriate control, risk response, or access model given the context.

Because results are pass/fail with no published scaled score, there's no partial-credit strategy to game - every question matters equally toward the same outcome. For specifics on what threshold you're aiming for, see CCA Passing Score 2026: Exactly What You Need to Pass.

Practice with intent: Since the exam is entirely multiple-choice, timed practice questions that mirror the eight-domain weighting are the single highest-leverage prep activity. Running full-length simulations on a CCA-focused practice test site before test day helps you calibrate pacing across 90 minutes and 75 questions - roughly 72 seconds per question on average.

Remote Proctoring: What Trips People Up

The exam is delivered remotely through PSI's online proctoring system, and the logistics catch more candidates off guard than the content does. You'll need valid identification, a compatible computer, a working webcam and microphone, and a private, secure testing environment free of interruptions.

  • No reference materials of any kind are permitted during the exam
  • No calculator is allowed
  • No scheduled breaks - plan your hydration and bathroom needs before you start the 90-minute clock
  • Your room must be clear of notes, secondary monitors, and other people

Test your webcam, microphone, and internet connection well ahead of your scheduled slot. A proctoring rejection or technical delay on exam day can cost you time you don't get back. If you're still choosing a testing window, CCA Exam Dates 2026: Testing Windows, Deadlines & Scheduling explains how remote scheduling works in practice.

Common First-Attempt Mistakes

Most candidates who don't pass on their first attempt fall into one of a few predictable patterns:

  • Treating all domains equally. Spending the same number of hours on Securing the Layers (5%) as on Data Security (15%) is a poor use of limited study time.
  • Confusing the exam blueprint with the learning program. The exam has eight domains; the optional learning program has nine courses. Studying course-by-course without mapping back to the handbook's domain weights can leave gaps.
  • Under-preparing for remote-proctoring logistics. Losing 15 minutes to a webcam setup issue inside a 90-minute exam is a self-inflicted disadvantage.
  • Skipping timed practice. Reading domain content passively doesn't build the pacing instinct needed to move through 75 questions in 90 minutes confidently.
  • Not registering with a buffer. Because your purchased exam must be used within 6 months, waiting too long to schedule can force a rushed, underprepared attempt near the deadline.

Our broader CCA study guide resources and the domain guide linked above are good places to cross-check your prep plan against the actual blueprint one more time before you commit to a test date.

After the Exam: Retakes and Certification Maintenance

If you don't pass, the retake fee is lower than the original exam fee - $195 for members and $350 for non-members - so a second attempt is financially more forgiving than starting from scratch. Use your score report to identify which domains need another study pass, particularly if Data Security or User Access Control questions felt uncertain.

One notable upside once you do pass: the Certificate in Cybersecurity Analysis does not expire and requires no recertification or continuing development units (CDUs). Unlike many professional credentials, there's no ongoing renewal fee or annual maintenance cycle to budget for after you earn it.

Curious how this credential translates into actual job titles and hiring demand? CCA Jobs and CCA Salary Guide 2026: Complete Earnings Analysis both explore that from a market-demand angle, while CCA Training covers preparation resources beyond self-study.

Frequently Asked Questions

How many questions are on the IIBA-CCA exam and how long do I get?

The exam contains 75 knowledge-based multiple-choice questions, and you have 90 minutes to complete it via PSI remote proctoring.

Which CCA domains should I prioritize if I'm short on study time?

Focus first on Data Security and User Access Control, each weighted at 15% - together they represent 30% of the exam, the largest concentration among the eight domains.

Is the CCA learning program required to sit the exam?

No. The learning-and-exam package is optional. Candidates can register for the exam alone and study independently against the eight-domain handbook blueprint.

What happens if I don't pass on my first attempt?

You can retake the exam for $195 (members) or $350 (non-members), which is lower than the original exam fee. Use the time before retesting to revisit your weaker domains.

Does the CCA certification expire?

No. Once earned, the Certificate in Cybersecurity Analysis does not expire, and there is no recertification requirement or CDU obligation to maintain it.

Ready to pass your CCA exam?

Put this into practice with free CCA questions across every exam domain.