Home › Business Analysis › IIBA-CCA › How to pass
IIBA-CCA · IIBA · Updated October 2026

How to pass the IIBA-CCA exam

The IIBA-CCA is knowledge exam — it tests how precisely you know IIBA's Cybersecurity Analysis guidance, in its own vocabulary. This guide gives you the official blueprint, a realistic study plan, and the exact way to practise so you walk in ready.

🔒 6 free questions · no credit card · no dumps

⚡ The short version

  • The exam: 75 multiple-choice questions, 120 minutes. Pass/fail — no published score.
  • The trap: it rewards precision — questions use the standard's exact vocabulary, and near-miss options punish paraphrase-level knowledge.
  • The plan: read IIBA's Cybersecurity Analysis guidance → drill questions by area → run full timed mocks until you hold 80–85% → review every miss. Budget around 25–45 hours (no official IIBA figure).
  • Where to focus: Data Security is 15% of the exam — study it hardest.
75
Questions
120 min
2h
Pass / fail
No published score
8
Blueprint areas

What the IIBA-CCA exam actually is

75 multiple-choice knowledge-based questions in 90 minutes. Taken online with remote proctoring (PSI); on-screen pass/fail result at completion.

Important: IIBA does not publish a numeric passing score. Instead of a percentage you get pass/fail plus performance indicators per area — so you can't let one weak area sink you. Treat ~70% on realistic mocks as a floor and aim for 80–85%.

The official exam blueprint (competency areas)

IIBA publishes exactly how the exam content is distributed. This is your single most useful planning fact — weight your study to match it:

AreaWeight
Data Security15%
User Access Control15%
Cybersecurity Overview & Basic Concepts14%
Enterprise Risk14%
Solution Delivery13%
Cybersecurity Risks & Controls12%
Operations12%
Securing the Layers5%

Source: IIBA-CCA Handbook. Data Security alone is 15% — most candidates under-weight it.

Eligibility & cost (the quick facts)

Before you book, you have to qualify and apply:

  • No formal prerequisites — no required work experience, PD hours, or references. IIBA recommends roughly 2 years of work in the specialty area.
Cost: No application fee. Learning + Exam bundle $395 (member) / $550 (non-member); Learning-only $195 / $250 — check iiba.org for current packaging.

How long should you study?

For most working analysts, around 25–45 hours (no official IIBA figure) is the realistic range. With a structured prep course and strong existing BABOK fluency, some pass faster; treat "I crammed it in a weekend" stories as outliers built on years of hands-on experience.

What matters more than the hour count is how you spend them. Passive re-reading plateaus fast. The candidates who pass comfortably shift most of their time into answering questions and analysing why each option is right or wrong.

What's the IIBA-CCA pass rate? (the honest answer)

IIBA does not publish official pass rates — so any site quoting an exact "IIBA-CCA pass rate" is guessing or repeating someone else's guess. Here's what we can say honestly:

  • Community-reported first-attempt figures vary widely and can't be verified — treat them as noise.
  • What is knowable: candidates who consistently hold 80–85% on realistic, full-length mocks before booking overwhelmingly report passing; candidates who book on gut feel are the ones writing "failed by a hair" posts.
  • The exam is deliberately passable for prepared candidates — IIBA wants competent certified professionals, not a lottery. Preparation quality, not luck, is the variable you control.
Practical takeaway: ignore pass-rate folklore. Use a measurable readiness bar instead — 80–85% held across all knowledge areas on fresh mocks — and book only when you're there.

The core strategy: precision beats familiarity

This exam rewards exact knowledge of IIBA's Cybersecurity Analysis guidance — its definitions, its terms, and how its pieces fit together. The distractors are engineered to look right to anyone who knows the material "roughly": they swap adjacent terms, invert a rule, or quote a plausible-sounding phrase that isn't in the standard.

So don't study by osmosis. Learn the vocabulary as written, quiz yourself on the exact definitions, and practise telling near-miss options apart. If your workplace uses different words for the same ideas, note the mapping — the exam only accepts the standard's language.

A study plan that works

Adjust the pace to your timeline, but keep the shape: build understanding first, then convert it into exam reflexes through questions.

1

Read the standard + take a diagnostic

Read IIBA's Cybersecurity Analysis guidance once for the map — how the areas connect. Take a free diagnostic to see where you stand and seed your error log.

2

Study area by area

Work one area at a time, heaviest first (Data Security → User Access Control). Read that area, then drill questions on it with explanations for every option. Don't move on until you're at ~80%.

3

Drill the traps: techniques, terms & calculations

Attack whatever the diagnostic marked weakest — exact definitions, look-alike terms, and any calculation-style items.

4

Run full-length timed mocks

Sit complete 75-question, 120-minute simulations under exam conditions. Review every wrong answer; spaced repetition resurfaces misses on a 1 → 3 → 7 → 16-day schedule.

5

Reach readiness & book

When you hold 80–85% across all areas on fresh mocks — not one lucky run — schedule the exam while you're sharp.

The week-by-week plan

The same shape, laid out as a calendar. Studying part-time (around 25–45 hours (no official IIBA figure))? Follow it as written. More time? Compress two weeks into one — but keep the order and the goals.

WhenFocusYou're done when…
Week 1Cybersecurity Overview & Basic Concepts (14%) + Enterprise Risk (14%) — the vocabulary layer. Free diagnostic.You can define the core security concepts without notes
Week 2Data Security (15%) + User Access Control (15%) — the two heaviest domains.80%+ on both
Week 3Cybersecurity Risks & Controls (12%) + Solution Delivery (13%) + Operations (12%).80%+ on all three
Week 4Securing the Layers (5%), then two full timed mocks and error-log review; book.80–85% held on fresh mocks

Falling behind? Cut scope from the lightest blueprint areas, never from mocks or error-log review — those two convert knowledge into a pass.

Practice questions: how to actually use them

Do

  • Read the explanation for every option — wrong answers teach the most
  • Track accuracy per knowledge area, not overall
  • Re-attempt misses on a spaced schedule
  • Sit full, timed 75-question mocks before booking

Don't

  • Use "exam dumps" — stale, often wrong, against IIBA's policies
  • Grind questions without analysing why
  • Judge readiness on one good run
  • Assume job experience covers the whole syllabus

That's exactly how ExamDeck's IIBA-CCA bank is built: original, expert-reviewed questions, an explanation linked to the source for every option, per-area readiness scoring, and a spaced-repetition error log — no dumps, no ads.

See the quality — a real IIBA-CCA question

Cybersecurity Foundations
A business analyst is documenting requirements for a new patient portal. The compliance officer states that under no circumstances may a patient's lab results be disclosed to anyone other than the patient and their authorized clinicians. Which element of the CIA triad does this requirement primarily protect?
AIntegrity
BAvailability
CNon-repudiation
DConfidentiality
Why D. The CIA triad is the foundation of information security. Confidentiality limits information access to authorized parties, integrity protects against improper modification, and availability ensures timely access for authorized users. A rule that data may only be disclosed to specific authorized people is a confidentiality control. A BA must correctly classify such requirements so that appropriate controls (e.g., access controls, encryption) are specified.

Exam-day tactics

  1. Read every scenario twice. The detail that changes the answer is usually in the last sentence.
  2. Pace yourself — about 1.6 minutes per question. Don't sprint, don't stall.
  3. Mark-and-skip the hard ones. Bank the easy marks first; return with the time you saved.
  4. Never leave a question blank. There's no penalty for guessing — answer everything.
  5. Pick the best answer per IIBA's Cybersecurity Analysis guidance, not the real-world-fastest. They're often different.
  6. If you're online-proctored, prep your room early: clear desk, ID ready, one monitor, break planned.

Why candidates fail (and how to avoid it)

  • Under-studying. "I've done BA work for years" isn't a plan — the exam covers areas your job may not.
  • Memorising instead of understanding. Recall fails on "what next?" questions.
  • Ignoring the blueprint. Spreading time evenly when Data Security is 15% leaves the biggest area under-prepared.
  • Relying on dumps. Stale, often wrong, and a code-of-conduct risk.
  • Poor pacing. Six minutes on one question means rushing the last twenty.

Start preparing for IIBA-CCA today

6 free questions in study mode · per-area readiness · no card, no dumps, no ads.

Create your free account →

IIBA-CCA exam — frequently asked

How many questions is the IIBA-CCA exam and how long is it?

75 multiple-choice knowledge-based questions in 90 minutes.

What is the passing score for IIBA-CCA?

IIBA does not publish a numeric cut score — results are pass/fail with per-area performance indicators. Aim for a consistent 80–85% on realistic mocks before booking.

What is the IIBA-CCA pass rate?

IIBA does not publish official pass rates, so any exact percentage quoted online is unverified. The readiness signal that actually predicts passing: consistently holding 80–85% on realistic, full-length practice exams before you book.

What are the IIBA-CCA eligibility requirements?

No formal prerequisites — no required work experience, PD hours, or references. IIBA recommends roughly 2 years of work in the specialty area.

How much does IIBA-CCA cost?

No application fee. Learning + Exam bundle $395 (member) / $550 (non-member); Learning-only $195 / $250 — check iiba.org for current packaging.

How long should I study for IIBA-CCA?

For most candidates, around 25–45 hours (no official IIBA figure). What matters most is practising questions and analysing why each option is right or wrong — not just reading.

Does the IIBA-CCA certification need recertification?

None — the CCA is a knowledge-based certificate and does not expire.

Are ExamDeck's IIBA-CCA questions exam dumps?

No — every question is original, written to test the concepts and reviewed before it ships, with an explanation linked to the source for every option. Dumps are stale, often wrong, and against IIBA's policies.

ExamDeck is an independent study tool. Not affiliated with, endorsed by, or sponsored by IIBA. BABOK® and IIBA-CCA are trademarks of the International Institute of Business Analysis. Exam facts checked against official IIBA materials; always confirm current details with the certification body.