How to pass the IIBA-CCA exam
The IIBA-CCA is knowledge exam — it tests how precisely you know IIBA's Cybersecurity Analysis guidance, in its own vocabulary. This guide gives you the official blueprint, a realistic study plan, and the exact way to practise so you walk in ready.
⚡ The short version
- The exam: 75 multiple-choice questions, 120 minutes. Pass/fail — no published score.
- The trap: it rewards precision — questions use the standard's exact vocabulary, and near-miss options punish paraphrase-level knowledge.
- The plan: read IIBA's Cybersecurity Analysis guidance → drill questions by area → run full timed mocks until you hold 80–85% → review every miss. Budget around 25–45 hours (no official IIBA figure).
- Where to focus: Data Security is 15% of the exam — study it hardest.
What the IIBA-CCA exam actually is
75 multiple-choice knowledge-based questions in 90 minutes. Taken online with remote proctoring (PSI); on-screen pass/fail result at completion.
The official exam blueprint (competency areas)
IIBA publishes exactly how the exam content is distributed. This is your single most useful planning fact — weight your study to match it:
| Area | Weight | |
|---|---|---|
| Data Security | 15% | |
| User Access Control | 15% | |
| Cybersecurity Overview & Basic Concepts | 14% | |
| Enterprise Risk | 14% | |
| Solution Delivery | 13% | |
| Cybersecurity Risks & Controls | 12% | |
| Operations | 12% | |
| Securing the Layers | 5% |
Source: IIBA-CCA Handbook. Data Security alone is 15% — most candidates under-weight it.
Eligibility & cost (the quick facts)
Before you book, you have to qualify and apply:
- No formal prerequisites — no required work experience, PD hours, or references. IIBA recommends roughly 2 years of work in the specialty area.
How long should you study?
For most working analysts, around 25–45 hours (no official IIBA figure) is the realistic range. With a structured prep course and strong existing BABOK fluency, some pass faster; treat "I crammed it in a weekend" stories as outliers built on years of hands-on experience.
What matters more than the hour count is how you spend them. Passive re-reading plateaus fast. The candidates who pass comfortably shift most of their time into answering questions and analysing why each option is right or wrong.
What's the IIBA-CCA pass rate? (the honest answer)
IIBA does not publish official pass rates — so any site quoting an exact "IIBA-CCA pass rate" is guessing or repeating someone else's guess. Here's what we can say honestly:
- Community-reported first-attempt figures vary widely and can't be verified — treat them as noise.
- What is knowable: candidates who consistently hold 80–85% on realistic, full-length mocks before booking overwhelmingly report passing; candidates who book on gut feel are the ones writing "failed by a hair" posts.
- The exam is deliberately passable for prepared candidates — IIBA wants competent certified professionals, not a lottery. Preparation quality, not luck, is the variable you control.
The core strategy: precision beats familiarity
This exam rewards exact knowledge of IIBA's Cybersecurity Analysis guidance — its definitions, its terms, and how its pieces fit together. The distractors are engineered to look right to anyone who knows the material "roughly": they swap adjacent terms, invert a rule, or quote a plausible-sounding phrase that isn't in the standard.
So don't study by osmosis. Learn the vocabulary as written, quiz yourself on the exact definitions, and practise telling near-miss options apart. If your workplace uses different words for the same ideas, note the mapping — the exam only accepts the standard's language.
A study plan that works
Adjust the pace to your timeline, but keep the shape: build understanding first, then convert it into exam reflexes through questions.
Read the standard + take a diagnostic
Read IIBA's Cybersecurity Analysis guidance once for the map — how the areas connect. Take a free diagnostic to see where you stand and seed your error log.
Study area by area
Work one area at a time, heaviest first (Data Security → User Access Control). Read that area, then drill questions on it with explanations for every option. Don't move on until you're at ~80%.
Drill the traps: techniques, terms & calculations
Attack whatever the diagnostic marked weakest — exact definitions, look-alike terms, and any calculation-style items.
Run full-length timed mocks
Sit complete 75-question, 120-minute simulations under exam conditions. Review every wrong answer; spaced repetition resurfaces misses on a 1 → 3 → 7 → 16-day schedule.
Reach readiness & book
When you hold 80–85% across all areas on fresh mocks — not one lucky run — schedule the exam while you're sharp.
The week-by-week plan
The same shape, laid out as a calendar. Studying part-time (around 25–45 hours (no official IIBA figure))? Follow it as written. More time? Compress two weeks into one — but keep the order and the goals.
| When | Focus | You're done when… |
|---|---|---|
| Week 1 | Cybersecurity Overview & Basic Concepts (14%) + Enterprise Risk (14%) — the vocabulary layer. Free diagnostic. | You can define the core security concepts without notes |
| Week 2 | Data Security (15%) + User Access Control (15%) — the two heaviest domains. | 80%+ on both |
| Week 3 | Cybersecurity Risks & Controls (12%) + Solution Delivery (13%) + Operations (12%). | 80%+ on all three |
| Week 4 | Securing the Layers (5%), then two full timed mocks and error-log review; book. | 80–85% held on fresh mocks |
Falling behind? Cut scope from the lightest blueprint areas, never from mocks or error-log review — those two convert knowledge into a pass.
Practice questions: how to actually use them
Do
- Read the explanation for every option — wrong answers teach the most
- Track accuracy per knowledge area, not overall
- Re-attempt misses on a spaced schedule
- Sit full, timed 75-question mocks before booking
Don't
- Use "exam dumps" — stale, often wrong, against IIBA's policies
- Grind questions without analysing why
- Judge readiness on one good run
- Assume job experience covers the whole syllabus
That's exactly how ExamDeck's IIBA-CCA bank is built: original, expert-reviewed questions, an explanation linked to the source for every option, per-area readiness scoring, and a spaced-repetition error log — no dumps, no ads.
See the quality — a real IIBA-CCA question
Exam-day tactics
- Read every scenario twice. The detail that changes the answer is usually in the last sentence.
- Pace yourself — about 1.6 minutes per question. Don't sprint, don't stall.
- Mark-and-skip the hard ones. Bank the easy marks first; return with the time you saved.
- Never leave a question blank. There's no penalty for guessing — answer everything.
- Pick the best answer per IIBA's Cybersecurity Analysis guidance, not the real-world-fastest. They're often different.
- If you're online-proctored, prep your room early: clear desk, ID ready, one monitor, break planned.
Why candidates fail (and how to avoid it)
- Under-studying. "I've done BA work for years" isn't a plan — the exam covers areas your job may not.
- Memorising instead of understanding. Recall fails on "what next?" questions.
- Ignoring the blueprint. Spreading time evenly when Data Security is 15% leaves the biggest area under-prepared.
- Relying on dumps. Stale, often wrong, and a code-of-conduct risk.
- Poor pacing. Six minutes on one question means rushing the last twenty.
Start preparing for IIBA-CCA today
6 free questions in study mode · per-area readiness · no card, no dumps, no ads.
Create your free account →IIBA-CCA exam — frequently asked
How many questions is the IIBA-CCA exam and how long is it?
75 multiple-choice knowledge-based questions in 90 minutes.
What is the passing score for IIBA-CCA?
IIBA does not publish a numeric cut score — results are pass/fail with per-area performance indicators. Aim for a consistent 80–85% on realistic mocks before booking.
What is the IIBA-CCA pass rate?
IIBA does not publish official pass rates, so any exact percentage quoted online is unverified. The readiness signal that actually predicts passing: consistently holding 80–85% on realistic, full-length practice exams before you book.
What are the IIBA-CCA eligibility requirements?
No formal prerequisites — no required work experience, PD hours, or references. IIBA recommends roughly 2 years of work in the specialty area.
How much does IIBA-CCA cost?
No application fee. Learning + Exam bundle $395 (member) / $550 (non-member); Learning-only $195 / $250 — check iiba.org for current packaging.
How long should I study for IIBA-CCA?
For most candidates, around 25–45 hours (no official IIBA figure). What matters most is practising questions and analysing why each option is right or wrong — not just reading.
Does the IIBA-CCA certification need recertification?
None — the CCA is a knowledge-based certificate and does not expire.
Are ExamDeck's IIBA-CCA questions exam dumps?
No — every question is original, written to test the concepts and reviewed before it ships, with an explanation linked to the source for every option. Dumps are stale, often wrong, and against IIBA's policies.