CCITP-A logo
Focused certification exam prep
Start practice

CCITP-A Exam Domains 2026: Complete Guide to All 6 Content Areas

TL;DR
  • CCITP-A covers six domains, but only four carry a published individual weight: Policy and directives (20%), Social and behavior science (10%), Researching...
  • Domains 4 (Synthesis) and 5 (Tools and methods) are reported together at 35% of the exam - the largest published content group.
  • The exam itself is 86 scenario-based multiple-choice questions (80 scored, 6 unscored) in 135 minutes, delivered at Pearson VUE centers.
  • Passing requires a scaled score of 650/800, not a flat percentage of correct answers.

CCITP-A Exam Structure at a Glance

Before drilling into content, it helps to understand the shape of the test itself. The CCITP-A assessment is a scenario-based, multiple-choice exam made up of 86 total questions - 80 scored and 6 unscored - administered in 135 minutes at a Pearson VUE test center. Candidates must already hold DAU eligibility approval before they can schedule a seat, and the published handbook lists no assessment fee for eligible candidates, since the credential is administered through DCSA/CDSE/SPeD Program Management Office rather than a traditional membership-based certifying body.

Passing isn't a simple raw-percentage calculation. The handbook specifies a scaled passing threshold of 650 out of 800, which is a different thing entirely from "get 81% of questions right." For a deeper breakdown of exactly how that scaling works, see our dedicated CCITP-A Passing Score guide. If you're still mapping out eligibility - the CITP-F prerequisite, the 12-month program experience requirement, the training hour minimums - the CCITP-A Requirements breakdown walks through each piece in order.

Note on naming: You may see this credential referenced elsewhere as CITP-A rather than CCITP-A, reflecting an updated name used by CDSE. This guide uses the CCITP-A designation consistently throughout, and every fact here applies specifically to the Insider Threat Program analysis credential jointly conferred under the Under Secretary of Defense for Intelligence and Security and the Director of the National Counterintelligence and Security Center.

Here's how the six content domains break down, based on the most recently verified official weighting material:

DomainPublished Weight
1. Policy and directives20%
2. Social and behavior science10%
3. Researching20%
4. Synthesis35% combined
5. Tools and methods
6. Vulnerabilities assessment and management15%

Domains 4 and 5 are published jointly rather than as individual percentages, but together they represent more of the exam than any other content area - which should shape how you allocate study time. We'll address each domain below, and if you want a condensed, printable version of this breakdown once you've read it, bookmark the CCITP-A Cheat Sheet.

Domain 1: Policy and Directives (20%)

This domain tests your command of the governing framework that authorizes and constrains Insider Threat Program analysis work. Because CCITP-A sits at the intersection of counterintelligence and security policy, expect questions that probe whether you understand not just what a directive says, but when and how an analyst is authorized to act on information.

Policy and Directives

Candidates must understand the authorities and oversight structures that govern Insider Threat Program operations, including the distinction between program authorization and individual analyst authority.

  • Scope of authority for ITP personnel versus analysts
  • Oversight and reporting chains tied to program governance
  • How policy constraints intersect with UAM (User Activity Monitoring) authorizations

Because this is a scenario-based exam rather than a straight recall test, Policy and Directives questions are frequently framed as "what should the analyst do next" rather than "define this term." That framing matters for how you study - memorizing definitions alone won't get you through this domain.

Domain 2: Social and Behavior Science (10%)

At 10%, this is the lightest domain by published weight, but don't mistake "smallest" for "skippable." Social and behavior science underpins how an analyst interprets indicators in context - distinguishing a legitimate behavioral change from one that warrants further review.

Social and Behavior Science

This domain focuses on applying behavioral science concepts to insider threat indicator analysis, not on abstract psychology theory.

  • Interpreting behavioral indicators within a case context
  • Avoiding bias when weighing ambiguous behavioral data
  • Connecting behavioral observations to documented program case studies

Because eligibility requires review of 10 case studies as part of the prerequisite track, expect this domain to lean on applied judgment drawn from real program scenarios rather than textbook psychology.

Domain 3: Researching (20%)

Researching ties for the second-largest individually published weight at 20%, alongside Policy and Directives. This domain assesses how an analyst gathers, verifies, and documents information relevant to a potential insider threat case - a core function distinct from the foundational-level CITP-F credential.

Researching

Expect scenario prompts that require you to identify appropriate research methods, sources, and documentation standards for an active case.

  • Selecting appropriate data sources for a given case scenario
  • Verifying and cross-referencing information before escalation
  • Documentation standards expected of an Insider Threat Program analyst

Key Takeaway

Because Researching and Policy and Directives are tied at 20% each, treat them as equal-priority study blocks rather than assuming one outweighs the other.

Domains 4 & 5: Synthesis and Tools and Methods (35% Combined)

Here's the most important structural fact about the current CCITP-A blueprint: Domains 4 (Synthesis) and 5 (Tools and methods) are published together, and jointly they account for 35% of exam content - the largest content grouping on the test. No verified individual split between the two exists in current official material, so don't build a study plan around guessed sub-percentages; instead, treat this combined block as your single highest-priority study area.

Domain 4: Synthesis

Synthesis measures whether a candidate can take disparate pieces of research, behavioral observation, and policy context and combine them into a coherent analytic judgment.

  • Combining multiple data streams into a single analytic conclusion
  • Weighing conflicting or incomplete information
  • Producing analytic output that supports program decision-making

Domain 5: Tools and Methods

This domain covers the practical application of analytic and monitoring tools used within an Insider Threat Program, including how UAM tools fit into the broader analytic workflow.

  • Appropriate use of UAM tools within policy boundaries
  • Analytic methods for structuring a case investigation
  • Tool selection based on scenario constraints

The 8-hour UAM policy/tool training prerequisite exists specifically because this content area is tested - if your training hours felt thin on tool-specific application, that's the gap to close first. Our CCITP-A Study Guide goes deeper into sequencing practice questions around this combined domain block.

Domain 6: Vulnerabilities Assessment and Management (15%)

At 15%, this domain closes the loop between identifying a potential insider threat indicator and managing the organizational vulnerability it represents. It's distinct from Researching in that it's forward-looking - focused on mitigation and ongoing management rather than initial data gathering.

Vulnerabilities Assessment and Management

Candidates must demonstrate the ability to assess organizational and individual vulnerabilities and recommend or support management actions.

  • Distinguishing vulnerability assessment from threat assessment
  • Recommending risk mitigation actions within program authority
  • Tracking vulnerability status over the lifecycle of a case

Mapping the Domains to a Study Timeline

Generic study techniques only matter here if they're anchored to CCITP-A's actual weighting. Given that Domains 4 and 5 jointly represent 35% of the exam, and Domains 1 and 3 each represent 20%, a reasonable four-week structure front-loads the heaviest-weighted material first and reserves the final week for the two lighter domains plus full-length review.

Week 1

Synthesis and Tools and Methods

  • Review UAM tool application scenarios
  • Practice multi-source synthesis questions
Week 2

Policy and Directives + Researching

  • Map authority boundaries against scenario prompts
  • Drill source verification and documentation standards
Week 3

Vulnerabilities Assessment and Management + Social and Behavior Science

  • Practice vulnerability-to-mitigation reasoning chains
  • Review case-study-based behavioral indicator questions
Week 4

Full Review

  • Timed practice under the 135-minute, 86-question format
  • Revisit weak domains identified in prior weeks

For candidates wondering whether the overall exam difficulty warrants this much structure, our CCITP-A difficulty guide breaks down what makes the scaled-score format and scenario-based question style challenging compared to simple recall exams.

Who Actually Tests You On These Domains

CCITP-A isn't issued by a commercial training vendor - it's jointly conferred through the Under Secretary of Defense for Intelligence and Security and the Director of the National Counterintelligence and Security Center, with day-to-day administration handled by DCSA, CDSE, and the SPeD Program Management Office. That governance structure is why the domains lean so heavily on policy, authority, and documented program procedure rather than generic analytic theory you'd find in a commercial data-analysis certification.

As of the most recent published tracker, 223 active CCITP-A credentials were recorded in DAU - a relatively small, specialized population compared to broader IT or security certifications. If you're trying to gauge demand or career impact before committing to the eligibility process, the CCITP-A Jobs page and the CCITP-A ROI analysis both dig into what this credential signals to a hiring program manager within a federal or cleared-contractor Insider Threat Program.

Cost context: Unlike many professional certifications, the published handbook lists no assessment fee for eligible candidates. For the full picture of what "cost" actually means for CCITP-A - training hours, time investment, maintenance PDUs - see the CCITP-A Certification Cost breakdown.

Once certified, maintaining the credential currently requires 100 PDUs per two-year cycle, with at least 50 of those tied specifically to Insider Threat-related content and recorded in DAU. Older program material referenced a three-year cycle, so confirm your individual expiration date and any transition treatment directly with your SPeD Program Management Office point of contact rather than assuming either cycle length applies automatically.

If you haven't started studying yet and want a broader orientation before diving into domain-level prep, our practice test platform is built around these same six domains and the 86-question, 135-minute format described in the current handbook. You can also start with What Is CCITP-A? or CCITP-A Meaning for foundational orientation before working through domain-specific practice sets on the main practice site.

Frequently Asked Questions

How many questions are on the CCITP-A exam, and how is it timed?

The exam contains 86 total questions - 80 scored and 6 unscored - delivered in a 135-minute window at a Pearson VUE test center, using a scenario-based multiple-choice format.

Which CCITP-A domain carries the most weight?

Domains 4 (Synthesis) and 5 (Tools and methods) are published together and jointly account for 35% of exam content, the largest group of any domain. Individually, Policy and directives and Researching are each verified at 20%.

What score do I need to pass CCITP-A?

The handbook specifies a scaled passing threshold of 650 out of 800 rather than a flat correct-answer percentage. See the passing score guide for a full explanation of how scaled scoring works.

Is there a fee to take the CCITP-A exam?

The published official handbook lists no assessment fee for eligible candidates, since the credential is administered through DCSA/CDSE's SPeD Program Management Office rather than a membership-based certifying body.

What are the prerequisites before I can schedule the exam?

Candidates need current CITP-F status, current Insider Threat Program personnel standing, at least 12 months of program experience, 40 hours of analysis-related training, 8 hours of UAM policy/tool training, review of 10 case studies, and a signed eligibility memorandum from a program manager. Full detail is in the requirements guide.

Ready to pass your CCITP-A exam?

Put this into practice with free CCITP-A questions across every exam domain.