- What CCITP-A Actually Tests
- Exam Format: Questions, Timing, and Delivery
- The Six CCITP-A Domains, Weighted
- Eligibility, Fees, and Scheduling Mechanics
- Understanding the 650/800 Passing Threshold
- A Domain-Weighted Study Timeline
- Who Hires CCITP-A Credential Holders
- Maintaining the Credential After You Pass
- Frequently Asked Questions
- The exam has 86 questions (80 scored, 6 unscored) and a 135-minute time limit, delivered via Pearson VUE.
- Passing requires a scaled 650/800 score, not a fixed percent-correct cutoff.
- Domains 4 and 5 (Synthesis; Tools and methods) jointly carry 35% of the blueprint - the single largest weighting block.
- There is no assessment fee for eligible candidates - the official handbook lists $0.
What CCITP-A Actually Tests
CCITP-A - Certified Counter-Insider Threat Professional - Analysis - is a credential for analysts working inside Insider Threat Programs, conferred jointly under the authority of the Under Secretary of Defense for Intelligence and Security and the Director of the National Counterintelligence and Security Center, with administration handled by DCSA/CDSE's SPeD Program Management Office. If you've seen references to a renamed version of this credential (CDSE materials currently use "Certified Insider Threat Professional - Analysis," or CITP-A), know that the renaming date isn't fully verified in official sources - but the exam content, authorities, and mechanics described here apply specifically to the analysis-track credential, not to any other certification that happens to share the "CCITP-A" acronym.
If you're still orienting yourself to what this certification covers before diving into study logistics, our companion piece on What Is CCITP-A? and the deeper CCITP-A Certification overview are good starting points. This guide assumes you already know you want it and need a concrete path to a passing score.
Exam Format: Questions, Timing, and Delivery
According to the CDSE tracker dated July 1, 2026, the CCITP-A exam consists of 86 total questions - 80 scored and 6 unscored. The unscored items are typically used for item-bank calibration and are indistinguishable from scored questions during the test, so you should treat every question as if it counts.
The indexed official handbook specifies a 135-minute time limit and describes the question style as scenario-based multiple choice. This matters for prep strategy: you are not memorizing isolated definitions for recall-style questions. Instead, expect short case vignettes - a reporting anomaly, a policy conflict, an analytic tasking - followed by a question asking you to select the best next action, the correct tool, or the applicable directive.
The exam is delivered through Pearson VUE test centers. Before you can schedule a seat, your DAU eligibility must already be approved - scheduling comes after approval, not before. Details on open-book status, calculator use, home proctoring, and adaptivity in the current exam version are not verified in official sources as of this writing, so don't plan your prep around assumptions in any of those areas; confirm directly with your eligibility notification.
Key Takeaway
Practice with scenario-based questions, not flashcard-style recall drills. The CCITP-A exam rewards candidates who can apply policy and analytic method to a described situation, not just name a term.
The Six CCITP-A Domains, Weighted
The current six-topic weighting is verified from official 2024 AIRE material - no newly obtained 2026 blueprint has been confirmed, so treat these weights as the best available guide rather than a guaranteed final spec. For a full breakdown of what each domain actually covers, see our dedicated CCITP-A Exam Domains 2026: Complete Guide to All 6 Content Areas.
Domain 1: Policy and Directives (20%)
Covers the regulatory and directive framework governing Insider Threat Programs - the authorities, policy documents, and compliance obligations analysts must apply when assessing reported behavior.
- Know which directive governs which program function before you sit the exam
Domain 2: Social and Behavior Science (10%)
Tests understanding of behavioral indicators and the psychological/social frameworks analysts use to interpret reported conduct - the smallest weighted domain but still scenario-tested.
- Don't skip it just because it's the lightest weight; scenario questions still draw from it
Domain 3: Researching (20%)
Focuses on the research methods analysts use to gather, validate, and corroborate information relevant to a potential insider threat case.
- Expect questions on source validation and research sequencing
Domains 4 & 5: Synthesis and Tools and Methods (35% combined)
This is the largest published weighting block on the exam. Synthesis tests your ability to combine findings from multiple sources into a coherent analytic judgment; Tools and methods tests familiarity with the analytic and User Activity Monitoring (UAM) tools used in program operations.
- Prioritize this block above all others in your study sequence
- Review the 8-hour UAM policy/tool training content closely - it connects directly here
Domain 6: Vulnerabilities Assessment and Management (15%)
Covers identifying and managing organizational and individual vulnerabilities that elevate insider threat risk.
- Pair this domain's content with the case-study review required for eligibility
Do not treat any single-domain percentage inside the Domain 4/5 pairing as independently published - only the combined 35% figure is confirmed. If you want a condensed reference you can review the night before test day, bookmark the CCITP-A Cheat Sheet 2026: One-Page Review of Must-Know Facts.
Eligibility, Fees, and Scheduling Mechanics
Unlike many certifications where you simply pay and register, CCITP-A eligibility is a documented, approval-gated process. Per official prerequisites, you need:
- Current CITP-F status
- Current status as Insider Threat Program personnel
- At least 12 months of program experience
- 40 hours of analysis-related training
- 8 hours of UAM policy/tool training
- Review of 10 case studies
- Program-manager approval with a signed eligibility memorandum
No separate degree requirement or reference count is verified beyond this list, so don't assume additional academic prerequisites exist unless your program manager tells you otherwise. For the full breakdown of how these requirements fit together, read CCITP-A Requirements 2026: Eligibility, Prerequisites & How to Qualify.
Once your DAU eligibility is approved, scheduling happens through Pearson VUE. Current retake intervals are not verified in official sources, so plan your first attempt as though you want it to count - eligibility approval and memorandum sign-off take real lead time, and you don't want to burn a scheduling slot on a rushed first pass. For a sense of how exam windows and deadlines typically run, see CCITP-A Exam Dates 2026: Testing Windows, Deadlines & Scheduling.
Understanding the 650/800 Passing Threshold
This is one of the most commonly misunderstood facts about this exam. The indexed official handbook specifies a scaled passing score of 650 out of 800 - this is not the same as requiring 81.25% of raw questions correct. Scaled scoring typically weights items differently based on difficulty and domain calibration, meaning a candidate's raw correct-answer count does not map linearly to the final score. A newly linked combined handbook describing the exact scaling formula was inaccessible at time of writing, so don't trust any source claiming to show you a precise raw-to-scaled conversion table.
What this means practically: don't obsess over hitting a specific percentage on practice questions. Instead, focus on consistent performance across all six domains, since scenario-based scaled exams tend to penalize weak performance in any single heavily-weighted area more than an occasional miss on an easy item. For a deeper breakdown of how the scaled score works and what study benchmarks make sense, read CCITP-A Passing Score 2026: Exactly What You Need to Pass.
Key Takeaway
Train for consistent domain coverage, not a raw percentage target - the 650/800 scale doesn't reward raw-score math the way a flat percentage cutoff would.
A Domain-Weighted Study Timeline
Generic study techniques only help if they're sequenced around what the exam actually weighs. Since Domains 4 and 5 jointly carry 35% - the largest block - your preparation should front-load time there rather than splitting hours evenly across all six domains.
Policy and Directives + Researching
- Build a reference map of governing directives tied to program functions (Domain 1)
- Practice source-validation scenarios tied to Domain 3
Synthesis and Tools/Methods - the 35% block
- Work through multi-source scenario questions that require combining findings into a judgment
- Review UAM tool functions against your 8-hour UAM training material
Vulnerabilities and Behavior Science
- Revisit your 10 required case studies with Domain 6 vulnerability categories in mind
- Pair behavioral indicator review (Domain 2) with real program scenarios, not isolated terms
Full Scenario Review and Timing Practice
- Run full 135-minute timed scenario sets across all six domains
- Confirm your DAU eligibility status and Pearson VUE scheduling window is finalized
If this sequence still feels abstract, our broader CCITP-A Study Guide 2026: How to Pass on Your First Attempt walks through the same logic with additional scenario drill examples, and practicing with realistic scenario-style questions on our main practice test platform can help you get comfortable with the 135-minute pace before test day.
Who Hires CCITP-A Credential Holders
CCITP-A sits specifically within the counter-insider threat analytic track, meaning the roles it supports are tied to Insider Threat Program functions rather than general cybersecurity or law-enforcement credentials that happen to share a similar name. Holders typically work as insider threat analysts within program offices that require UAM tool proficiency, case research, and vulnerability assessment skills - the exact skill set reflected in the six domains above.
As of the July 2026 tracker, there were 223 active CITP-A credentials recorded in DAU - a small, specialized population rather than a mass-market certification count. This is not a keyword-search volume figure; it reflects actual active credential holders in the system of record, which gives you a sense of how niche and program-specific this credential is compared to broad IT certifications. If you're weighing whether the time investment makes sense for your career track, our analysis in Is the CCITP-A Certification Worth It? Complete ROI Analysis 2026 and CCITP-A Salary Guide 2026: Complete Earnings Analysis dig into that question further, and CCITP-A Jobs covers the kinds of roles that list it as a requirement or preference.
| Fact | Detail |
|---|---|
| Scored questions | 80 (out of 86 total) |
| Time limit | 135 minutes |
| Question style | Scenario-based multiple choice |
| Passing score | Scaled 650/800 |
| Assessment fee | $0 for eligible candidates |
| Delivery | Pearson VUE test centers |
| Largest domain weight | Domains 4 & 5 combined, 35% |
| Active credentials (DAU, July 2026) | 223 |
Maintaining the Credential After You Pass
Passing is not the end of the obligation. The current maintenance-page indexed text specifies 100 PDUs per two-year cycle, with at least 50 tied to Insider Threat-related content, recorded in DAU. Older official material referenced a three-year cycle instead, so if you're uncertain which cycle applies to your specific credential issuance, confirm your individual expiry date and transition treatment directly rather than assuming the newer two-year rule automatically applies retroactively.
Build PDU tracking into your calendar the same week you receive your passing result - waiting until renewal is near is the most common way credential holders lapse unintentionally.
For readers still mapping out terminology - whether you're searching for CCITP-A Meaning, What Does CCITP-A Stand For?, or What Is A CCITP-A? - those explainer pieces, along with What Does CCITP-A Mean? and What Is CCITP-A Certification?, cover the foundational definitions this study guide builds on. If you want structured coursework rather than self-study, CCITP-A Training outlines available options, and checking your readiness against realistic timed questions on our practice test site before scheduling is one of the simplest ways to catch weak domains early.
Frequently Asked Questions
The exam has 86 total questions - 80 scored and 6 unscored - with a 135-minute time limit, per the CDSE tracker and the indexed official handbook.
A scaled score of 650 out of 800, according to the indexed official handbook. This is not equivalent to a flat 81.25% raw-correct requirement, since scaled scoring weights items differently.
No. The published indexed official handbook lists no assessment fee - $0 for eligible candidates. There's no member versus non-member fee distinction to worry about.
Domains 4 and 5 - Synthesis and Tools and methods - jointly carry 35% of the exam, the largest published weighting group, so they deserve the most prep time relative to the other four domains.
You need current CITP-F status, current Insider Threat Program personnel status, at least 12 months of program experience, 40 hours of analysis-related training, 8 hours of UAM training, review of 10 case studies, and a signed program-manager eligibility memorandum before DAU approval and Pearson VUE scheduling.