C)SA1 logo
Focused certification exam prep
Start practice

C)SA1 Exam Domains 2026: Complete Guide to All 8 Content Areas

TL;DR
  • C)SA1 is Certified Security Awareness 1 from Mile2, aimed at end users, employees and managers, with no suggested prerequisites.
  • The eight domains map to the public course outline: an introduction plus seven numbered modules, 00 through 06.
  • These are unweighted preparation topics; no public percentage-weighted blueprint has been verified.
  • Question count, format, timer and passing threshold are unverified, so confirm them in your Mile2 account.

How to Read These Eight Domains

Certified Security Awareness 1 (C)SA1) is a Mile2 Cybersecurity Institute certification built for people who are not security professionals: end users, employees and managers. Mile2's public three-page course outline lists the topics a candidate prepares on. This guide walks through each one so you know what to study and why it matters in an ordinary workplace.

An important caveat about the word "domain": The eight headings below come from Mile2's public outline: the issuer introduction plus seven numbered modules (00 to 06). They are preparation topics, not eight officially weighted exam domains. No public percentage breakdown has been verified, so this article does not rank any domain as "most heavily tested." Treat all eight as in scope and give extra time to the ones that are new to you.

If you are still orienting yourself, the explainer on what C)SA1 certification is covers the basics, and the C)SA1 study guide turns the topics into a plan. For hands-on question practice, the main practice test site is the place to drill.

Domain 1: Who Is Mile2?

The first domain is the introduction to the issuer. It is the lightest topic conceptually, but do not skip it. Questions on a certification exam sometimes touch on the organization behind the credential and what the program covers.

INTRODUCTION: Who is Mile2?

Understand who issues the credential and how the C)SA1 course fits into Mile2's catalog.

  • Know that Mile2 Cybersecurity Institute is the issuer of Certified Security Awareness 1.
  • Recognize the intended audience: end users, employees and managers rather than technical staff.
  • Be able to distinguish completing the course from earning the Mile2 certification, since they are separate things.

The last point trips people up. Attending the live class, which Mile2 publishes as a two-hour English-language session carrying four CEUs, is training. It is not the certification exam, and the class length is not the exam timer. Keep those two ideas apart in your notes.

Domain 2: 2025 Cyberthreat Trends

This module is titled "2025 Cyberthreat Trends" in the public outline. The year in the heading does not tell you which exam version you will sit, and publishing a 2026 article does not imply a new version either. Read the heading as the name of a topic area: the current threat landscape an ordinary employee faces.

2025 Cyberthreat Trends

Build a working picture of how attackers target organizations through everyday users.

  • Learn the common threat categories: phishing, malware, ransomware, credential theft and social engineering.
  • Understand why attackers go after people and routine workflows rather than only technical weaknesses.
  • Be ready to match a described scenario to the threat type it represents.

Because the outline does not publish a statistics list, do not memorize invented figures from other sources. Focus on categories, attacker motives and recognizable patterns. A scenario-style question rewards understanding of how an attack unfolds far more than recall of a number.

Domain 3: The Human Factor

"The Human Factor" is the conceptual heart of an awareness certification. The premise is that technology controls only go so far, and everyday decisions made by employees and managers often determine whether an attack succeeds.

The Human Factor

Explain why people are both the most common point of failure and the most valuable line of defense.

  • Understand how habits, urgency, trust and distraction get exploited.
  • Recognize the difference between a mistake and a risky shortcut taken to save time.
  • Know that managers carry added responsibility for modeling and enforcing secure behavior.

Expect this topic to underpin the others. When you reach phishing, passwords and data handling, you will see the same idea repeated: the safest choice is usually the slower, more deliberate one. If you want a sense of how approachable that makes the exam, the C)SA1 difficulty guide discusses what makes it easier or harder for different backgrounds.

Domain 4: Phishing & Social Engineering

This is the domain most candidates expect to see, and it is the one where concrete recognition skills matter. Social engineering covers any attempt to manipulate a person into giving up access or information, and phishing is its best-known form.

Phishing & Social Engineering

Spot manipulation attempts across email, phone, text and in person.

  • Identify red flags in suspicious messages: mismatched senders, urgent demands, unexpected attachments and disguised links.
  • Distinguish the delivery channels by name, including email-based phishing, voice-based attempts and text-based attempts.
  • Understand pretexting, impersonation and the emotional levers attackers pull, such as fear, authority and curiosity.
  • Know the safe response: do not click or reply, verify through a trusted channel, and report it.

When you practice, train yourself to read a scenario and name both the technique and the correct employee action. The right answer is rarely "ignore it silently"; awareness programs consistently stress reporting. Original practice questions on the practice test site are a good way to rehearse that reflex.

Domain 5: Credentials, Passwords, and Access Security

This domain moves from recognizing attacks to protecting the keys attackers want. It covers how employees create, store and use credentials, and how access is controlled.

Credentials, Passwords, and Access Security

Apply sound habits for authentication and access.

  • Understand what makes a password strong versus weak, and why reuse across accounts is dangerous.
  • Learn the purpose of multi-factor authentication and why it limits the damage of a stolen password.
  • Know the role of password managers as a practical tool for unique credentials.
  • Grasp least-privilege thinking: people should have only the access their role requires.

A common exam pattern here is to present two or three plausible-sounding practices and ask which one best reduces risk. Favor answers that add a layer (such as MFA) or remove a weakness (such as reuse) over answers that rely on a person remembering to be careful.

Domain 6: Data Protection & Handling Sensitive Information

Here the focus shifts to what employees do with information once they have it. Sensitive data can leak through carelessness just as easily as through attack.

Data Protection & Handling Sensitive Information

Handle information according to how sensitive it is.

  • Recognize categories of sensitive information, such as personal, financial and confidential business data.
  • Understand the idea of classifying data and handling it according to its classification.
  • Know safe practices for storing, sharing, transporting and disposing of information, including physical documents and removable media.
  • Appreciate why clean-desk habits and screen privacy matter in shared or public spaces.

The conceptual thread is that protection should match sensitivity. If a question asks what to do with a particular kind of information, the strongest answer usually follows the organization's policy for that classification rather than a convenient shortcut.

Domain 7: Communication Security & Collaboration Tools

Modern work happens in email, chat, video meetings and shared documents. This domain covers how to use those tools without exposing the organization.

Communication Security & Collaboration Tools

Use everyday communication and collaboration platforms safely.

  • Understand the risks of sending sensitive material over the wrong channel or to the wrong recipient.
  • Know good practice for shared files and links, including who can view or edit them.
  • Be cautious with unapproved tools and personal accounts used for work, often called shadow IT.
  • Recognize risks on public or unsecured networks and the value of using approved secure connections.

Think of this as the practical application of the data-handling domain to specific tools. The same logic applies: choose the approved channel, limit access to those who need it, and double-check recipients before sending.

Domain 8: Incident Response, Security Culture, and Wrap-Up

The final domain covers what happens when something goes wrong and how an organization builds lasting good habits. For end users, incident response is mostly about speed and honesty.

Incident Response, Security Culture, and Wrap-Up

Know what to do after a suspected incident and how to support a security-minded workplace.

  • Understand that prompt reporting of a suspected incident matters more than trying to fix it alone.
  • Know that a blame-free reporting culture encourages people to speak up early.
  • Recognize the part managers play in reinforcing policy and supporting staff who report concerns.
  • Review how the earlier topics connect, since the wrap-up ties them into a single awareness mindset.

Key Takeaway

When a scenario describes a possible incident, the safest answer almost always involves stopping, not hiding or self-repairing, and reporting through the proper channel immediately.

Exam Logistics and What Is Still Unverified

Honest preparation means knowing what has and has not been confirmed. The public course outline names Mile2 Certified Network Principles in its exam-information paragraph, so its passing-score statement is not treated as C)SA1 policy. Mile2's Policies and Procedures document (dated 5-26-2026) expressly excludes C)SA1 and C)SA2 from its general 100-multiple-choice-item rule.

ItemStatus
Question countNot verified; confirm in your Mile2 account
Item formatNot verified; do not assume multiple choice
Exam timerNot verified
Passing thresholdNot verified for C)SA1
DeliveryOnline through the Mile2 account and learning management system
AttemptsTwo per Exam Combo, per the FAQ and exam combos page
ValidityThree years

Mile2's materials also conflict on supervision. The FAQ describes most standard exams as on-demand without a live-proctor appointment, while policy page 18 describes proctored, open-book assessment with advance scheduling. Confirm which applies to your assigned C)SA1 attempt and what resources you may use. See the passing score article and the exam dates and scheduling guide for how to approach those open questions.

Cost and bundle note: The C)SA1 Exam Combo publicly lists the exam, a simulator and a prep guide. Earlier reviews recorded an advertised bundle price, but no price appeared in the product text retrieved for this article, so treat any figure as unverified and check current checkout pricing. The certification cost breakdown explains what to look for. There are no suggested prerequisites, and Mile2 training is not mandatory; the requirements guide goes deeper.

Renewal in brief

Certification is valid for three years. The standard route described on Mile2's renewal pages involves 60 documented CEUs over three years, a renewal purchase and an ethics and policy acknowledgment, and a dedicated paths page also offers passing the latest existing-credential exam as an alternative. The course PDF and a policy page describe annual CEUs differently, so confirm your applicable route and deadline instead of assuming every statement applies at once.

Sequencing the Domains Over Your Prep Window

Because the domains build on one another, order matters more than volume. This sample plan assumes a short, focused window and front-loads the conceptual foundation so the practical domains make sense.

Week 1

Foundations: Domains 1 to 3

  • Read the introduction and the 2025 Cyberthreat Trends material.
  • Spend the most time on The Human Factor, since the later domains rest on it.
Week 2

Recognition and Protection: Domains 4 and 5

  • Practice classifying phishing and social engineering scenarios by technique and correct response.
  • Review credentials, MFA and least privilege with scenario questions.
Week 3

Applied Handling: Domains 6 to 8

  • Work through data classification, communication tools and incident reporting.
  • Finish with mixed practice across all eight topics and revisit your weakest area.

A one-page recap is useful in the last days; the C)SA1 cheat sheet is designed for that. Whatever you use, make sure your practice questions are original and scenario-based rather than memorized answer keys.

Frequently Asked Questions

Are the eight domains officially weighted on the exam?

No weighting has been verified. The eight headings come from Mile2's public course outline (an introduction plus modules 00 to 06) and are best treated as unweighted preparation topics. Study all of them rather than guessing which carries more points.

Does the "2025" in Cyberthreat Trends mean there is a 2025 exam version?

No. The year appears in a module heading and does not designate an exam version. Likewise, the year in this article's title does not establish a new exam version.

Do I need technical experience to study these domains?

No prerequisites are suggested. The course is intended for end users, employees and managers, and Mile2 training is not mandatory. The topics are framed around everyday workplace behavior rather than technical administration.

Is finishing the two-hour live class the same as being certified?

No. The live class is training and carries four CEUs, while the certification is the separate Mile2 credential earned through the exam. The class length is also not the exam timer.

How many questions are on the exam and what score do I need?

The question count, item format, timer and passing threshold are unverified for C)SA1, and Mile2's general 100-item rule expressly excludes it. Confirm the details in your Mile2 account before test day, and see the pass rate article for why no candidate pass rate is cited here.

Ready to pass your C)SA1 exam?

Put this into practice with free C)SA1 questions across every exam domain.