- How to Read These Eight Domains
- Domain 1: Who Is Mile2?
- Domain 2: 2025 Cyberthreat Trends
- Domain 3: The Human Factor
- Domain 4: Phishing & Social Engineering
- Domain 5: Credentials, Passwords, and Access Security
- Domain 6: Data Protection & Sensitive Information
- Domain 7: Communication Security & Collaboration Tools
- Domain 8: Incident Response, Security Culture, and Wrap-Up
- Exam Logistics and What Is Still Unverified
- Sequencing the Domains Over Your Prep Window
- Frequently Asked Questions
- C)SA1 is Certified Security Awareness 1 from Mile2, aimed at end users, employees and managers, with no suggested prerequisites.
- The eight domains map to the public course outline: an introduction plus seven numbered modules, 00 through 06.
- These are unweighted preparation topics; no public percentage-weighted blueprint has been verified.
- Question count, format, timer and passing threshold are unverified, so confirm them in your Mile2 account.
How to Read These Eight Domains
Certified Security Awareness 1 (C)SA1) is a Mile2 Cybersecurity Institute certification built for people who are not security professionals: end users, employees and managers. Mile2's public three-page course outline lists the topics a candidate prepares on. This guide walks through each one so you know what to study and why it matters in an ordinary workplace.
If you are still orienting yourself, the explainer on what C)SA1 certification is covers the basics, and the C)SA1 study guide turns the topics into a plan. For hands-on question practice, the main practice test site is the place to drill.
Domain 1: Who Is Mile2?
The first domain is the introduction to the issuer. It is the lightest topic conceptually, but do not skip it. Questions on a certification exam sometimes touch on the organization behind the credential and what the program covers.
INTRODUCTION: Who is Mile2?
Understand who issues the credential and how the C)SA1 course fits into Mile2's catalog.
- Know that Mile2 Cybersecurity Institute is the issuer of Certified Security Awareness 1.
- Recognize the intended audience: end users, employees and managers rather than technical staff.
- Be able to distinguish completing the course from earning the Mile2 certification, since they are separate things.
The last point trips people up. Attending the live class, which Mile2 publishes as a two-hour English-language session carrying four CEUs, is training. It is not the certification exam, and the class length is not the exam timer. Keep those two ideas apart in your notes.
Domain 2: 2025 Cyberthreat Trends
This module is titled "2025 Cyberthreat Trends" in the public outline. The year in the heading does not tell you which exam version you will sit, and publishing a 2026 article does not imply a new version either. Read the heading as the name of a topic area: the current threat landscape an ordinary employee faces.
2025 Cyberthreat Trends
Build a working picture of how attackers target organizations through everyday users.
- Learn the common threat categories: phishing, malware, ransomware, credential theft and social engineering.
- Understand why attackers go after people and routine workflows rather than only technical weaknesses.
- Be ready to match a described scenario to the threat type it represents.
Because the outline does not publish a statistics list, do not memorize invented figures from other sources. Focus on categories, attacker motives and recognizable patterns. A scenario-style question rewards understanding of how an attack unfolds far more than recall of a number.
Domain 3: The Human Factor
"The Human Factor" is the conceptual heart of an awareness certification. The premise is that technology controls only go so far, and everyday decisions made by employees and managers often determine whether an attack succeeds.
The Human Factor
Explain why people are both the most common point of failure and the most valuable line of defense.
- Understand how habits, urgency, trust and distraction get exploited.
- Recognize the difference between a mistake and a risky shortcut taken to save time.
- Know that managers carry added responsibility for modeling and enforcing secure behavior.
Expect this topic to underpin the others. When you reach phishing, passwords and data handling, you will see the same idea repeated: the safest choice is usually the slower, more deliberate one. If you want a sense of how approachable that makes the exam, the C)SA1 difficulty guide discusses what makes it easier or harder for different backgrounds.
Domain 4: Phishing & Social Engineering
This is the domain most candidates expect to see, and it is the one where concrete recognition skills matter. Social engineering covers any attempt to manipulate a person into giving up access or information, and phishing is its best-known form.
Phishing & Social Engineering
Spot manipulation attempts across email, phone, text and in person.
- Identify red flags in suspicious messages: mismatched senders, urgent demands, unexpected attachments and disguised links.
- Distinguish the delivery channels by name, including email-based phishing, voice-based attempts and text-based attempts.
- Understand pretexting, impersonation and the emotional levers attackers pull, such as fear, authority and curiosity.
- Know the safe response: do not click or reply, verify through a trusted channel, and report it.
When you practice, train yourself to read a scenario and name both the technique and the correct employee action. The right answer is rarely "ignore it silently"; awareness programs consistently stress reporting. Original practice questions on the practice test site are a good way to rehearse that reflex.
Domain 5: Credentials, Passwords, and Access Security
This domain moves from recognizing attacks to protecting the keys attackers want. It covers how employees create, store and use credentials, and how access is controlled.
Credentials, Passwords, and Access Security
Apply sound habits for authentication and access.
- Understand what makes a password strong versus weak, and why reuse across accounts is dangerous.
- Learn the purpose of multi-factor authentication and why it limits the damage of a stolen password.
- Know the role of password managers as a practical tool for unique credentials.
- Grasp least-privilege thinking: people should have only the access their role requires.
A common exam pattern here is to present two or three plausible-sounding practices and ask which one best reduces risk. Favor answers that add a layer (such as MFA) or remove a weakness (such as reuse) over answers that rely on a person remembering to be careful.
Domain 6: Data Protection & Handling Sensitive Information
Here the focus shifts to what employees do with information once they have it. Sensitive data can leak through carelessness just as easily as through attack.
Data Protection & Handling Sensitive Information
Handle information according to how sensitive it is.
- Recognize categories of sensitive information, such as personal, financial and confidential business data.
- Understand the idea of classifying data and handling it according to its classification.
- Know safe practices for storing, sharing, transporting and disposing of information, including physical documents and removable media.
- Appreciate why clean-desk habits and screen privacy matter in shared or public spaces.
The conceptual thread is that protection should match sensitivity. If a question asks what to do with a particular kind of information, the strongest answer usually follows the organization's policy for that classification rather than a convenient shortcut.
Domain 7: Communication Security & Collaboration Tools
Modern work happens in email, chat, video meetings and shared documents. This domain covers how to use those tools without exposing the organization.
Communication Security & Collaboration Tools
Use everyday communication and collaboration platforms safely.
- Understand the risks of sending sensitive material over the wrong channel or to the wrong recipient.
- Know good practice for shared files and links, including who can view or edit them.
- Be cautious with unapproved tools and personal accounts used for work, often called shadow IT.
- Recognize risks on public or unsecured networks and the value of using approved secure connections.
Think of this as the practical application of the data-handling domain to specific tools. The same logic applies: choose the approved channel, limit access to those who need it, and double-check recipients before sending.
Domain 8: Incident Response, Security Culture, and Wrap-Up
The final domain covers what happens when something goes wrong and how an organization builds lasting good habits. For end users, incident response is mostly about speed and honesty.
Incident Response, Security Culture, and Wrap-Up
Know what to do after a suspected incident and how to support a security-minded workplace.
- Understand that prompt reporting of a suspected incident matters more than trying to fix it alone.
- Know that a blame-free reporting culture encourages people to speak up early.
- Recognize the part managers play in reinforcing policy and supporting staff who report concerns.
- Review how the earlier topics connect, since the wrap-up ties them into a single awareness mindset.
Key Takeaway
When a scenario describes a possible incident, the safest answer almost always involves stopping, not hiding or self-repairing, and reporting through the proper channel immediately.
Exam Logistics and What Is Still Unverified
Honest preparation means knowing what has and has not been confirmed. The public course outline names Mile2 Certified Network Principles in its exam-information paragraph, so its passing-score statement is not treated as C)SA1 policy. Mile2's Policies and Procedures document (dated 5-26-2026) expressly excludes C)SA1 and C)SA2 from its general 100-multiple-choice-item rule.
| Item | Status |
|---|---|
| Question count | Not verified; confirm in your Mile2 account |
| Item format | Not verified; do not assume multiple choice |
| Exam timer | Not verified |
| Passing threshold | Not verified for C)SA1 |
| Delivery | Online through the Mile2 account and learning management system |
| Attempts | Two per Exam Combo, per the FAQ and exam combos page |
| Validity | Three years |
Mile2's materials also conflict on supervision. The FAQ describes most standard exams as on-demand without a live-proctor appointment, while policy page 18 describes proctored, open-book assessment with advance scheduling. Confirm which applies to your assigned C)SA1 attempt and what resources you may use. See the passing score article and the exam dates and scheduling guide for how to approach those open questions.
Renewal in brief
Certification is valid for three years. The standard route described on Mile2's renewal pages involves 60 documented CEUs over three years, a renewal purchase and an ethics and policy acknowledgment, and a dedicated paths page also offers passing the latest existing-credential exam as an alternative. The course PDF and a policy page describe annual CEUs differently, so confirm your applicable route and deadline instead of assuming every statement applies at once.
Sequencing the Domains Over Your Prep Window
Because the domains build on one another, order matters more than volume. This sample plan assumes a short, focused window and front-loads the conceptual foundation so the practical domains make sense.
Foundations: Domains 1 to 3
- Read the introduction and the 2025 Cyberthreat Trends material.
- Spend the most time on The Human Factor, since the later domains rest on it.
Recognition and Protection: Domains 4 and 5
- Practice classifying phishing and social engineering scenarios by technique and correct response.
- Review credentials, MFA and least privilege with scenario questions.
Applied Handling: Domains 6 to 8
- Work through data classification, communication tools and incident reporting.
- Finish with mixed practice across all eight topics and revisit your weakest area.
A one-page recap is useful in the last days; the C)SA1 cheat sheet is designed for that. Whatever you use, make sure your practice questions are original and scenario-based rather than memorized answer keys.
Frequently Asked Questions
No weighting has been verified. The eight headings come from Mile2's public course outline (an introduction plus modules 00 to 06) and are best treated as unweighted preparation topics. Study all of them rather than guessing which carries more points.
No. The year appears in a module heading and does not designate an exam version. Likewise, the year in this article's title does not establish a new exam version.
No prerequisites are suggested. The course is intended for end users, employees and managers, and Mile2 training is not mandatory. The topics are framed around everyday workplace behavior rather than technical administration.
No. The live class is training and carries four CEUs, while the certification is the separate Mile2 credential earned through the exam. The class length is also not the exam timer.
The question count, item format, timer and passing threshold are unverified for C)SA1, and Mile2's general 100-item rule expressly excludes it. Confirm the details in your Mile2 account before test day, and see the pass rate article for why no candidate pass rate is cited here.