Skip to main content
Course

Certificate of Competence in Zero Trust (CCZT) Exam Prep

Zero trust architecture, strategy, and implementation planning.

Intermediate

Level

5

Modules

20

Lessons

5

Graded quizzes

7 hours

Estimated time

What you will be able to do

  • Explain zero trust principles and how they replace perimeter thinking
  • Describe the NIST SP 800-207 logical components and deployment models
  • Explain software defined perimeter and its role in zero trust
  • Plan a zero trust implementation across identity, device, and network
  • Govern and measure a zero trust programme over time
  • Pass a timed practice exam covering the CCZT body of knowledge

What is inside

5 modules, 20 lessons. Each module ends in a graded quiz.

  1. 01

    Zero Trust Foundations and Architecture

    Covers the CCZT foundational domain: why the perimeter model failed, the core tenets of never trust and always verify, and the logical architecture built from the Policy Engine, Policy Administrator, and Policy Enforcement Point. You will learn to define a protect surface, reason about the identity, device, network, application, and data pillars, and place enforcement where it actually changes the outcome. Every lesson ends with exam style checks that force you to separate Zero Trust strategy from Zero Trust products.

    4 lessons · 15 quiz questions

  2. 02

    Software Defined Perimeter and Reference Guidance

    Software Defined Perimeter is the pattern the CCZT exam uses to turn Zero Trust principles into a concrete access architecture, and this module walks the full workflow from Controller onboarding to dynamic tunnel teardown. You will learn how Single Packet Authorization, mutual TLS, and default drop enforcement combine to hide infrastructure from unauthorized parties, and how each SDP deployment model answers a specific access problem. The module closes by mapping SDP components onto NIST SP 800-207 logical components and deployment variations and onto the CISA Zero Trust Maturity Model so cross reference questions become straightforward.

    4 lessons · 15 quiz questions

  3. 03

    Building the Zero Trust Strategy

    Covers the CCZT Zero Trust Strategy domain, the planning layer that turns Zero Trust principles into a funded, governed program. You will learn to align Zero Trust to business objectives and risk appetite, secure executive sponsorship and workable governance, assess current maturity against a target operating model, and build a business case, roadmap, and metric set that survive board scrutiny. Every lesson uses original scenarios in the style the exam favors.

    4 lessons · 15 quiz questions

  4. 04

    Planning the Zero Trust Program

    Covers the CCZT Zero Trust Planning domain, where strategy becomes an executable program. You learn to define protect surfaces around crown jewel data, map the transaction flows and dependencies that policy must respect, design a target architecture with placed enforcement points and selected capabilities, and sequence migration so that enforcement arrives without breaking the business. Every lesson closes with exam style checks, and the module ends with a fifteen question domain quiz.

    4 lessons · 15 quiz questions

  5. 05

    Implementing and Sustaining Zero Trust

    Covers the CCZT Zero Trust Implementation domain, where architecture on paper becomes controls that actually decide and enforce. You will sequence an identity and device trust rollout, segment a protect surface, wire telemetry into continuous verification, and run the program as a repeatable operating model. Each lesson closes with original, exam-style scenarios that mirror the judgment the exam asks for.

    4 lessons · 15 quiz questions