Reviewed by the Aegentra Security Team — NV1-cleared ISO 27001 practitioners · Updated May 2026
A practical guide to the PECB Certified Cloud Security Analyst (CCSA) — the hands-on cloud security certification for professionals securing AWS, Azure, and GCP environments in Australia, covering identity, data security, threat detection, monitoring, Docker and Kubernetes hardening, the 3-hour exam, cost, and the two credential tiers.
The PECB Certified Cloud Security Analyst (CCSA) is a hands-on, 5-day-equivalent cloud security certification ($1,250 + GST through Aegentra) covering AWS, Azure, and GCP — identity, data security, threat detection, monitoring, and Docker and Kubernetes security — assessed by a 3-hour remotely proctored exam across five domains, earning 31 CPD credits.
CCSA is a practical cloud security course rather than a governance one. It runs a 5-day equivalent of material — around 35–45 hours self-paced — across cloud security fundamentals and the shared responsibility model, identity and access management, cloud data security, encryption and key management, cloud threat detection including lateral movement and crypto mining attacks, security monitoring and log management in AWS and Azure, and container security with Docker and Kubernetes. It is delivered with hands-on labs and practical exercises across AWS, Azure, and GCP, and is deliberately multi-cloud rather than vendor-specific. Most cloud certifications test whether you understand the shared responsibility model; this one also asks whether you can find lateral movement in cloud logs and harden a Kubernetes cluster. View the full course details.
The Australian Cyber Security Centre publishes cloud security guidance and the Information Security Manual (ISM) carries cloud-specific controls, while Commonwealth and state agencies increasingly host in IRAP-assessed AWS and Azure regions — the platform is assessed, but agencies still need practitioners who can configure and monitor their own workloads. Misconfiguration under the shared responsibility model remains the dominant cause of Australian cloud incidents: exposed storage, over-privileged identities, and unmonitored logging are customer-side failures. APRA CPS 234 requires regulated entities to evidence that cloud environments are monitored and controlled, not merely provisioned. CCSA pairs naturally with a governance credential — see the ISO 27001 certification guide for the management-system side of the pairing.
System and network administrators, security analysts and SOC team members, compliance and risk officers working with cloud environments, IT professionals pivoting into cloud security, and security consultants and auditors assessing cloud estates. PECB expects a solid technical foundation — command-line operations, TCP/IP, DNS, HTTP/S, and general system administration — making this the most technically demanding entry requirement in the Aegentra catalogue. It maps to Cloud Security Analyst, Cloud Security Engineer, SOC Analyst, DevSecOps Engineer, and Security Consultant roles in the Australian market. Adjacent credentials are covered in the incident response certification guide.
Day 1 covers cloud security fundamentals, service models, the shared responsibility model, governance and compliance, and identity and access management. Day 2 covers cloud data security, encryption and key management, threat detection, lateral movement and crypto mining attacks, and attack isolation. Day 3 covers security tooling in AWS and Azure, cloud security monitoring, and log management and analysis. Day 4 covers container security fundamentals, Docker and Kubernetes security practices, and securing container workloads in the cloud. Day 5 is the certification exam.
A 3-hour, remotely proctored PECB exam mixing multiple-choice and scenario-based questions, with a 70% pass mark, across five competency domains: cloud security fundamentals, governance and compliance; identity and access management and cloud data security; cloud threat detection, lateral movement and attack isolation; cloud security monitoring and log management; and container security with Docker and Kubernetes. Certification and examination fees are included in the course price, covering a first attempt plus one free retake within 12 months.
Through Aegentra, an official PECB authorised training partner, the course is $1,250 + GST. The price includes the official CCSA slide deck and 300+ pages of training materials, hands-on labs across AWS, Azure, and GCP, 12 months access via myPECB, the official exam voucher, one free resit within 12 months, a PECB digital certificate on pass, and 31 CPD credits. Instructor-led and in-person delivery in Melbourne and Sydney is available on request.
There are two tiers rather than the usual four. Provisional Analyst is awarded on passing the exam with no experience requirement. The full Analyst credential requires five years of professional experience, two of them in cloud security, plus at least 300 hours of cloud security project activities. Both require signing the PECB Code of Ethics. Browse all Aegentra Academy courses.