Each guide starts with distinctions that often blur together, adds enough context to make the choice meaningful, and ends with scenario clues plus a rapid-review grid. Use them for a short refresher, then return to the full domain guides when you need the surrounding objective context.

CIA, AAA, risk, controls, governance, continuity, recovery, and metrics

Security Principles, Governance, and Resilience Quick Reference

Separate security principles, risk and control decisions, governance documents, continuity, recovery, and effectiveness measures without losing the business purpose.

Review principles and governance

IAM, access models, segmentation, zero trust, cloud models, and responsibility

Identity, Access, and Network Trust Quick Reference

Compare identity lifecycle decisions, access-control models, least privilege, separation of duties, segmentation, zero trust, and cloud responsibility.

Review identity and trust

Data security, monitoring, triage, response, changes, assets, and testing

Security Operations and Incident Response Quick Reference

Connect data protection, cryptography, monitoring, triage, threat information, incident response, change management, asset lifecycle, and security testing.

Review operations and response

Return to the full CC context

Quick review is best for correcting a blurred distinction. Use the September 2026 study guide for the complete five-domain roadmap and the practice test to apply the concepts in randomized scenarios.