- How CFR-410 Scoring Actually Works
- Scaled Scores and Statistical Equating Explained
- Domain Weights and Their Impact on Your Score
- Reading Your Score Report After the Exam
- What Actually Affects Your Raw Score
- Preparing Domain by Domain to Hit the Passing Threshold
- Free Retake Policy and Score Reset Rules
- Frequently Asked Questions
- CFR-410 passing score is 70%-73%, depending on your specific exam form - not a fixed cutoff.
- Your score is statistically equated across forms, so a harder form does not penalize you.
- 80 scored questions across 5 NIST-aligned domains must be answered in 120 minutes.
- Domain 2 (Protect) carries the highest weight at 24% - weak performance here costs the most points.
How CFR-410 Scoring Actually Works
Most candidates approaching the CyberSec First Responder exam assume there is a single, fixed passing score. The reality is more nuanced - and understanding it changes how you should interpret your results, whether you passed or fell short.
CertNexus administers CFR-410 through Pearson VUE, either at a physical test center or via the OnVUE remote proctoring platform. The exam contains 80 scored multiple-choice and multiple-response questions delivered in a 120-minute window. The exam is closed book and is not adaptive - every candidate receives a fixed set of questions from the same domain blueprint, though not necessarily the same questions.
That last point is crucial: because different candidates may receive different forms of the exam - sets of questions drawn from the same pool but varying in difficulty - CertNexus uses statistical equating to ensure your score reflects your actual knowledge level, not the particular difficulty of your form. The result is a passing threshold expressed as a range: 70% to 73%. Your required score depends on which form you received, but the equating process ensures you are not disadvantaged by a harder set of questions.
Scaled Scores and Statistical Equating Explained
Pearson VUE delivers your result as a scaled score rather than a simple percentage of questions answered correctly. A scaled score accounts for the statistical difficulty of your specific exam form, translating raw performance into a standardized number on a consistent scale.
CertNexus does not publicly publish the exact scaled score scale for CFR-410, but the framework is consistent with ANAB-accredited certification programs operating under ISO/IEC 17024 - which CFR holds. Under that standard, the passing point must be defensible through psychometric analysis, and the range of 70%-73% reflects where that analysis places competent performance across forms.
What This Means in Practice
If you answered, for example, 58 of 80 questions correctly, your raw score is 72.5% - almost certainly a pass on any form. If you answered 55 correctly (68.75%), you are likely below the cutoff on most forms. The danger zone is roughly 56-58 correct answers, where your result depends on your specific form. This is why candidates who report scores "just below" passing sometimes describe feeling that a few questions seemed unusually ambiguous - they may have received a slightly harder form whose equated cutoff happened to fall at 71% or 72%.
The practical takeaway: aim for a comfortable margin above 73%, not just 70%. Targeting 80% or better on CFR practice tests gives you a realistic buffer against form-level variation.
Key Takeaway
Because the passing threshold shifts between 70% and 73% by form, a candidate scoring exactly 70% on a raw basis has not necessarily passed. Build a score buffer of at least 7-10 percentage points above the minimum when practicing.
Domain Weights and Their Impact on Your Score
The CFR-410 exam blueprint (v1.10, issued May 1, 2021, modified February 22, 2022) maps every question to one of five domains aligned to the NIST Cybersecurity Framework. The proportion of your 80 questions coming from each domain is fixed by those weights, which means your domain-level performance directly determines whether you pass.
| Domain | Blueprint Weight | Approximate Questions (of 80) | Risk if Underprepared |
|---|---|---|---|
| Domain 1: Identify | 22% | ~18 | High - second-largest domain |
| Domain 2: Protect | 24% | ~19 | Highest - most questions on the exam |
| Domain 3: Detect | 18% | ~14 | Moderate |
| Domain 4: Respond | 19% | ~15 | High - operationally core to the role |
| Domain 5: Recover | 17% | ~14 | Moderate - smallest share but still meaningful |
Domain 2 (Protect) alone accounts for nearly one in four questions. A candidate who treats Protect as a secondary focus and performs poorly on that domain can lose close to 5 percentage points off their total score from that domain alone - more than enough to push a borderline candidate below the cutoff.
Domain 2: Protect - The Exam's Highest-Stakes Domain
With 24% of questions, Protect is where most candidates need to spend disproportionate preparation time. It covers the security controls, policies, and architectures that a cyber first responder must understand to contain threats before escalation.
- Identity and access management controls (MFA, RBAC, PAM)
- Data security and encryption standards applicable to incident scope
- Network security architectures including segmentation and DMZ design
- Security information sharing and protective technology deployment
- Vulnerability management processes and prioritization frameworks
Domain 1: Identify - Risk Context That Frames the Entire Exam
At 22%, Identify covers asset management, business environment, governance, risk assessment, and supply chain risk. Questions here often require interpreting organizational context to evaluate which threats matter most - a thinking skill that carries across all other domains.
- Asset inventory and classification methodology
- Risk assessment frameworks (NIST SP 800-30, OCTAVE)
- Governance structures and policy hierarchies
- Supply chain threat modeling concepts
Reading Your Score Report After the Exam
When you complete CFR-410 at a Pearson VUE test center or via OnVUE remote proctoring, you receive an unofficial score report immediately after the session ends. This report shows your overall pass/fail status and a domain-by-domain performance breakdown - but it does not show a precise percentage per domain.
Instead, CertNexus and Pearson VUE use a proficiency indicator for each domain, typically shown as a bar or descriptor (such as "Below Proficient," "Proficient," or "Above Proficient"). This matters enormously for candidates who did not pass. A score report showing that you were Below Proficient in Domain 2 (Protect) and Domain 4 (Respond) tells you exactly where to concentrate your 30-day retake preparation - two domains that together account for 43% of your score.
Official Score Report vs. Unofficial Results
The on-screen result is unofficial. CertNexus issues your official digital certificate and score record through their credentialing portal after the session is processed - typically within a few business days. The domain breakdown on your score report is the most actionable piece of data you will receive, so study it carefully regardless of your outcome.
If you are planning your next attempt after an unsuccessful first try, reviewing the domain-level report alongside the CFR Study Materials 2026: Books, Tools and Resources guide will help you match the right resources to your weakest domains rather than studying everything from scratch.
What Actually Affects Your Raw Score
CFR-410 is not an adaptive exam, meaning question difficulty does not adjust in real time based on your performance. All 80 questions are presented regardless of how you perform on earlier items. This creates a specific risk: a bad start to the exam does not shut you out, but a careless final 20 questions - often answered under time pressure - can drag down an otherwise solid performance.
Multiple-Response Questions and Score Impact
The exam includes both standard multiple-choice (select one) and multiple-response (select all that apply) questions. Multiple-response questions are typically all-or-nothing scored - partial credit is not awarded for selecting some but not all correct answers. This means a question requiring you to identify four correct security controls from a list of six counts as zero if you select only three, even if all three are correct.
Candidates unfamiliar with this format frequently lose several points not from lack of knowledge but from misreading question stems. The phrase "select all that apply" should trigger a different answering strategy than a single-answer item - read every option before selecting any, and look for the full set of logically consistent answers rather than stopping at the first plausible one.
Who Hires CFR-Certified Professionals - and Why That Shapes the Question Style
CFR-410 is specifically recognized under DoD Directive 8570.01-M and DoD 8140 for four role categories: CSSP Analyst, CSSP Infrastructure Support, CSSP Incident Responder, and CSSP Auditor. Federal agencies, defense contractors, and critical infrastructure operators account for a significant portion of CFR hiring. This influences how exam questions are framed: scenarios frequently involve enterprise network environments, SIEM alert triage, threat intelligence integration, and chain-of-custody considerations for digital evidence - all operationally real contexts for SOC and CSIRT professionals.
CertNexus recommends 2-5 years of hands-on CERT, CSIRT, or SOC experience as background preparation. Candidates without that depth of experience often find that theoretical knowledge of frameworks is insufficient - many questions present a realistic incident scenario and ask what a first responder should do next, requiring judgment rather than recall.
Preparing Domain by Domain to Hit the Passing Threshold
Because your score is a weighted aggregate of five domain scores, your most efficient preparation strategy is to sequence your study in proportion to domain weight, starting with the highest-impact domains while your retention is freshest.
Domain 2: Protect (24%) + Domain 1: Identify (22%)
- Map all Protect sub-topics against the v1.10 blueprint; prioritize access control and vulnerability management
- Review NIST SP 800-53 control families relevant to protective technology deployment
- Study Identify domain's risk assessment frameworks and asset classification approaches
- Complete at least 30 CFR practice questions focused on these two domains
Domain 4: Respond (19%) + Domain 3: Detect (18%)
- Drill incident response lifecycle steps in order: preparation, detection, containment, eradication, recovery
- Study SIEM log analysis, IDS/IPS alert interpretation, and threat hunting methodology for Detect
- Practice digital forensics chain-of-custody and evidence handling scenarios
- Work through scenario-based multiple-response questions to build selection discipline
Domain 5: Recover (17%) + Full-Length Practice
- Study business continuity, disaster recovery planning, and post-incident lessons-learned processes
- Complete two full 80-question timed practice exams; review every incorrect answer by domain
- Revisit any domain where practice scores fall below 75% - prioritizing Protect and Respond if applicable
- Review the CFR Exam Score Report: How Passing Is Calculated 2026 article to mentally rehearse how to interpret your real score report
This three-week structure applies spaced repetition within a CFR-specific sequence - Protect first because it is the most heavily weighted, Recover last because it is the lightest, and full-length mocks in the final days to simulate real exam pacing. For deeper resource recommendations by domain, the CFR Study Materials 2026: Books, Tools and Resources guide includes textbook and tool recommendations aligned to each blueprint area.
Free Retake Policy and Score Reset Rules
One of the more candidate-friendly aspects of CFR-410 is that CertNexus includes a free retake within the original exam voucher. The $367.50 fee you pay covers both your first attempt and one additional attempt if you do not pass - or if you passed but wish to attempt a higher score (though retaking a passed exam is uncommon and rarely advisable).
The mandatory waiting period between attempts is 30 days. This is not optional - Pearson VUE enforces it at the scheduling level. Thirty days is a sufficient window to diagnose your domain weaknesses from the score report, address them with targeted study, and take at least two full practice exams before rescheduling.
After a Failed First Attempt: Score Report Strategy
Your domain proficiency indicators from the first attempt are the highest-value data you have going into the retake. A candidate who was Below Proficient in Domain 3 (Detect) and Domain 5 (Recover) should spend the 30-day window almost entirely on those domains, since their combined weight is 35% of the exam. Spreading retake preparation evenly across all five domains when you already performed well in three of them is an inefficient use of limited time.
If you exhaust your free retake, subsequent attempts require purchasing a new voucher at the standard $367.50 price. CertNexus does not offer discounted retake-only vouchers - the full fee applies from the third attempt onward. There is no published maximum number of attempts, but each additional attempt requires the same fee and 30-day wait.
Frequently Asked Questions
The passing score varies between 70% and 73% depending on the specific exam form you receive. CertNexus uses statistical equating to adjust the threshold based on the difficulty of each form, so a harder set of questions may have a slightly lower cutoff than an easier one. You cannot know your form's exact cutoff in advance - aim for a score well above 73% to account for this variation.
With 80 scored questions and a passing threshold of 70%-73%, you need roughly 56-59 correct answers depending on your form's equated cutoff. Because multiple-response questions are all-or-nothing scored, your effective "correct answer" count can drop more sharply than expected on those items. Targeting a practice exam average of 80% or higher provides a meaningful safety margin.
Yes. Pearson VUE delivers an immediate unofficial score report that includes a domain-by-domain proficiency breakdown for all five domains (Identify, Protect, Detect, Respond, Recover). The breakdown does not show exact percentages per domain but uses proficiency level indicators. This breakdown is actionable data - whether you passed or not, it tells you where your strengths and gaps lie relative to the blueprint weights.
Yes, CFR-410 is available through Pearson VUE's OnVUE remote proctoring platform as well as at physical test centers. The exam content, scoring methodology, and passing threshold are identical regardless of delivery format. Your choice of in-center or remote proctoring does not affect your score calculation in any way.
If you do not pass on either attempt included in your voucher, you must purchase a new voucher at the full $367.50 price to attempt the exam again. A 30-day waiting period applies between each attempt. CertNexus does not publish a maximum number of lifetime attempts. Use the domain proficiency breakdown from your score reports to make each subsequent attempt as targeted as possible rather than repeating the same broad preparation approach.