ISC2 - Certified in Cybersecurity (CC)
1. What is the difference between role-based access C
control (RBAC) and attribute-based access control
(ABAC)?
A) RBAC is based on the sensitivity of the resource,
while ABAC is based on the identity of the user.
B) RBAC and ABAC are the same thing.
C) RBAC is based on the identity of the user, while
ABAC is based on the sensitivity of the resource.
D) RBAC and ABAC are both types of logical access
control
2. Which of the following is an example of a technical C
control?
A) Incident response plan
B) Security awareness training
C) Firewall implementation
D) Security policy
3. Which of the following is a common type of network A
load balancer?
A) All of the above
B) Weighted round-robin
C) Round-robin
D) Least connections
4. Which of the following is an example of a BYOD poli- C
cy?
A) Providing employees with company-owned devices
for work
, ISC2 - Certified in Cybersecurity (CC)
B) All of the above
C) Allowing employees to bring their own devices to
work
D) Requiring employees to use only company-owned
devices
5. Which principle of the CIA Triad ensures that informa- B
tion is accurate, complete, and trustworthy?
A) Authentication
B) Integrity
C) Availability
D) Confidentiality
6. Which of the following is an example of social engi- C
neering?
A) A brute force attack
B) A SQL injection attack
C) A phishing email
D) A DDoS attack
7. Which of the following is a best practice for security D
awareness training?
A) Providing training only once a year
B) None of the above
C) Providing the same training to all employees
D) Making training sessions mandatory for all employ-
ees
8. Why is off-site data backup an important considera- D
tion in disaster recovery?
, ISC2 - Certified in Cybersecurity (CC)
A) It eliminates the need for data recovery procedures
B) It minimizes the risk of data breaches during a
disruption
C) It provides physical security for data centers
D) It ensures business continuity in case of a local site
failure
9. What is the difference between a vulnerability scan A
and a penetration test?
A) A vulnerability scan is a less comprehensive security
assessment that only looks for known vulnerabilities,
while a penetration test is a more comprehensive as-
sessment that tries to simulate a real-world attack.
B) A vulnerability scan and a penetration test are both
types of logical access control.
C) A vulnerability scan and a penetration test are the
same thing.
D) A vulnerability scan is a comprehensive security
assessment that tests all aspects of a network, while a
penetration test is a less comprehensive assessment
that only focuses on specific vulnerabilities.
10. What is the primary purpose of a network intrusion C
detection system (IDS)?
A) To prevent network attacks
B) To remove malware from a network
C) To detect network attacks
D) To improve network performance
11. B
, ISC2 - Certified in Cybersecurity (CC)
Which of the following is a best practice for securing
web applications?
A) Using a weak password for the web application
B) Regularly applying security patches and updates
C) Allowing users to upload files without validation
D) None of the above
12. What is the primary purpose of a network demilita- D
rized zone (DMZ)?
A) To remove malware from a network
B) To monitor network traffic
C) To improve network performance
D) To provide a secure area for internet-facing services
13. Which of the following is a key component of a disas- D
ter recovery plan related to hardware and infrastruc-
ture?
A) Data backup and recovery procedures
B) Risk assessment and mitigation strategies
C) Incident response team contact information
D) Configuration documentation for network devices
14. What is the purpose of data loss prevention (DLP) C
technology?
A) To monitor network traffic for malicious activity
B) To prevent unauthorized access to a network
C) To prevent the loss or theft of sensitive data
D) To provide remote access to a network
1. What is the difference between role-based access C
control (RBAC) and attribute-based access control
(ABAC)?
A) RBAC is based on the sensitivity of the resource,
while ABAC is based on the identity of the user.
B) RBAC and ABAC are the same thing.
C) RBAC is based on the identity of the user, while
ABAC is based on the sensitivity of the resource.
D) RBAC and ABAC are both types of logical access
control
2. Which of the following is an example of a technical C
control?
A) Incident response plan
B) Security awareness training
C) Firewall implementation
D) Security policy
3. Which of the following is a common type of network A
load balancer?
A) All of the above
B) Weighted round-robin
C) Round-robin
D) Least connections
4. Which of the following is an example of a BYOD poli- C
cy?
A) Providing employees with company-owned devices
for work
, ISC2 - Certified in Cybersecurity (CC)
B) All of the above
C) Allowing employees to bring their own devices to
work
D) Requiring employees to use only company-owned
devices
5. Which principle of the CIA Triad ensures that informa- B
tion is accurate, complete, and trustworthy?
A) Authentication
B) Integrity
C) Availability
D) Confidentiality
6. Which of the following is an example of social engi- C
neering?
A) A brute force attack
B) A SQL injection attack
C) A phishing email
D) A DDoS attack
7. Which of the following is a best practice for security D
awareness training?
A) Providing training only once a year
B) None of the above
C) Providing the same training to all employees
D) Making training sessions mandatory for all employ-
ees
8. Why is off-site data backup an important considera- D
tion in disaster recovery?
, ISC2 - Certified in Cybersecurity (CC)
A) It eliminates the need for data recovery procedures
B) It minimizes the risk of data breaches during a
disruption
C) It provides physical security for data centers
D) It ensures business continuity in case of a local site
failure
9. What is the difference between a vulnerability scan A
and a penetration test?
A) A vulnerability scan is a less comprehensive security
assessment that only looks for known vulnerabilities,
while a penetration test is a more comprehensive as-
sessment that tries to simulate a real-world attack.
B) A vulnerability scan and a penetration test are both
types of logical access control.
C) A vulnerability scan and a penetration test are the
same thing.
D) A vulnerability scan is a comprehensive security
assessment that tests all aspects of a network, while a
penetration test is a less comprehensive assessment
that only focuses on specific vulnerabilities.
10. What is the primary purpose of a network intrusion C
detection system (IDS)?
A) To prevent network attacks
B) To remove malware from a network
C) To detect network attacks
D) To improve network performance
11. B
, ISC2 - Certified in Cybersecurity (CC)
Which of the following is a best practice for securing
web applications?
A) Using a weak password for the web application
B) Regularly applying security patches and updates
C) Allowing users to upload files without validation
D) None of the above
12. What is the primary purpose of a network demilita- D
rized zone (DMZ)?
A) To remove malware from a network
B) To monitor network traffic
C) To improve network performance
D) To provide a secure area for internet-facing services
13. Which of the following is a key component of a disas- D
ter recovery plan related to hardware and infrastruc-
ture?
A) Data backup and recovery procedures
B) Risk assessment and mitigation strategies
C) Incident response team contact information
D) Configuration documentation for network devices
14. What is the purpose of data loss prevention (DLP) C
technology?
A) To monitor network traffic for malicious activity
B) To prevent unauthorized access to a network
C) To prevent the loss or theft of sensitive data
D) To provide remote access to a network