ISC2 CERTIFIED IN CYBERSECURITY (CC) FINAL PRACTICE EXAMINATION |
STUDY GUIDE | LATEST UPDATE 2026/2027 | ACTUAL EXAM | PRACTICE
QUESTIONS AND ANSWERS | EXAM REVIEW | 100% CORRECT ANSWERS |
VERIFIED SOLUTIONS
This final practice examination is designed for candidates completing their preparation for the
ISC2 Certified in Cybersecurity (CC) certification. As the culminating assessment tool, this 100-
question examination provides comprehensive coverage across all five CC domains: Security
Principles, Business Continuity and Disaster Recovery, Access Controls, Network Security, and
Security Operations. Each question has been carefully crafted to reflect the cognitive level and
format of the actual CC examination, with detailed answer rationales that reinforce fundamental
cybersecurity concepts. This resource serves as the final validation of readiness, helping
candidates identify any remaining knowledge gaps and build the confidence necessary for first-
attempt success. By completing this examination under simulated testing conditions, candidates
will demonstrate mastery of the foundational cybersecurity knowledge required for the CC
credential and establish a solid foundation for career advancement in information security.
Table of Contents
Domain 1: Security Principles (Questions 1-20)
Domain 2: Business Continuity and Disaster Recovery (Questions 21-34)
Domain 3: Access Controls Concepts (Questions 35-54)
Domain 4: Network Security (Questions 55-74)
Domain 5: Security Operations (Questions 75-100)
,DOMAIN 1: SECURITY PRINCIPLES
Question 1
An organization wants to ensure that sensitive customer data remains protected from
unauthorized disclosure while being stored in its database. Which security principle should be
the primary focus?
A) Availability
B) Integrity
C) Confidentiality
D) Non-repudiation
Correct Answer: C
Confidentiality ensures that information is accessible only to authorized individuals or systems.
Protecting stored customer data from unauthorized disclosure is a confidentiality concern.
Availability (A) ensures data is accessible when needed. Integrity (B) ensures data accuracy.
Non-repudiation (D) provides proof of actions.
Question 2
A security analyst identifies a software vulnerability that could allow an attacker to modify
financial records without authorization. Which component of the CIA triad is most directly
threatened?
A) Confidentiality
B) Integrity
C) Availability
D) Authentication
Correct Answer: B
Integrity ensures data is accurate, complete, and protected from unauthorized modification. The
ability to modify financial records without authorization directly threatens data integrity.
Confidentiality (A) addresses unauthorized disclosure. Availability (C) addresses system access.
Authentication (D) is not part of the CIA triad.
Question 3
What is the fundamental difference between a vulnerability and a threat?
A) They are interchangeable terms
B) A vulnerability is a weakness that could be exploited; a threat is a potential danger that could
exploit that weakness
C) A threat is always internal; a vulnerability is always external
D) Vulnerabilities only exist in software; threats only come from humans
Correct Answer: B
A vulnerability is a gap or weakness in security controls. A threat is any potential danger that
could exploit a vulnerability. For example, an unpatched operating system (vulnerability) could
, be exploited by ransomware (threat). Understanding this distinction is fundamental to risk
management.
Question 4
An organization installs a security camera system throughout its facility. The cameras record
continuously and footage is reviewed whenever a security incident is suspected. What type of
security control are these cameras?
A) Preventive control
B) Detective control
C) Corrective control
D) Compensating control
Correct Answer: B
Detective controls identify and record security events. Security cameras record activity for later
investigation and review, making them detective controls. While cameras may also serve as a
deterrent, their primary function described is detection. Preventive controls (A) stop actions
before they occur. Corrective controls (C) remedy incidents afterward.
Question 5
The principle of least privilege should be applied to which of the following?
A) Only system administrators
B) All users, systems, and processes
C) Only external contractors
D) Only users with access to financial data
Correct Answer: B
Least privilege applies universally—to all users, systems, applications, and processes. Every
entity should have only the minimum access necessary to perform its authorized function. This
limits potential damage from errors, compromised accounts, or malicious activity.
Question 6
An organization deploys a firewall at the network perimeter, implements strong authentication
for all users, encrypts sensitive data, and provides security awareness training to employees.
What security principle does this multi-layered approach demonstrate?
A) Least privilege
B) Separation of duties
C) Defense in depth
D) Fail-safe defaults
Correct Answer: C
Defense in depth uses multiple, independent layers of security controls. If one layer fails, others
continue to provide protection. The scenario describes technical controls (firewall,
authentication, encryption) and administrative controls (training) working together.
Question 7
What is the primary purpose of a security policy?
STUDY GUIDE | LATEST UPDATE 2026/2027 | ACTUAL EXAM | PRACTICE
QUESTIONS AND ANSWERS | EXAM REVIEW | 100% CORRECT ANSWERS |
VERIFIED SOLUTIONS
This final practice examination is designed for candidates completing their preparation for the
ISC2 Certified in Cybersecurity (CC) certification. As the culminating assessment tool, this 100-
question examination provides comprehensive coverage across all five CC domains: Security
Principles, Business Continuity and Disaster Recovery, Access Controls, Network Security, and
Security Operations. Each question has been carefully crafted to reflect the cognitive level and
format of the actual CC examination, with detailed answer rationales that reinforce fundamental
cybersecurity concepts. This resource serves as the final validation of readiness, helping
candidates identify any remaining knowledge gaps and build the confidence necessary for first-
attempt success. By completing this examination under simulated testing conditions, candidates
will demonstrate mastery of the foundational cybersecurity knowledge required for the CC
credential and establish a solid foundation for career advancement in information security.
Table of Contents
Domain 1: Security Principles (Questions 1-20)
Domain 2: Business Continuity and Disaster Recovery (Questions 21-34)
Domain 3: Access Controls Concepts (Questions 35-54)
Domain 4: Network Security (Questions 55-74)
Domain 5: Security Operations (Questions 75-100)
,DOMAIN 1: SECURITY PRINCIPLES
Question 1
An organization wants to ensure that sensitive customer data remains protected from
unauthorized disclosure while being stored in its database. Which security principle should be
the primary focus?
A) Availability
B) Integrity
C) Confidentiality
D) Non-repudiation
Correct Answer: C
Confidentiality ensures that information is accessible only to authorized individuals or systems.
Protecting stored customer data from unauthorized disclosure is a confidentiality concern.
Availability (A) ensures data is accessible when needed. Integrity (B) ensures data accuracy.
Non-repudiation (D) provides proof of actions.
Question 2
A security analyst identifies a software vulnerability that could allow an attacker to modify
financial records without authorization. Which component of the CIA triad is most directly
threatened?
A) Confidentiality
B) Integrity
C) Availability
D) Authentication
Correct Answer: B
Integrity ensures data is accurate, complete, and protected from unauthorized modification. The
ability to modify financial records without authorization directly threatens data integrity.
Confidentiality (A) addresses unauthorized disclosure. Availability (C) addresses system access.
Authentication (D) is not part of the CIA triad.
Question 3
What is the fundamental difference between a vulnerability and a threat?
A) They are interchangeable terms
B) A vulnerability is a weakness that could be exploited; a threat is a potential danger that could
exploit that weakness
C) A threat is always internal; a vulnerability is always external
D) Vulnerabilities only exist in software; threats only come from humans
Correct Answer: B
A vulnerability is a gap or weakness in security controls. A threat is any potential danger that
could exploit a vulnerability. For example, an unpatched operating system (vulnerability) could
, be exploited by ransomware (threat). Understanding this distinction is fundamental to risk
management.
Question 4
An organization installs a security camera system throughout its facility. The cameras record
continuously and footage is reviewed whenever a security incident is suspected. What type of
security control are these cameras?
A) Preventive control
B) Detective control
C) Corrective control
D) Compensating control
Correct Answer: B
Detective controls identify and record security events. Security cameras record activity for later
investigation and review, making them detective controls. While cameras may also serve as a
deterrent, their primary function described is detection. Preventive controls (A) stop actions
before they occur. Corrective controls (C) remedy incidents afterward.
Question 5
The principle of least privilege should be applied to which of the following?
A) Only system administrators
B) All users, systems, and processes
C) Only external contractors
D) Only users with access to financial data
Correct Answer: B
Least privilege applies universally—to all users, systems, applications, and processes. Every
entity should have only the minimum access necessary to perform its authorized function. This
limits potential damage from errors, compromised accounts, or malicious activity.
Question 6
An organization deploys a firewall at the network perimeter, implements strong authentication
for all users, encrypts sensitive data, and provides security awareness training to employees.
What security principle does this multi-layered approach demonstrate?
A) Least privilege
B) Separation of duties
C) Defense in depth
D) Fail-safe defaults
Correct Answer: C
Defense in depth uses multiple, independent layers of security controls. If one layer fails, others
continue to provide protection. The scenario describes technical controls (firewall,
authentication, encryption) and administrative controls (training) working together.
Question 7
What is the primary purpose of a security policy?