CERTIFIED IN CYBERSECURITY (CC) COMPLETE QUESTION BANK | STUDY
GUIDE | LATEST UPDATE 2026/2027 | ACTUAL EXAM | PRACTICE QUESTIONS
AND ANSWERS | EXAM REVIEW | 100% CORRECT ANSWERS | VERIFIED
SOLUTIONS
This comprehensive question bank is designed for entry-level cybersecurity professionals, career
changers, and students preparing for the ISC2 Certified in Cybersecurity (CC) certification. This
foundational credential validates knowledge across five essential security domains and serves as
an ideal stepping stone to advanced certifications like the CISSP. With 100 meticulously
developed and verified questions spanning Security Principles, Business Continuity, Access
Controls, Network Security, and Security Operations, this resource provides complete coverage
of the CC examination objectives. Each question includes a detailed rationale explaining not
only the correct answer but also why alternative options are incorrect. By mastering this
question bank, candidates will build the foundational cybersecurity knowledge and test-taking
confidence required for first-attempt success on the CC examination and establish a solid
framework for a rewarding career in information security.
Table of Contents
Domain 1: Security Principles (Questions 1-25)
Domain 2: Business Continuity and Disaster Recovery (Questions 26-45)
Domain 3: Access Controls Concepts (Questions 46-65)
Domain 4: Network Security (Questions 66-85)
Domain 5: Security Operations (Questions 86-100)
,DOMAIN 1: SECURITY PRINCIPLES (Questions 1-25)
Question 1
Which of the following represents the three fundamental objectives of information security
known as the CIA triad?
A) Control, Investigation, Audit
B) Confidentiality, Integrity, Availability
C) Certification, Identification, Authentication
D) Compliance, Integration, Assessment
Correct Answer: B
The CIA triad represents the three core security principles. Confidentiality ensures data is
accessible only to authorized parties. Integrity ensures data accuracy and protection from
unauthorized modification. Availability ensures systems and data are accessible when needed by
authorized users. These three principles form the foundation of all information security
programs.
Question 2
An employee accidentally deletes a critical file, and the organization is able to restore it from a
backup. Which principle of the CIA triad was primarily protected by having the backup?
A) Confidentiality
B) Integrity
C) Availability
D) Authentication
Correct Answer: C
Availability ensures that data and systems are accessible to authorized users when needed.
Having a backup allowed the organization to restore the deleted file, maintaining its availability
despite the accidental deletion. Confidentiality would involve preventing unauthorized access.
Integrity would involve preventing unauthorized modification.
Question 3
Which of the following best defines a vulnerability in information security?
,A) Any potential danger to an asset
B) A weakness in a system that could be exploited by a threat
C) A person who attacks a system
D) A security policy violation
Correct Answer: B
A vulnerability is a weakness or gap in security controls that could be exploited by a threat.
Examples include unpatched software, weak passwords, or misconfigured systems. A threat (A)
is the potential danger. A threat actor (C) is the person or entity carrying out the threat.
Understanding the difference between threats and vulnerabilities is fundamental to risk
management.
Question 4
A company stores its customer database on an encrypted hard drive. If the drive is stolen, the
data remains protected because the thief cannot read it. Which security principle is primarily
being applied?
A) Availability
B) Integrity
C) Confidentiality
D) Non-repudiation
Correct Answer: C
Confidentiality ensures that information is accessible only to those authorized to access it.
Encryption protects confidentiality by making data unreadable without the proper decryption
key. Even though the physical drive was stolen, the data remains confidential because the thief
cannot decrypt it.
Question 5
What is the primary difference between a threat and a risk?
A) They are the same concept
B) A threat is a potential danger; risk is the likelihood and impact of that threat exploiting a
vulnerability
C) Risk is always intentional; threats can be accidental
D) Threats only apply to technology; risk applies to business
, Correct Answer: B
A threat is any potential danger (malware, natural disaster, human error). Risk is the
combination of the likelihood that a threat will exploit a vulnerability and the resulting impact.
Risk = Threat × Vulnerability × Impact. This distinction is essential for understanding risk
management.
Question 6
Which of the following is an example of a preventive security control?
A) Reviewing security logs for suspicious activity
B) A security guard checking badges at a building entrance
C) A firewall blocking unauthorized network traffic
D) A security incident report documenting what occurred
Correct Answer: C
Preventive controls stop security incidents before they occur. A firewall blocking unauthorized
traffic prevents attacks from reaching internal systems. Log review (A) is a detective control. A
security guard (B) can be preventive or detective depending on their function. Incident reports
(D) are corrective or documentation controls.
Question 7
An organization installs security cameras throughout its facility. These cameras record all
activity and the footage is reviewed after a suspected incident. What type of security control do
the cameras represent?
A) Preventive control
B) Detective control
C) Corrective control
D) Deterrent control
Correct Answer: B
Detective controls identify and record security events after they occur. Security cameras detect
and record activity for later review. While cameras may also serve as a deterrent (D), their
primary function in this scenario is detection—identifying what happened after an incident.
GUIDE | LATEST UPDATE 2026/2027 | ACTUAL EXAM | PRACTICE QUESTIONS
AND ANSWERS | EXAM REVIEW | 100% CORRECT ANSWERS | VERIFIED
SOLUTIONS
This comprehensive question bank is designed for entry-level cybersecurity professionals, career
changers, and students preparing for the ISC2 Certified in Cybersecurity (CC) certification. This
foundational credential validates knowledge across five essential security domains and serves as
an ideal stepping stone to advanced certifications like the CISSP. With 100 meticulously
developed and verified questions spanning Security Principles, Business Continuity, Access
Controls, Network Security, and Security Operations, this resource provides complete coverage
of the CC examination objectives. Each question includes a detailed rationale explaining not
only the correct answer but also why alternative options are incorrect. By mastering this
question bank, candidates will build the foundational cybersecurity knowledge and test-taking
confidence required for first-attempt success on the CC examination and establish a solid
framework for a rewarding career in information security.
Table of Contents
Domain 1: Security Principles (Questions 1-25)
Domain 2: Business Continuity and Disaster Recovery (Questions 26-45)
Domain 3: Access Controls Concepts (Questions 46-65)
Domain 4: Network Security (Questions 66-85)
Domain 5: Security Operations (Questions 86-100)
,DOMAIN 1: SECURITY PRINCIPLES (Questions 1-25)
Question 1
Which of the following represents the three fundamental objectives of information security
known as the CIA triad?
A) Control, Investigation, Audit
B) Confidentiality, Integrity, Availability
C) Certification, Identification, Authentication
D) Compliance, Integration, Assessment
Correct Answer: B
The CIA triad represents the three core security principles. Confidentiality ensures data is
accessible only to authorized parties. Integrity ensures data accuracy and protection from
unauthorized modification. Availability ensures systems and data are accessible when needed by
authorized users. These three principles form the foundation of all information security
programs.
Question 2
An employee accidentally deletes a critical file, and the organization is able to restore it from a
backup. Which principle of the CIA triad was primarily protected by having the backup?
A) Confidentiality
B) Integrity
C) Availability
D) Authentication
Correct Answer: C
Availability ensures that data and systems are accessible to authorized users when needed.
Having a backup allowed the organization to restore the deleted file, maintaining its availability
despite the accidental deletion. Confidentiality would involve preventing unauthorized access.
Integrity would involve preventing unauthorized modification.
Question 3
Which of the following best defines a vulnerability in information security?
,A) Any potential danger to an asset
B) A weakness in a system that could be exploited by a threat
C) A person who attacks a system
D) A security policy violation
Correct Answer: B
A vulnerability is a weakness or gap in security controls that could be exploited by a threat.
Examples include unpatched software, weak passwords, or misconfigured systems. A threat (A)
is the potential danger. A threat actor (C) is the person or entity carrying out the threat.
Understanding the difference between threats and vulnerabilities is fundamental to risk
management.
Question 4
A company stores its customer database on an encrypted hard drive. If the drive is stolen, the
data remains protected because the thief cannot read it. Which security principle is primarily
being applied?
A) Availability
B) Integrity
C) Confidentiality
D) Non-repudiation
Correct Answer: C
Confidentiality ensures that information is accessible only to those authorized to access it.
Encryption protects confidentiality by making data unreadable without the proper decryption
key. Even though the physical drive was stolen, the data remains confidential because the thief
cannot decrypt it.
Question 5
What is the primary difference between a threat and a risk?
A) They are the same concept
B) A threat is a potential danger; risk is the likelihood and impact of that threat exploiting a
vulnerability
C) Risk is always intentional; threats can be accidental
D) Threats only apply to technology; risk applies to business
, Correct Answer: B
A threat is any potential danger (malware, natural disaster, human error). Risk is the
combination of the likelihood that a threat will exploit a vulnerability and the resulting impact.
Risk = Threat × Vulnerability × Impact. This distinction is essential for understanding risk
management.
Question 6
Which of the following is an example of a preventive security control?
A) Reviewing security logs for suspicious activity
B) A security guard checking badges at a building entrance
C) A firewall blocking unauthorized network traffic
D) A security incident report documenting what occurred
Correct Answer: C
Preventive controls stop security incidents before they occur. A firewall blocking unauthorized
traffic prevents attacks from reaching internal systems. Log review (A) is a detective control. A
security guard (B) can be preventive or detective depending on their function. Incident reports
(D) are corrective or documentation controls.
Question 7
An organization installs security cameras throughout its facility. These cameras record all
activity and the footage is reviewed after a suspected incident. What type of security control do
the cameras represent?
A) Preventive control
B) Detective control
C) Corrective control
D) Deterrent control
Correct Answer: B
Detective controls identify and record security events after they occur. Security cameras detect
and record activity for later review. While cameras may also serve as a deterrent (D), their
primary function in this scenario is detection—identifying what happened after an incident.