Page 1 of 284
ISC2 CC EXAM/ ISC2 CERTIFIED IN
CYBERSECURITY (CC) EXAM PREP***
QUESTIONS AND ANSWERS | VERIFIED AND
WELL DETAILED ANSWERS | DOWNLOAD AND
PASS | LATEST EXAM UPDATE 2026/2027
Which of these is NOT a feature of a SIEM (Security Information and
Event Management)?
A. Log consolidation
B. Log retention
C. Log encryption
D. Log auditing
D. Log auditing
A SIEM typically provides the following features; log consolidation, which
consists in collecting logs from various sources (like servers, firewalls, or
IDS/IPS) and then storing them in one central location. Log retention,
which consists in storing logs for a specific period (like 90 days), so as to
allow security analysts to keep track of and investigate past events. Log
encryption, which is an optional feature that safeguards the
confidentiality of log data. Log analysis, which involves identifying
patterns, trends and anomalies related to security events, in or close to
real time. Though related to log analysis, log auditing specifically refers
to ensuring the reliability and trustworthiness of log data for debugging,
,Page 2 of 284
performance monitoring, security, and compliance purposes. This is
usually done on a periodic bases (not real-time).
What does the term 'data remanence' refer?
A. All of the data in a system
B. Files saved locally that can't be remotely accessed
C. Data in use that can't be encrypted
D. Data left over after routine removal and deletion
D. Data left over after routine removal and deletion
Data remanence refers to data left over after routing removal and
deletion of data from a storage device (see Chapter 4, module 3). When
digital data is deleted, instead of being erased from the storage media, it
is often only marked deleted, and the corresponding space is then made
available to be overwritten later on. Consequently, deleted data can still
be present on the storage media, and can be recovered using the proper
media analysis and recovery tools. Data remanence is a concern when
media storage devices containing sensitive or confidential data need to
be disposed of. Specialized techniques and tools can be used to security
erase data and reduce the risk of data remanence, such as degaussing
and other specialized data destruction tools. Therefore, the term data
remanence is unrelated to any of the other options.
,Page 3 of 284
Which of these devices has the PRIMARY objective of determining the
most efficient path for he traffic to flow across the network?
A. Firewalls
B. Hubs
C. Switches
D. Routers
D. Routers
A router is a networking device whose primary objective is to determine
the most efficient path for traffic to flow across a network. Routers
connect two or more networks and forward data packets between them
according to their destination address (Chapter 4, module 1). When a
router receives a data packet, it checks the destination address and
determines the best route on which to forward the packet, based on its
routing table. The routing table is a set of rules hat the router used to
determine the next hop for a given data packet. Hubs connect multiple
devices on a network and broadcast incoming data packets to all
connected devices. Hubs cannot route data based on destination
address; as a result, all connected devices receive all incoming data
packets. Switches connect multiple devices on a network and forward
data packets between them based on the MAC address of the
destination device. Switches use MAC addresses to create a forwarding
table that efficiently routes data to the correct destination. Firewalls are
network devices or software designed to protect a network from
external threats (like hacking and malware). Firewalls can block or allow
traffic based on various criteria, such as source or destination of the
traffic, as well as the type of data.
, Page 4 of 284
Which of these is an attack whose PRIMARY goal is to gain access to a
target system through falsified identity?
A. Ransomware
B. Spoofing
C. Amplification
D. DDoS
B. Spoofing
Spoofing is an attack whose primary goal is to gain access to a target
system through a falsified identity; the attacker creates or manipulates a
digital identity or communication, so as to deceive the target into
believing hat the attacker is someone or something else. There are many
different types of spoofing attacks, including email spoofing, IP spoofing,
and URL spoofing. Such attacks are used to gain unauthorized access to
systems or networks, steal sensitive information, or spread malware
(Chapter 4, module 2). The other types of attacks listed above have
different primary goals. DDoS attacks aim at overwhelming a target
system with traffic to disrupt its operation; amplification attacks involve
using a third-party system to amplify the strength of an attack; and
ransomware attacks typically encrypt a target system's data, and then
demand a ransom in exchange for the decryption code.
ISC2 CC EXAM/ ISC2 CERTIFIED IN
CYBERSECURITY (CC) EXAM PREP***
QUESTIONS AND ANSWERS | VERIFIED AND
WELL DETAILED ANSWERS | DOWNLOAD AND
PASS | LATEST EXAM UPDATE 2026/2027
Which of these is NOT a feature of a SIEM (Security Information and
Event Management)?
A. Log consolidation
B. Log retention
C. Log encryption
D. Log auditing
D. Log auditing
A SIEM typically provides the following features; log consolidation, which
consists in collecting logs from various sources (like servers, firewalls, or
IDS/IPS) and then storing them in one central location. Log retention,
which consists in storing logs for a specific period (like 90 days), so as to
allow security analysts to keep track of and investigate past events. Log
encryption, which is an optional feature that safeguards the
confidentiality of log data. Log analysis, which involves identifying
patterns, trends and anomalies related to security events, in or close to
real time. Though related to log analysis, log auditing specifically refers
to ensuring the reliability and trustworthiness of log data for debugging,
,Page 2 of 284
performance monitoring, security, and compliance purposes. This is
usually done on a periodic bases (not real-time).
What does the term 'data remanence' refer?
A. All of the data in a system
B. Files saved locally that can't be remotely accessed
C. Data in use that can't be encrypted
D. Data left over after routine removal and deletion
D. Data left over after routine removal and deletion
Data remanence refers to data left over after routing removal and
deletion of data from a storage device (see Chapter 4, module 3). When
digital data is deleted, instead of being erased from the storage media, it
is often only marked deleted, and the corresponding space is then made
available to be overwritten later on. Consequently, deleted data can still
be present on the storage media, and can be recovered using the proper
media analysis and recovery tools. Data remanence is a concern when
media storage devices containing sensitive or confidential data need to
be disposed of. Specialized techniques and tools can be used to security
erase data and reduce the risk of data remanence, such as degaussing
and other specialized data destruction tools. Therefore, the term data
remanence is unrelated to any of the other options.
,Page 3 of 284
Which of these devices has the PRIMARY objective of determining the
most efficient path for he traffic to flow across the network?
A. Firewalls
B. Hubs
C. Switches
D. Routers
D. Routers
A router is a networking device whose primary objective is to determine
the most efficient path for traffic to flow across a network. Routers
connect two or more networks and forward data packets between them
according to their destination address (Chapter 4, module 1). When a
router receives a data packet, it checks the destination address and
determines the best route on which to forward the packet, based on its
routing table. The routing table is a set of rules hat the router used to
determine the next hop for a given data packet. Hubs connect multiple
devices on a network and broadcast incoming data packets to all
connected devices. Hubs cannot route data based on destination
address; as a result, all connected devices receive all incoming data
packets. Switches connect multiple devices on a network and forward
data packets between them based on the MAC address of the
destination device. Switches use MAC addresses to create a forwarding
table that efficiently routes data to the correct destination. Firewalls are
network devices or software designed to protect a network from
external threats (like hacking and malware). Firewalls can block or allow
traffic based on various criteria, such as source or destination of the
traffic, as well as the type of data.
, Page 4 of 284
Which of these is an attack whose PRIMARY goal is to gain access to a
target system through falsified identity?
A. Ransomware
B. Spoofing
C. Amplification
D. DDoS
B. Spoofing
Spoofing is an attack whose primary goal is to gain access to a target
system through a falsified identity; the attacker creates or manipulates a
digital identity or communication, so as to deceive the target into
believing hat the attacker is someone or something else. There are many
different types of spoofing attacks, including email spoofing, IP spoofing,
and URL spoofing. Such attacks are used to gain unauthorized access to
systems or networks, steal sensitive information, or spread malware
(Chapter 4, module 2). The other types of attacks listed above have
different primary goals. DDoS attacks aim at overwhelming a target
system with traffic to disrupt its operation; amplification attacks involve
using a third-party system to amplify the strength of an attack; and
ransomware attacks typically encrypt a target system's data, and then
demand a ransom in exchange for the decryption code.