ISC2 Certified in Cybersecurity (CC)
Exam (AGACNP-C) 2026–2027 |
Comprehensive Question Practice Test
with Answers & Rationales| Free Pdf
Access
1. The primary objective of cybersecurity is to:
A. Protect the confidentiality, integrity, and availability of information
B. Increase network bandwidth
C. Eliminate all business risks
D. Improve computer processing speed
Correct Answer: A
Rationale: The CIA triad (Confidentiality, Integrity, and Availability) is the foundation of
cybersecurity.
2. Which component of the CIA triad ensures information is accurate and has
not been altered without authorization?
A. Confidentiality
B. Integrity
C. Availability
,D. Accountability
Correct Answer: B
Rationale: Integrity protects information from unauthorized modification.
3. Confidentiality is primarily achieved through:
A. Encryption and access controls
B. System backups
C. Hardware upgrades
D. Network redundancy
Correct Answer: A
Rationale: Encryption and access controls prevent unauthorized disclosure of information.
4. Availability ensures that:
A. Information and systems are accessible to authorized users when needed
B. Information cannot be modified
C. Data remains confidential
D. Passwords are encrypted
Correct Answer: A
Rationale: Availability ensures reliable access to systems and data.
5. Which of the following is considered an asset?
A. Information, hardware, software, and people
B. Only computer hardware
,C. Only applications
D. Only financial records
Correct Answer: A
Rationale: Assets include anything valuable to an organization.
6. A threat is best defined as:
A. A potential cause of an unwanted incident
B. A security policy
C. A firewall rule
D. A software update
Correct Answer: A
Rationale: Threats have the potential to exploit vulnerabilities.
7. A vulnerability is:
A. A weakness that could be exploited by a threat
B. A security awareness program
C. A backup strategy
D. An access control model
Correct Answer: A
Rationale: Vulnerabilities create opportunities for attacks.
8. Risk is generally determined by:
A. Likelihood multiplied by impact
, B. Number of employees
C. Amount of storage
D. Internet bandwidth
Correct Answer: A
Rationale: Risk combines the probability of an event and its potential consequences.
9. Which risk response strategy involves purchasing cyber insurance?
A. Risk Acceptance
B. Risk Avoidance
C. Risk Transfer
D. Risk Mitigation
Correct Answer: C
Rationale: Insurance transfers financial risk to another party.
10. Security awareness training primarily aims to:
A. Reduce human-related security incidents
B. Replace firewalls
C. Eliminate malware
D. Increase network speed
Correct Answer: A
Rationale: Employees are often targeted by attackers, making awareness essential.
11. Business continuity planning focuses on:
Exam (AGACNP-C) 2026–2027 |
Comprehensive Question Practice Test
with Answers & Rationales| Free Pdf
Access
1. The primary objective of cybersecurity is to:
A. Protect the confidentiality, integrity, and availability of information
B. Increase network bandwidth
C. Eliminate all business risks
D. Improve computer processing speed
Correct Answer: A
Rationale: The CIA triad (Confidentiality, Integrity, and Availability) is the foundation of
cybersecurity.
2. Which component of the CIA triad ensures information is accurate and has
not been altered without authorization?
A. Confidentiality
B. Integrity
C. Availability
,D. Accountability
Correct Answer: B
Rationale: Integrity protects information from unauthorized modification.
3. Confidentiality is primarily achieved through:
A. Encryption and access controls
B. System backups
C. Hardware upgrades
D. Network redundancy
Correct Answer: A
Rationale: Encryption and access controls prevent unauthorized disclosure of information.
4. Availability ensures that:
A. Information and systems are accessible to authorized users when needed
B. Information cannot be modified
C. Data remains confidential
D. Passwords are encrypted
Correct Answer: A
Rationale: Availability ensures reliable access to systems and data.
5. Which of the following is considered an asset?
A. Information, hardware, software, and people
B. Only computer hardware
,C. Only applications
D. Only financial records
Correct Answer: A
Rationale: Assets include anything valuable to an organization.
6. A threat is best defined as:
A. A potential cause of an unwanted incident
B. A security policy
C. A firewall rule
D. A software update
Correct Answer: A
Rationale: Threats have the potential to exploit vulnerabilities.
7. A vulnerability is:
A. A weakness that could be exploited by a threat
B. A security awareness program
C. A backup strategy
D. An access control model
Correct Answer: A
Rationale: Vulnerabilities create opportunities for attacks.
8. Risk is generally determined by:
A. Likelihood multiplied by impact
, B. Number of employees
C. Amount of storage
D. Internet bandwidth
Correct Answer: A
Rationale: Risk combines the probability of an event and its potential consequences.
9. Which risk response strategy involves purchasing cyber insurance?
A. Risk Acceptance
B. Risk Avoidance
C. Risk Transfer
D. Risk Mitigation
Correct Answer: C
Rationale: Insurance transfers financial risk to another party.
10. Security awareness training primarily aims to:
A. Reduce human-related security incidents
B. Replace firewalls
C. Eliminate malware
D. Increase network speed
Correct Answer: A
Rationale: Employees are often targeted by attackers, making awareness essential.
11. Business continuity planning focuses on: