Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 4 out of 62 pages
Exam (elaborations)

(ISC)² Certified in Cybersecurity – Exam Prep | Questions & Answers, Practice Test, Study Guide & Revision Notes | Latest 2026 PDF

Document preview thumbnail
Preview 4 out of 62 pages

Prepare confidently for the (ISC)² Certified in Cybersecurity (CC) Exam with this comprehensive certification study guide. This PDF includes exam-focused questions and answers with concise revision notes covering security principles, business continuity, disaster recovery, incident response, access controls, network security, security operations, risk management, governance, and essential cybersecurity concepts. Designed for efficient revision and effective learning, it helps reinforce foundational security knowledge, strengthen exam readiness, and improve test-taking confidence. Ideal for aspiring cybersecurity professionals, IT students, entry-level security candidates, and professionals preparing for the (ISC)² Certified in Cybersecurity certification examination.

Content preview

(ISC)2 Certified in Cybersecurity - Exam Prep



_________ are methods used by attackers. Threat Vectors


_________ are the combination of a threat and a Risks
vulnerability.


We rank risks by _________ and _________. Likelihood and impact


_________ use subjective ratings to evaluate risk likelihood Qualitative Risk Assessment
and impact.


_________ use objective numeric ratings to evaluate risk Quantitative Risk Assessment
likelihood and impact.


_________ analyzes and implements possible responses to Risk Treatment
control risk.


_________ changes business practices to make a risk Risk Avoidance
irrelevant.


_________ reduces the likelihood or impact of a risk. Risk Mitigation


An organization's _________ is the set of risks that it faces. Risk Profile




_________ Initial Risk of an organization. Inherent Risk


_________ Risk that remains in an organization after Residual Risk
controls.


_________ is the level of risk an organization is willing to Risk Tolerance
accept.


_________ reduce the likelihood or impact of a risk and Security Controls
help identify issues.


_________ stop a security issue from occurring. Preventive Control


_________ identify security issues requiring investigation. Detective Control


_________ remediate security issues that have occurred. Recovery Control


Hardening == Preventative Virus == Detective


Backups == Recovery For exam (Local and Technical Controls are the same)

, (ISC)2 Certified in Cybersecurity - Exam Prep




_________ use technology to achieve control objectives. Technical Controls


_________ use processes to achieve control objectives. Administrative Controls


_________ impact the physical world. Physical Controls


_________ tracks specific device settings. Configuration Management


_________ provide a configuration snapshot. Baselines (track changes)


_________ assigns numbers to each version. Versioning


_________ serve as important configuration artifacts. Diagrams


_________ and _________ help ensure a stable operating Change and Configuration Management
environment.


Purchasing an insurance policy is an example of which Risk Transference
risk management strategy?




What two factors are used to evaluate a risk? Likelihood and Impact


What term best describes making a snapshot of a Baselining
system or application at a point in time for later
comparison?


What type of security control is designed to stop a Preventive
security issue from occurring in the first place?


What term describes risks that originate inside the Internal
organization?


What four items belong to the security policy Policies, Standards, Guidelines, Procedures
framework?


_________ describe an organization's security expectations. Policies (mandatory and approved at the highest level of an organization)

, (ISC)2 Certified in Cybersecurity - Exam Prep

_________ describe specific security controls and are often Standards (mandatory)
derived from policies.


_________ describe best practices. Guidelines (recommendations/advice and compliance is not mandatory)


_________ step-by-step instructions. Procedures (not mandatory)




_________ describe authorized uses of technology. Acceptable Use Policies (AUP)


_________ describe how to protect sensitive information. Data Handling Policies


_________ cover password security practices. Password Policies


_________ cover use of personal devices with company Bring Your Own Device (BYOD) Policies
information.


_________ cover the use of personally identifiable Privacy Policies
information.


_________ cover the documentation, approval, and rollback Change Management Policies
of technology changes.


Which element of the security policy framework Guidelines
includes suggestions that are not mandatory?


What law applies to the use of personal information GDPR
belonging to European Union residents?


What type of security policy normally describes how BYOD Policy
users may access business information with their own
devices?


_________ the set of controls designed to keep a business Business Continuity Planning (BCP)
running in the face of adversity, whether natural or
man-made.


BCP is also known as _________. Continuity of Operations Planning (COOP)


Defining the BCP Scope: What business activities will the plan cover? What systems will it cover? What
controls will it consider?


_________ identifies and prioritizes risks. Business Impact Assessment

, (ISC)2 Certified in Cybersecurity - Exam Prep

BCP in the cloud requires _________ between providers Collaboration
and customers.


_________ protects against the failure of a single Redundancy
component.


_________ identifies and removes SPOFs. Single Point of Failure Analysis


_________ continues until the cost of addressing risks SPOF Analysis
outweighs the benefit.


_________ uses multiple systems to protect against service High Availability
failure.


_________ makes a single system resilient against technical Fault Tolerance
failures.


_________ spreads demand across systems. Load Balancing


3 Common Points of Failure in a system. Power Supply, Storage Media, Networking


Disk Mirroring is which RAID level? 1


Disk striping with parity is which RAID level? 5 (uses 3 or more disks to store data)


What goal of security is enhanced by a strong business Availability
continuity program?


What is the minimum number of disk required to 3
perform RAID level 5?


What type of control are we using if we supplement a High Availability
single firewall with a second standby firewall ready to
assume responsibility if the primary firewall fails?


_________ provide structure during cybersecurity incidents. Incident Response Plan


_________ describe the policies and procedures governing Incident Response Plans
cybersecurity incidents.


_________ leads to strong incident response. Prior Planning


Incident Response Plans should include: Statement of Purpose, Strategies and goals for incident response, Approach to
incident response, Communication with other groups, Senior leadership
approval


_________ should be consulted when developing a plan. NIST SP 800-61


Incident response teams must have personnel available 24/7
_________.


_________ is crucial to effective incident identification. Monitoring

Document information

Uploaded on
August 25, 2026
Number of pages
62
Written in
2026/2027
Type
Exam (elaborations)
Contains
Questions & answers
$9.99

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
Pacesetter111
4.3
(3)
Sold
12
Followers
0
Items
1113
Last sold
2 weeks ago



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions