ISC2 - CERTIFIED IN CYBERSECURITY (CC) EXAM
QUESTIONS AND 100% CORRECT ANSWERS (A+) 2025
What is the difference between role-based access control (RBAC) and attribute-
based access control (ABAC)?
A) RBAC is based on the sensitivity of the resource, while ABAC is based on the
identity of the user.
B) RBAC and ABAC are the same thing.
C) RBAC is based on the identity of the user, while ABAC is based on the
sensitivity of the resource.
D) RBAC and ABAC are both types of logical access control
C
Which of the following is an example of a technical control?
A) Incident response plan
B) Security awareness training
C) Firewall implementation
D) Security policy
C
Which of the following is a common type of network load balancer?
A) All of the above
B) Weighted round-robin
C) Round-robin
D) Least connections
A
Which of the following is an example of a BYOD policy?
A) Providing employees with company-owned devices for work
B) All of the above
C) Allowing employees to bring their own devices to work
,D) Requiring employees to use only company-owned devices
C
Which principle of the CIA Triad ensures that information is accurate, complete,
and trustworthy?
A) Authentication
B) Integrity
C) Availability
D) Confidentiality
B
Which of the following is an example of social engineering?
A) A brute force attack
B) A SQL injection attack
C) A phishing email
D) A DDoS attack
C
Which of the following is a best practice for security awareness training?
A) Providing training only once a year
B) None of the above
C) Providing the same training to all employees
D) Making training sessions mandatory for all employees
D
Why is off-site data backup an important consideration in disaster recovery?
A) It eliminates the need for data recovery procedures
B) It minimizes the risk of data breaches during a disruption
C) It provides physical security for data centers
D) It ensures business continuity in case of a local site failure
, D
What is the difference between a vulnerability scan and a penetration test?
A) A vulnerability scan is a less comprehensive security assessment that only looks
for known vulnerabilities, while a penetration test is a more comprehensive
assessment that tries to simulate a real-world attack.
B) A vulnerability scan and a penetration test are both types of logical access
control.
C) A vulnerability scan and a penetration test are the same thing.
D) A vulnerability scan is a comprehensive security assessment that tests all
aspects of a network, while a penetration test is a less comprehensive assessment
that only focuses on specific vulnerabilities.
A
What is the primary purpose of a network intrusion detection system (IDS)?
A) To prevent network attacks
B) To remove malware from a network
C) To detect network attacks
D) To improve network performance
C
Which of the following is a best practice for securing web applications?
A) Using a weak password for the web application
B) Regularly applying security patches and updates
C) Allowing users to upload files without validation
D) None of the above
B
What is the primary purpose of a network demilitarized zone (DMZ)?
A) To remove malware from a network
B) To monitor network traffic
QUESTIONS AND 100% CORRECT ANSWERS (A+) 2025
What is the difference between role-based access control (RBAC) and attribute-
based access control (ABAC)?
A) RBAC is based on the sensitivity of the resource, while ABAC is based on the
identity of the user.
B) RBAC and ABAC are the same thing.
C) RBAC is based on the identity of the user, while ABAC is based on the
sensitivity of the resource.
D) RBAC and ABAC are both types of logical access control
C
Which of the following is an example of a technical control?
A) Incident response plan
B) Security awareness training
C) Firewall implementation
D) Security policy
C
Which of the following is a common type of network load balancer?
A) All of the above
B) Weighted round-robin
C) Round-robin
D) Least connections
A
Which of the following is an example of a BYOD policy?
A) Providing employees with company-owned devices for work
B) All of the above
C) Allowing employees to bring their own devices to work
,D) Requiring employees to use only company-owned devices
C
Which principle of the CIA Triad ensures that information is accurate, complete,
and trustworthy?
A) Authentication
B) Integrity
C) Availability
D) Confidentiality
B
Which of the following is an example of social engineering?
A) A brute force attack
B) A SQL injection attack
C) A phishing email
D) A DDoS attack
C
Which of the following is a best practice for security awareness training?
A) Providing training only once a year
B) None of the above
C) Providing the same training to all employees
D) Making training sessions mandatory for all employees
D
Why is off-site data backup an important consideration in disaster recovery?
A) It eliminates the need for data recovery procedures
B) It minimizes the risk of data breaches during a disruption
C) It provides physical security for data centers
D) It ensures business continuity in case of a local site failure
, D
What is the difference between a vulnerability scan and a penetration test?
A) A vulnerability scan is a less comprehensive security assessment that only looks
for known vulnerabilities, while a penetration test is a more comprehensive
assessment that tries to simulate a real-world attack.
B) A vulnerability scan and a penetration test are both types of logical access
control.
C) A vulnerability scan and a penetration test are the same thing.
D) A vulnerability scan is a comprehensive security assessment that tests all
aspects of a network, while a penetration test is a less comprehensive assessment
that only focuses on specific vulnerabilities.
A
What is the primary purpose of a network intrusion detection system (IDS)?
A) To prevent network attacks
B) To remove malware from a network
C) To detect network attacks
D) To improve network performance
C
Which of the following is a best practice for securing web applications?
A) Using a weak password for the web application
B) Regularly applying security patches and updates
C) Allowing users to upload files without validation
D) None of the above
B
What is the primary purpose of a network demilitarized zone (DMZ)?
A) To remove malware from a network
B) To monitor network traffic