(ISC)², 2025–2026 Complete Study Guide and Practice Questions
with Answers
Introduction:
This document covers the core domains of the (ISC)² Certified in
Cybersecurity (CC) certification, including security principles,
access control, risk management, incident response, business
continuity, disaster recovery, network security, cloud computing,
and data protection. It contains extensive practice questions with
detailed answers as well as key cybersecurity terminology and
definitions commonly tested on the CC exam.
The material is designed to support exam preparation by combining
theoretical concepts with realistic multiple-choice questions. It also
includes glossary-style explanations of important security
frameworks, controls, protocols, and governance concepts.
Exam Questions and Answers
Trina and Doug both work at Triffid, Inc. Doug is having
trouble logging into the network. Trina offers to log in for
Doug, using Trina's credentials, so that Doug can get some
work done.
What is the problem with this?
A. Doug is a bad person
B. If Trina logs in for Doug, then Doug will never be
encouraged to remember credential without assistance
C. Anything either of them do will be attributed to Trina
,D. It is against the law --- correct detailed answers ---C.
Anything either of them do will be attributed to Trina
Which of the following is a biometric access control
mechanism?
A. A badge reader
B. A copper key
C. A fence with razor on it
D. A door locked by a voiceprint identifier --- correct detailed
answers ---D. A door locked by a voiceprint identifier
Which of the following statements is true?
A. Logical access controls can protect the IT environment
perfectly; there is no reason to deploy any other controls.
B. Physical access controls can protect the IT environment
perfectly; there is no reason to deploy any other controls.
C. Administrative access controls can protect the IT
environment perfectly; there is no reason to deploy any other
controls.
D. It is best to use a blend of controls in order to provide
optimum security. --- correct detailed answers ---D. It is best
to use a blend of controls in order to provide optimum
security.
Which of the following would be considered a logical access
control?
A. An iris reader that allows an employee to enter a controlled
area.
,B. A fingerprint reader that allows an employee to enter a
controlled area.
C. A fingerprint reader that allows an employee to access a
laptop computer.
D. A chain attached to a laptop computer that connects it to
furniture so it cannot be taken. --- correct detailed answers --
-C. A fingerprint reader that allows an employee to access a
laptop computer.
Which of the following is probably most useful at the
perimeter of a property?
A. A safe
B. A fence
C. A data center
D. A centralized log storage facility --- correct detailed
answers ---B. A fence
Handel is a senior manager at Triffid, Inc., and is in charge of
implementing a new access control scheme for the company.
Handel wants to ensure that employees who are assigned to
new positions in the company do not retain whatever access
they had in their old positions. Which method should Handel
select?
A. Role-based access controls (RBAC)
B. Mandatory access controls (MAC)
C. Discretionary access controls (DAC)
D. Logging --- correct detailed answers ---A. Role-based
access controls (RBAC)
, Prina is a database manager. Prina is allowed to add new
users to the database, remove current users and create new
usage functions for the users. Prina is not allowed to read the
data in the fields of the database itself. This is an example of:
A. Role-based access controls (RBAC)
B. Mandatory access controls (MAC)
C. Discretionary access controls (DAC)
D. Alleviating threat access controls (ATAC) --- correct
detailed answers ---A. Role-based access controls (RBAC)
Gary is unable to log in to the production environment. Gary
tries three times and is then locked out of trying again for one
hour. Why?
A. Gary is being punished
B. The network is tired
C. Users remember their credentials if they are given time to
think about it
D. Gary's actions look like an attack --- correct detailed
answers ---D. Gary's actions look like an attack
Larry and Fern both work in the data center. In order to enter
the data center to begin their workday, they must both
present their own keys (which are different) to the key reader,
before the door to the data center opens.
Which security concept is being applied in this situation?
A. Defense in depth
B. Segregation of duties