ISC2 CERTIFIED IN CYBERSECURITY (CC) MOCK EXAMINATION | STUDY
GUIDE | LATEST UPDATE 2026/2027 | ACTUAL EXAM | PRACTICE QUESTIONS
AND ANSWERS | EXAM REVIEW | 100% CORRECT ANSWERS | VERIFIED
SOLUTIONS
This mock examination is designed for entry-level cybersecurity professionals and career
changers preparing for the ISC2 Certified in Cybersecurity (CC) credential. This foundational
certification validates knowledge across five essential security domains and serves as the ideal
starting point for a career in information security. This 100-question mock exam simulates the
format and cognitive level of the actual CC examination, with questions distributed across
Security Principles, Business Continuity and Disaster Recovery, Access Controls, Network
Security, and Security Operations. Each question includes a comprehensive rationale explaining
the correct answer and why alternatives are incorrect. By completing this mock examination
under timed conditions and reviewing the detailed answer rationales, candidates will assess
their readiness, identify knowledge gaps, and build the confidence necessary for first-attempt
success on the CC certification examination.
Table of Contents
Domain 1: Security Principles (Questions 1-22)
Domain 2: Business Continuity and Disaster Recovery (Questions 23-38)
Domain 3: Access Controls Concepts (Questions 39-58)
Domain 4: Network Security (Questions 59-78)
Domain 5: Security Operations (Questions 79-100)
,DOMAIN 1: SECURITY PRINCIPLES
Question 1
An organization's security team has implemented multiple controls including firewalls, intrusion
detection systems, security awareness training, and encryption. What security principle is
demonstrated by using these different types of controls together?
A) Least privilege
B) Separation of duties
C) Defense in depth
D) Fail-safe defaults
Correct Answer: C
Defense in depth uses multiple, overlapping layers of security controls (technical, administrative,
physical). If one control fails, others provide continuing protection. The scenario describes
firewalls (technical), IDS (technical/detective), training (administrative), and encryption
(technical)—a layered approach. Least privilege (A) limits access rights. Separation of duties
(B) divides responsibilities. Fail-safe defaults (D) deny by default.
Question 2
Which of the following correctly identifies the three components of the CIA triad?
A) Control, Integrity, Authentication
B) Confidentiality, Integrity, Availability
C) Certification, Investigation, Assessment
D) Compliance, Identification, Authorization
Correct Answer: B
The CIA triad is the foundation of information security. Confidentiality protects data from
unauthorized disclosure. Integrity protects data from unauthorized modification. Availability
ensures data is accessible when needed by authorized users. These three principles guide all
security decisions and control implementations.
Question 3
A financial services company discovers that an employee modified transaction records to hide
,fraudulent activity. Which principle of the CIA triad was directly violated?
A) Confidentiality
B) Integrity
C) Availability
D) Authentication
Correct Answer: B
Integrity ensures data accuracy and protection from unauthorized modification. The employee's
unauthorized modification of transaction records violates integrity. Confidentiality (A) involves
unauthorized disclosure. Availability (C) involves access to systems. Authentication (D) verifies
identity and is not part of the CIA triad.
Question 4
What is the primary difference between a vulnerability and a threat?
A) They are identical concepts
B) A vulnerability is a weakness; a threat is a potential danger that could exploit that weakness
C) A threat is always internal; a vulnerability is always external
D) Vulnerabilities only apply to software; threats only apply to people
Correct Answer: B
A vulnerability is a gap or weakness in security controls (unpatched software, weak passwords,
misconfigured firewalls). A threat is any potential danger (malware, hackers, natural disasters,
human error) that could exploit a vulnerability. For example, an unpatched server
(vulnerability) could be exploited by ransomware (threat).
Question 5
An organization installs a security camera system that records all activity in the server room. The
footage is stored for 90 days and reviewed after any suspected incident. How should the security
cameras be classified as a control?
A) Preventive control
B) Detective control
C) Corrective control
D) Deterrent control
, Correct Answer: B
Detective controls identify and record events after they occur. Security cameras record activity
for later review, making them detective controls. While cameras may also deter (D) potential
wrongdoers, their primary function described in the scenario is detection through recording.
Preventive controls (A) stop actions before they occur. Corrective controls (C) remedy after
detection.
Question 6
What does the principle of least privilege require?
A) All employees should have administrator access to their workstations
B) Users should be granted only the minimum access necessary to perform their job functions
C) Access should be based on the employee's length of service
D) All users in the same department should have identical access rights
Correct Answer: B
Least privilege limits access to the minimum needed for authorized tasks. This reduces potential
damage from errors, compromised accounts, or malicious insiders. Administrator access (A) for
all users violates this principle. Access should be based on job requirements, not tenure (C) or
department alone (D).
Question 7
A healthcare organization encrypts all patient records stored in its database. Even if an attacker
gains access to the database files, they cannot read the patient information. Which security
principle is being applied?
A) Availability
B) Integrity
C) Confidentiality
D) Non-repudiation
Correct Answer: C
Encryption protects confidentiality by making data unreadable without the proper key. Even
though the attacker accessed the files, the encryption prevented disclosure of the patient
information. Availability (A) ensures access for authorized users. Integrity (B) prevents
modification. Non-repudiation (D) proves who performed an action.
GUIDE | LATEST UPDATE 2026/2027 | ACTUAL EXAM | PRACTICE QUESTIONS
AND ANSWERS | EXAM REVIEW | 100% CORRECT ANSWERS | VERIFIED
SOLUTIONS
This mock examination is designed for entry-level cybersecurity professionals and career
changers preparing for the ISC2 Certified in Cybersecurity (CC) credential. This foundational
certification validates knowledge across five essential security domains and serves as the ideal
starting point for a career in information security. This 100-question mock exam simulates the
format and cognitive level of the actual CC examination, with questions distributed across
Security Principles, Business Continuity and Disaster Recovery, Access Controls, Network
Security, and Security Operations. Each question includes a comprehensive rationale explaining
the correct answer and why alternatives are incorrect. By completing this mock examination
under timed conditions and reviewing the detailed answer rationales, candidates will assess
their readiness, identify knowledge gaps, and build the confidence necessary for first-attempt
success on the CC certification examination.
Table of Contents
Domain 1: Security Principles (Questions 1-22)
Domain 2: Business Continuity and Disaster Recovery (Questions 23-38)
Domain 3: Access Controls Concepts (Questions 39-58)
Domain 4: Network Security (Questions 59-78)
Domain 5: Security Operations (Questions 79-100)
,DOMAIN 1: SECURITY PRINCIPLES
Question 1
An organization's security team has implemented multiple controls including firewalls, intrusion
detection systems, security awareness training, and encryption. What security principle is
demonstrated by using these different types of controls together?
A) Least privilege
B) Separation of duties
C) Defense in depth
D) Fail-safe defaults
Correct Answer: C
Defense in depth uses multiple, overlapping layers of security controls (technical, administrative,
physical). If one control fails, others provide continuing protection. The scenario describes
firewalls (technical), IDS (technical/detective), training (administrative), and encryption
(technical)—a layered approach. Least privilege (A) limits access rights. Separation of duties
(B) divides responsibilities. Fail-safe defaults (D) deny by default.
Question 2
Which of the following correctly identifies the three components of the CIA triad?
A) Control, Integrity, Authentication
B) Confidentiality, Integrity, Availability
C) Certification, Investigation, Assessment
D) Compliance, Identification, Authorization
Correct Answer: B
The CIA triad is the foundation of information security. Confidentiality protects data from
unauthorized disclosure. Integrity protects data from unauthorized modification. Availability
ensures data is accessible when needed by authorized users. These three principles guide all
security decisions and control implementations.
Question 3
A financial services company discovers that an employee modified transaction records to hide
,fraudulent activity. Which principle of the CIA triad was directly violated?
A) Confidentiality
B) Integrity
C) Availability
D) Authentication
Correct Answer: B
Integrity ensures data accuracy and protection from unauthorized modification. The employee's
unauthorized modification of transaction records violates integrity. Confidentiality (A) involves
unauthorized disclosure. Availability (C) involves access to systems. Authentication (D) verifies
identity and is not part of the CIA triad.
Question 4
What is the primary difference between a vulnerability and a threat?
A) They are identical concepts
B) A vulnerability is a weakness; a threat is a potential danger that could exploit that weakness
C) A threat is always internal; a vulnerability is always external
D) Vulnerabilities only apply to software; threats only apply to people
Correct Answer: B
A vulnerability is a gap or weakness in security controls (unpatched software, weak passwords,
misconfigured firewalls). A threat is any potential danger (malware, hackers, natural disasters,
human error) that could exploit a vulnerability. For example, an unpatched server
(vulnerability) could be exploited by ransomware (threat).
Question 5
An organization installs a security camera system that records all activity in the server room. The
footage is stored for 90 days and reviewed after any suspected incident. How should the security
cameras be classified as a control?
A) Preventive control
B) Detective control
C) Corrective control
D) Deterrent control
, Correct Answer: B
Detective controls identify and record events after they occur. Security cameras record activity
for later review, making them detective controls. While cameras may also deter (D) potential
wrongdoers, their primary function described in the scenario is detection through recording.
Preventive controls (A) stop actions before they occur. Corrective controls (C) remedy after
detection.
Question 6
What does the principle of least privilege require?
A) All employees should have administrator access to their workstations
B) Users should be granted only the minimum access necessary to perform their job functions
C) Access should be based on the employee's length of service
D) All users in the same department should have identical access rights
Correct Answer: B
Least privilege limits access to the minimum needed for authorized tasks. This reduces potential
damage from errors, compromised accounts, or malicious insiders. Administrator access (A) for
all users violates this principle. Access should be based on job requirements, not tenure (C) or
department alone (D).
Question 7
A healthcare organization encrypts all patient records stored in its database. Even if an attacker
gains access to the database files, they cannot read the patient information. Which security
principle is being applied?
A) Availability
B) Integrity
C) Confidentiality
D) Non-repudiation
Correct Answer: C
Encryption protects confidentiality by making data unreadable without the proper key. Even
though the attacker accessed the files, the encryption prevented disclosure of the patient
information. Availability (A) ensures access for authorized users. Integrity (B) prevents
modification. Non-repudiation (D) proves who performed an action.