ISC2 CERTIFIED IN CYBERSECURITY (CC) PRACTICE EXAMINATION | STUDY
GUIDE | LATEST UPDATE 2026/2027 | ACTUAL EXAM | PRACTICE QUESTIONS
AND ANSWERS | EXAM REVIEW | 100% CORRECT ANSWERS | VERIFIED
SOLUTIONS
This comprehensive practice examination is designed for entry-level cybersecurity professionals
and career changers preparing for the ISC2 Certified in Cybersecurity (CC) certification. This
foundational credential validates knowledge across five essential security domains: Security
Principles, Business Continuity and Disaster Recovery, Access Controls, Network Security, and
Security Operations. Each question has been developed to reflect the appropriate cognitive level
for this entry-level certification, providing a stepping stone to more advanced credentials like the
CISSP. Candidates will engage with scenarios covering fundamental security concepts, risk
management basics, network security principles, access control fundamentals, and incident
response procedures. By working through these 100 verified questions with detailed answer
rationales, you will build the foundational knowledge and test-taking confidence required for
success on the CC examination and establish a solid base for your cybersecurity career.
Table of Contents
Domain 1: Security Principles
Domain 2: Business Continuity and Disaster Recovery
Domain 3: Access Controls Concepts
Domain 4: Network Security
Domain 5: Security Operations
,DOMAIN 1: SECURITY PRINCIPLES
Question 1
Which of the following best describes the CIA triad in information security?
A) Central Intelligence Agency requirements
B) Confidentiality, Integrity, and Availability - the three core principles of information security
C) Computer, Internet, and Application security
D) Control, Investigation, and Audit functions
Correct Answer: B
The CIA triad represents the three fundamental security objectives. Confidentiality ensures data
is accessible only to authorized parties. Integrity ensures data is accurate and unmodified.
Availability ensures data and systems are accessible when needed. This is the foundational
concept in information security.
Question 2
Which of the following is an example of a preventive security control?
A) Reviewing security logs after an incident
B) A firewall that blocks unauthorized network traffic
C) A security camera recording events
D) An incident response report
Correct Answer: B
Preventive controls stop security incidents before they occur. A firewall blocking unauthorized
traffic prevents attacks. Log review (A) and security cameras (C) are detective controls that
identify incidents. Incident reports (D) are corrective or documentation controls.
Question 3
What does the principle of least privilege require?
A) All users should have maximum access to perform their jobs
B) Users should be granted only the minimum access necessary to perform their job functions
C) All users should have the same access level
D) Access should never be revoked
,Correct Answer: B
Least privilege limits access rights to what is needed for authorized tasks. This reduces damage
from errors, compromised accounts, or insider threats. It is a fundamental security principle
applicable to users, processes, and systems.
Question 4
Which of the following best describes a threat in information security?
A) A weakness in a system
B) Any potential danger that could exploit a vulnerability to cause harm
C) A security control
D) A security policy
Correct Answer: B
A threat is any circumstance or event with the potential to cause harm. A vulnerability (A) is a
weakness. Threat actors (hackers, malware, natural disasters) exploit vulnerabilities. Risk is the
combination of threat, vulnerability, and impact.
Question 5
What is the primary purpose of a security policy in an organization?
A) To provide step-by-step technical instructions
B) To establish management's expectations and requirements for information security
C) To configure security tools
D) To replace all security controls
Correct Answer: B
Security policies are high-level documents stating management's commitment and requirements.
They define what must be done and why. Procedures (A) provide step-by-step instructions.
Policies are the foundation of the security program.
Question 6
Which of the following is an example of a physical security control?
A) A password policy
B) A firewall
, C) A locked door with access card reader
D) Antivirus software
Correct Answer: C
Physical controls protect tangible assets and facilities. A locked door with card reader controls
physical access. Password policies (A) are administrative controls. Firewalls (B) and antivirus
(D) are technical controls. Security controls can be physical, technical, or administrative.
Question 7
What is the primary difference between a vulnerability and a threat?
A) They are the same thing
B) A vulnerability is a weakness; a threat is something that could exploit that weakness
C) A threat is always a person; a vulnerability is always technical
D) Vulnerabilities are more serious than threats
Correct Answer: B
A vulnerability is a weakness in a system, process, or control. A threat is a potential danger that
could exploit that vulnerability. For example, an unpatched system (vulnerability) could be
exploited by malware (threat). Understanding this distinction is fundamental to risk
management.
Question 8
What does the concept of defense in depth mean?
A) Using a single strong control to protect assets
B) Implementing multiple layers of different security controls so that if one fails, others provide
protection
C) Focusing all security on the perimeter
D) Relying only on encryption
Correct Answer: B
Defense in depth uses multiple, overlapping security controls. If one layer fails, others still
protect assets. For example: perimeter fence (physical), firewall (network), authentication
(logical), and encryption (data). This layered approach is more robust than relying on a single
control.
GUIDE | LATEST UPDATE 2026/2027 | ACTUAL EXAM | PRACTICE QUESTIONS
AND ANSWERS | EXAM REVIEW | 100% CORRECT ANSWERS | VERIFIED
SOLUTIONS
This comprehensive practice examination is designed for entry-level cybersecurity professionals
and career changers preparing for the ISC2 Certified in Cybersecurity (CC) certification. This
foundational credential validates knowledge across five essential security domains: Security
Principles, Business Continuity and Disaster Recovery, Access Controls, Network Security, and
Security Operations. Each question has been developed to reflect the appropriate cognitive level
for this entry-level certification, providing a stepping stone to more advanced credentials like the
CISSP. Candidates will engage with scenarios covering fundamental security concepts, risk
management basics, network security principles, access control fundamentals, and incident
response procedures. By working through these 100 verified questions with detailed answer
rationales, you will build the foundational knowledge and test-taking confidence required for
success on the CC examination and establish a solid base for your cybersecurity career.
Table of Contents
Domain 1: Security Principles
Domain 2: Business Continuity and Disaster Recovery
Domain 3: Access Controls Concepts
Domain 4: Network Security
Domain 5: Security Operations
,DOMAIN 1: SECURITY PRINCIPLES
Question 1
Which of the following best describes the CIA triad in information security?
A) Central Intelligence Agency requirements
B) Confidentiality, Integrity, and Availability - the three core principles of information security
C) Computer, Internet, and Application security
D) Control, Investigation, and Audit functions
Correct Answer: B
The CIA triad represents the three fundamental security objectives. Confidentiality ensures data
is accessible only to authorized parties. Integrity ensures data is accurate and unmodified.
Availability ensures data and systems are accessible when needed. This is the foundational
concept in information security.
Question 2
Which of the following is an example of a preventive security control?
A) Reviewing security logs after an incident
B) A firewall that blocks unauthorized network traffic
C) A security camera recording events
D) An incident response report
Correct Answer: B
Preventive controls stop security incidents before they occur. A firewall blocking unauthorized
traffic prevents attacks. Log review (A) and security cameras (C) are detective controls that
identify incidents. Incident reports (D) are corrective or documentation controls.
Question 3
What does the principle of least privilege require?
A) All users should have maximum access to perform their jobs
B) Users should be granted only the minimum access necessary to perform their job functions
C) All users should have the same access level
D) Access should never be revoked
,Correct Answer: B
Least privilege limits access rights to what is needed for authorized tasks. This reduces damage
from errors, compromised accounts, or insider threats. It is a fundamental security principle
applicable to users, processes, and systems.
Question 4
Which of the following best describes a threat in information security?
A) A weakness in a system
B) Any potential danger that could exploit a vulnerability to cause harm
C) A security control
D) A security policy
Correct Answer: B
A threat is any circumstance or event with the potential to cause harm. A vulnerability (A) is a
weakness. Threat actors (hackers, malware, natural disasters) exploit vulnerabilities. Risk is the
combination of threat, vulnerability, and impact.
Question 5
What is the primary purpose of a security policy in an organization?
A) To provide step-by-step technical instructions
B) To establish management's expectations and requirements for information security
C) To configure security tools
D) To replace all security controls
Correct Answer: B
Security policies are high-level documents stating management's commitment and requirements.
They define what must be done and why. Procedures (A) provide step-by-step instructions.
Policies are the foundation of the security program.
Question 6
Which of the following is an example of a physical security control?
A) A password policy
B) A firewall
, C) A locked door with access card reader
D) Antivirus software
Correct Answer: C
Physical controls protect tangible assets and facilities. A locked door with card reader controls
physical access. Password policies (A) are administrative controls. Firewalls (B) and antivirus
(D) are technical controls. Security controls can be physical, technical, or administrative.
Question 7
What is the primary difference between a vulnerability and a threat?
A) They are the same thing
B) A vulnerability is a weakness; a threat is something that could exploit that weakness
C) A threat is always a person; a vulnerability is always technical
D) Vulnerabilities are more serious than threats
Correct Answer: B
A vulnerability is a weakness in a system, process, or control. A threat is a potential danger that
could exploit that vulnerability. For example, an unpatched system (vulnerability) could be
exploited by malware (threat). Understanding this distinction is fundamental to risk
management.
Question 8
What does the concept of defense in depth mean?
A) Using a single strong control to protect assets
B) Implementing multiple layers of different security controls so that if one fails, others provide
protection
C) Focusing all security on the perimeter
D) Relying only on encryption
Correct Answer: B
Defense in depth uses multiple, overlapping security controls. If one layer fails, others still
protect assets. For example: perimeter fence (physical), firewall (network), authentication
(logical), and encryption (data). This layered approach is more robust than relying on a single
control.