1 | Page
ISC2 CERTIFIED IN CYBERSECURITY (CC)
ACTUAL EXAM 2026/2027 QUESTIONS
WITH VERIFIED ANSWERS & COMPLETE
RATIONALES
**1. A web server runs an unpatched library with a known
remote code execution flaw. Attack groups are actively
scanning for it. The server holds payment records. Which term
describes the unpatched library?**
A. Threat
B. Vulnerability
C. Risk
D. Asset
**Correct answer:** B
**Rationale:** A vulnerability is a weakness that can be
exploited. The attack groups are the threat, the payment
records and server are assets, and the risk is the combination
of the likelihood of exploitation and the impact if it happens .
---
,2 | Page
**2. A company installs a visible warning sign stating that an
area is under camera surveillance. What control function is the
sign?**
A. Preventive
B. Detective
C. Deterrent
D. Corrective
**Correct answer:** C
**Rationale:** A sign discourages an attempt without physically
stopping it, which is the definition of a deterrent. The camera
recording is detective; a lock would be preventive; restoring
from backup would be corrective .
---
**3. An organization buys cyber insurance to cover the financial
consequence of a breach it cannot fully prevent. Which risk
treatment is this?**
A. Avoid
B. Mitigate
C. Transfer
D. Accept
, 3 | Page
**Correct answer:** C
**Rationale:** Transfer moves the financial consequence to
another party. Avoid means stopping the activity, mitigate
means applying controls to reduce likelihood or impact, and
accept means documenting and taking no further action .
---
**4. A government system labels documents Secret and Top
Secret, and the system enforces clearance levels that users
cannot override. Which access control model is this?**
A. DAC
B. MAC
C. RBAC
D. ABAC
**Correct answer:** B
**Rationale:** Mandatory access control (MAC) is system-
enforced from labels and clearances, and users cannot change
it. DAC lets the data owner decide, RBAC attaches permissions
to roles, and ABAC evaluates attributes at access time .
ISC2 CERTIFIED IN CYBERSECURITY (CC)
ACTUAL EXAM 2026/2027 QUESTIONS
WITH VERIFIED ANSWERS & COMPLETE
RATIONALES
**1. A web server runs an unpatched library with a known
remote code execution flaw. Attack groups are actively
scanning for it. The server holds payment records. Which term
describes the unpatched library?**
A. Threat
B. Vulnerability
C. Risk
D. Asset
**Correct answer:** B
**Rationale:** A vulnerability is a weakness that can be
exploited. The attack groups are the threat, the payment
records and server are assets, and the risk is the combination
of the likelihood of exploitation and the impact if it happens .
---
,2 | Page
**2. A company installs a visible warning sign stating that an
area is under camera surveillance. What control function is the
sign?**
A. Preventive
B. Detective
C. Deterrent
D. Corrective
**Correct answer:** C
**Rationale:** A sign discourages an attempt without physically
stopping it, which is the definition of a deterrent. The camera
recording is detective; a lock would be preventive; restoring
from backup would be corrective .
---
**3. An organization buys cyber insurance to cover the financial
consequence of a breach it cannot fully prevent. Which risk
treatment is this?**
A. Avoid
B. Mitigate
C. Transfer
D. Accept
, 3 | Page
**Correct answer:** C
**Rationale:** Transfer moves the financial consequence to
another party. Avoid means stopping the activity, mitigate
means applying controls to reduce likelihood or impact, and
accept means documenting and taking no further action .
---
**4. A government system labels documents Secret and Top
Secret, and the system enforces clearance levels that users
cannot override. Which access control model is this?**
A. DAC
B. MAC
C. RBAC
D. ABAC
**Correct answer:** B
**Rationale:** Mandatory access control (MAC) is system-
enforced from labels and clearances, and users cannot change
it. DAC lets the data owner decide, RBAC attaches permissions
to roles, and ABAC evaluates attributes at access time .