Free Practice Questions for ISC2 Certified in Cybersecurity (CC) Certification

    🔄 Last checked for updates July 3rd, 2026

    Study with 337 exam-style practice questions designed to help you prepare for the ISC2 Certified in Cybersecurity (CC). All questions are aligned with the latest exam guide and include detailed explanations to help you master the material.

    Start Practicing

    All Domains

    Practice with randomly mixed questions from all topics

    Question MixAll Topics
    FormatRandom Order

    Domain Mode

    Practice questions from a specific topic area

    Quiz History

    Exam Details

    Key information about ISC2 Certified in Cybersecurity (CC)

    Official study guide

    View

    Question formats CertSafari offers
    • Multiple choice
    • Matching
    language:

    English, Chinese, Japanese, German, Spanish

    exam format:

    Multiple choice and advanced item types, Computerized Adaptive Testing (CAT)

    passing score:

    700 out of 1000 points

    prerequisites:

    Basic IT knowledge recommended; no formal prerequisites or work experience.

    delivery method:

    Pearson VUE Testing Center

    target audience:

    Individuals seeking entry- or junior-level cybersecurity roles.

    time limit minutes:

    120

    number of questions:

    100 - 125

    Exam Topics & Skills Assessed

    Skills measured (from the official study guide)

    Domain 1: Security Principles

    Subdomain 1.1: Understand the security concepts of information assurance

    Confidentiality Integrity Availability Authentication (e.g., methods of authentication, multi-factor authentication (MFA)) Non-repudiation Privacy

    Subdomain 1.2: Understand the risk management process

    Risk management (e.g., risk priorities, risk tolerance) Risk identification, assessment and treatment

    Subdomain 1.3: Understand security controls

    Technical controls Administrative controls Physical controls

    Subdomain 1.4: Understand ISC2 Code of Ethics

    Professional code of conduct

    Subdomain 1.5: Understand governance processes

    Policies Procedures Standards Regulations and laws

    Domain 2: Business Continuity (BC), Disaster Recovery (DR) & Incident Response Concepts

    Subdomain 2.1: Understand business continuity (BC)

    Purpose Importance Components

    Subdomain 2.2: Understand disaster recovery (DR)

    Purpose Importance Components

    Subdomain 2.3: Understand incident response

    Purpose Importance Components

    Domain 3: Access Controls Concepts

    Subdomain 3.1: Understand physical access controls

    Physical security controls (e.g., badge systems, gate entry, environmental design) Monitoring (e.g., security guards, closed-circuit television (CCTV), alarm systems, logs) Authorized versus unauthorized personnel

    Subdomain 3.2: Understand logical access controls

    Principle of least privilege Segregation of duties Discretionary access control (DAC) Mandatory access control (MAC) Role-based access control (RBAC)

    Domain 4: Network Security

    Subdomain 4.1: Understand computer networking

    Networks (e.g., Open Systems Interconnection (OSI) model, Transmission Control Protocol/Internet Protocol (TCP/IP) model, Internet Protocol version 4 (IPv4), Internet Protocol version 6 (IPv6), WiFi) Ports Applications

    Subdomain 4.2: Understand network threats and attacks

    Types of threats (e.g., distributed denial-of-service (DDoS), virus, worm, Trojan, man-in-the-middle (MITM), side-channel) Identification (e.g., intrusion detection system (IDS), host-based intrusion detection system (HIDS), network intrusion detection system (NIDS)) Prevention (e.g., antivirus, scans, firewalls, intrusion prevention system (IPS))

    Subdomain 4.3: Understand network security infrastructure

    On-premises (e.g., power, data center/closets, Heating, Ventilation, and Air Conditioning (HVAC), environmental, fire suppression, redundancy, memorandum of understanding (MOU)/memorandum of agreement (MOA)) Design (e.g., network segmentation (demilitarized zone (DMZ), virtual local area network (VLAN), virtual private network (VPN), micro-segmentation), defense in depth, Network Access Control (NAC) (segmentation for embedded systems, Internet of Things (IoT))) Cloud (e.g., service-level agreement (SLA), managed service provider (MSP), Software as a Service (SaaS), Infrastructure as a Service (IaaS), Platform as a Service (PaaS), hybrid)

    Domain 5: Security Operations

    Subdomain 5.1: Understand data security

    Encryption (e.g., symmetric, asymmetric, hashing) Data handling (e.g., destruction, retention, classification, labeling) Logging and monitoring security events

    Subdomain 5.2: Understand system hardening

    Configuration management (e.g., baselines, updates, patches)

    Subdomain 5.3: Understand best practice security policies

    Data handling policy Password policy Acceptable Use Policy (AUP) Bring your own device (BYOD) policy Change management policy (e.g., documentation, approval, rollback) Privacy policy

    Subdomain 5.4: Understand security awareness training

    Purpose/concepts (e.g., social engineering, password protection) Importance

    Techniques & products

    Confidentiality
    Integrity
    Availability
    Authentication
    Multi-factor authentication (MFA)
    Non-repudiation
    Privacy
    Risk management
    Risk identification
    Risk assessment
    Risk treatment
    Technical controls
    Administrative controls
    Physical controls
    ISC2 Code of Ethics
    Professional code of conduct
    Policies
    Procedures
    Standards
    Regulations
    Laws
    Business Continuity (BC)
    Disaster Recovery (DR)
    Incident Response
    Physical security controls
    Badge systems
    Gate entry
    Environmental design
    Security guards
    Closed-circuit television (CCTV)
    Alarm systems
    Logs
    Principle of least privilege
    Segregation of duties
    Discretionary access control (DAC)
    Mandatory access control (MAC)
    Role-based access control (RBAC)
    Computer networking
    OSI model
    TCP/IP model
    IPv4
    IPv6
    WiFi
    Ports
    Applications
    Network threats
    Distributed denial-of-service (DDoS)
    Virus
    Worm
    Trojan
    Man-in-the-middle (MITM)
    Side-channel attacks
    Intrusion detection system (IDS)
    Host-based intrusion detection system (HIDS)
    Network intrusion detection system (NIDS)
    Antivirus
    Scans
    Firewalls
    Intrusion prevention system (IPS)
    Network security infrastructure
    On-premises infrastructure
    Power
    Data center
    Closets
    HVAC
    Environmental controls
    Fire suppression
    Redundancy
    Memorandum of understanding (MOU)
    Memorandum of agreement (MOA)
    Network design
    Network segmentation
    Demilitarized zone (DMZ)
    Virtual local area network (VLAN)
    Virtual private network (VPN)
    Micro-segmentation
    Defense in depth
    Network Access Control (NAC)
    Embedded systems
    Internet of Things (IoT)
    Cloud security
    Service-level agreement (SLA)
    Managed service provider (MSP)
    Software as a Service (SaaS)
    Infrastructure as a Service (IaaS)
    Platform as a Service (PaaS)
    Hybrid cloud
    Data security
    Encryption
    Symmetric encryption
    Asymmetric encryption
    Hashing
    Data handling
    Data destruction
    Data retention
    Data classification
    Data labeling
    Logging
    Monitoring security events
    System hardening
    Configuration management
    Baselines
    Updates
    Patches
    Security policies
    Data handling policy
    Password policy
    Acceptable Use Policy (AUP)
    Bring your own device (BYOD) policy
    Change management policy
    Privacy policy
    Security awareness training
    Social engineering
    Password protection

    CertSafari is not affiliated with, endorsed by, or officially connected to (ISC)². Full disclaimer