CertSafari

    Free Practice Questions for ISC2 Certified in Cybersecurity (CC) Certification

    Exam guide version:
    October 1, 2025
    Guide checked for updates:
    18 Sep 2026
    Question bank created:
    3 Jul 2026
    Question bank last updated:
    11 Sep 2026

    Study with 337 exam-style practice questions designed to help you prepare for the ISC2 Certified in Cybersecurity (CC). All questions are aligned with the latest exam guide and include detailed explanations to help you master the material.

    Your progress

    Coverage
    Mastery
    Performance

    Start Practicing

    Start a quiz

    Practice with randomly mixed questions from all topics

    Question MixAll Topics
    FormatRandom Order

    Exam experiences

    Pass and fail outcomes from candidates who prepared here — advice, scores, and prep time.

    Your saved questions

    Open the list of questions you bookmarked during practice for this exam.

    Study notes

    Private notes per question, grouped by exam domain — opens on its own page, not inline on this overview.

    Quiz History

    Exam Details

    Key information about ISC2 Certified in Cybersecurity (CC)

    Official study guide

    View

    Question formats CertSafari offers
    • Multiple choice
    • Matching
    language:

    English, Chinese, Japanese, German, Spanish

    exam format:

    Multiple choice and advanced item types, Computerized Adaptive Testing (CAT)

    passing score:

    700 out of 1000 points

    prerequisites:

    Basic IT knowledge recommended; no formal prerequisites or work experience.

    delivery method:

    Pearson VUE Testing Center

    target audience:

    Individuals seeking entry- or junior-level cybersecurity roles.

    time limit minutes:

    120

    number of questions:

    100 - 125

    Exam Topics & Skills Assessed

    Skills measured (from the official study guide)

    1: Security Principles

    1.1: Understand the security concepts of information assurance

    1.2: Understand the risk management process

    1.3: Understand security controls

    1.4: Understand ISC2 Code of Ethics

    1.5: Understand governance processes

    2: Business Continuity (BC), Disaster Recovery (DR) & Incident Response Concepts

    2.1: Understand business continuity (BC)

    2.2: Understand disaster recovery (DR)

    2.3: Understand incident response

    3: Access Controls Concepts

    3.1: Understand physical access controls

    3.2: Understand logical access controls

    4: Network Security

    4.1: Understand computer networking

    4.2: Understand network threats and attacks

    4.3: Understand network security infrastructure

    5: Security Operations

    5.1: Understand data security

    5.2: Understand system hardening

    5.3: Understand best practice security policies

    5.4: Understand security awareness training

    Techniques & products

    Confidentiality
    Integrity
    Availability
    Authentication
    Multi-factor authentication (MFA)
    Non-repudiation
    Privacy
    Risk management
    Risk identification
    Risk assessment
    Risk treatment
    Technical controls
    Administrative controls
    Physical controls
    ISC2 Code of Ethics
    Professional code of conduct
    Policies
    Procedures
    Standards
    Regulations
    Laws
    Business Continuity (BC)
    Disaster Recovery (DR)
    Incident Response
    Physical security controls
    Badge systems
    Gate entry
    Environmental design
    Security guards
    Closed-circuit television (CCTV)
    Alarm systems
    Logs
    Principle of least privilege
    Segregation of duties
    Discretionary access control (DAC)
    Mandatory access control (MAC)
    Role-based access control (RBAC)
    Computer networking
    OSI model
    TCP/IP model
    IPv4
    IPv6
    WiFi
    Ports
    Applications
    Network threats
    Distributed denial-of-service (DDoS)
    Virus
    Worm
    Trojan
    Man-in-the-middle (MITM)
    Side-channel attacks
    Intrusion detection system (IDS)
    Host-based intrusion detection system (HIDS)
    Network intrusion detection system (NIDS)
    Antivirus
    Scans
    Firewalls
    Intrusion prevention system (IPS)
    Network security infrastructure
    On-premises infrastructure
    Power
    Data center
    Closets
    HVAC
    Environmental controls
    Fire suppression
    Redundancy
    Memorandum of understanding (MOU)
    Memorandum of agreement (MOA)
    Network design
    Network segmentation
    Demilitarized zone (DMZ)
    Virtual local area network (VLAN)
    Virtual private network (VPN)
    Micro-segmentation
    Defense in depth
    Network Access Control (NAC)
    Embedded systems
    Internet of Things (IoT)
    Cloud security
    Service-level agreement (SLA)
    Managed service provider (MSP)
    Software as a Service (SaaS)
    Infrastructure as a Service (IaaS)
    Platform as a Service (PaaS)
    Hybrid cloud
    Data security
    Encryption
    Symmetric encryption
    Asymmetric encryption
    Hashing
    Data handling
    Data destruction
    Data retention
    Data classification
    Data labeling
    Logging
    Monitoring security events
    System hardening
    Configuration management
    Baselines
    Updates
    Patches
    Security policies
    Data handling policy
    Password policy
    Acceptable Use Policy (AUP)
    Bring your own device (BYOD) policy
    Change management policy
    Privacy policy
    Security awareness training
    Social engineering
    Password protection

    CertSafari is not affiliated with, endorsed by, or officially connected to (ISC)². Full disclaimer