CertSafari

    Free ISC2 Certified in Cybersecurity (CC) Sample Questions

    35 free sample questions from our bank of 337+, covering every exam domain, with answers and detailed explanations. Updated August 2026.

    Domain 1: Security Principles

    Subdomain 1.3: Understand security controls

    1.Security awareness training programs are classified as which type of control?

    1. A.Technical control
    2. B.Administrative control
    3. C.Physical control
    4. D.Detective control
    Show answer & explanation

    Correct answer: BAdministrative control

    • A. Incorrect. Technical controls are implemented through hardware or software mechanisms such as firewalls, encryption, and access control systems. Security awareness training is not a technology-based safeguard.
    • B. Correct. Security awareness training is an administrative control because it is a policy- and people-based measure designed to influence user behavior and reduce risk. It helps ensure users understand security responsibilities and procedures.
    • C. Incorrect. Physical controls protect facilities and assets through tangible measures like locks, guards, and badges. Training does not directly protect the physical environment.
    • D. Incorrect. Detective controls are designed to identify and alert on incidents or suspicious activity after they occur, such as intrusion detection systems or audits. Training is a preventive and administrative measure, not primarily detective.

    Subdomain 1.3: Understand security controls

    2.To prevent laptops from being stolen from open office areas, which physical control should be deployed?

    1. A.Full disk encryption
    2. B.Cable locks
    3. C.Security awareness posters
    4. D.Antivirus software
    Show answer & explanation

    Correct answer: BCable locks

    • A. Incorrect. Full disk encryption is a technical/logical control that protects data confidentiality if a laptop is stolen, but it does not physically prevent the device from being taken.
    • B. Correct. Cable locks are a physical control that secures a laptop to a desk or fixed object, deterring opportunistic theft. This directly addresses physical theft in open office areas.
    • C. Incorrect. Security awareness posters are an administrative/awareness control that educates users, but they do not provide physical prevention of theft.
    • D. Incorrect. Antivirus software is a technical control that protects against malware, not against physical theft of devices.

    Subdomain 1.3: Understand security controls

    3.An organization stores backup data tapes at an off-site facility protected by fences, guards, and access controls. The off-site storage is primarily a:

    1. A.Technical control
    2. B.Physical control
    3. C.Administrative control
    4. D.Recovery control
    Show answer & explanation

    Correct answer: BPhysical control

    • A. Incorrect. Technical controls are technology-based mechanisms such as firewalls or encryption used to protect systems and data. Fences, guards, and access controls at a storage facility are not technical in nature.
    • B. Correct. Physical controls are tangible measures, including fences, guards, locks, and access controls, designed to protect physical assets and facilities. The off-site storage protections described are exemplars of physical controls.
    • C. Incorrect. Administrative controls encompass policies, procedures, and guidelines (e.g., security training, audits) that direct how security is managed. The listed protections are physical safeguards, not administrative.
    • D. Incorrect. Recovery controls are measures intended to restore systems or data after an incident, such as backups and disaster recovery plans. While the tapes support recovery, the facility protections (fences, guards, access controls) themselves are physical controls.

    Subdomain 1.4: Understand ISC2 Code of Ethics

    4.A coworker is observed scanning internal networks without apparent authorization. According to the ISC2 Code of Ethics, what is the most appropriate action?

    1. A.Confront the coworker and demand they cease the activity immediately.
    2. B.Report the observed behavior to management or an appropriate body.
    3. C.Disregard the observed behavior unless it results in harm to the organization.
    4. D.Send an anonymous tip to the administrators of the scanned networks.
    Show answer & explanation

    Correct answer: BReport the observed behavior to management or an appropriate body.

    • A. Incorrect. Directly confronting the coworker may escalate the situation and bypasses proper reporting channels. The ISC2 Code of Ethics emphasizes professionalism and using appropriate procedures to address potentially unauthorized activity.
    • B. Correct. Reporting the observed behavior to management or an appropriate body aligns with the ISC2 Code of Ethics, which requires acting in the best interest of the organization and the public. This ensures proper investigation and adherence to ethical standards.
    • C. Incorrect. Disregarding unethical behavior violates the ISC2 Code of Ethics, which mandates taking action to protect the organization and the public from harm. Professionals are expected to report or escalate concerns proactively.
    • D. Incorrect. Sending an anonymous tip bypasses internal processes and may not provide sufficient context or accountability. The Code of Ethics encourages transparency and reporting through authorized internal channels, especially when a coworker is involved.

    Subdomain 1.4: Understand ISC2 Code of Ethics

    5.During a security assessment, you discover a critical vulnerability that could expose customer data. What is the most ethical course of action according to the ISC2 Code of Ethics?

    1. A.Include discovery in the final report and proceed with the test plan.
    2. B.Immediately inform the client of the finding so they can take action.
    3. C.Anonymously alert the affected customers to protect their interests.
    4. D.Finish the test first, then disclose at the end to avoid disruption.
    Show answer & explanation

    Correct answer: BImmediately inform the client of the finding so they can take action.

    • A. Incorrect. While findings should be documented, delaying action by waiting until the final report does not align with the duty to protect the public and the organization. Immediate notification is often required for critical vulnerabilities to mitigate risk promptly.
    • B. Correct. The ISC2 Code of Ethics requires professionals to act honorably and protect society and the common good. Immediately informing the client through proper channels allows the organization to take swift action to mitigate the risk, fulfilling the ethical duty of responsible disclosure.
    • C. Incorrect. Anonymously alerting customers bypasses the client’s authority and can cause confusion, panic, or legal issues. Ethical security professionals should not independently disclose findings to third parties unless explicitly authorized or legally required.
    • D. Incorrect. Delaying disclosure until the end of the test could leave the client exposed to unnecessary risk if the vulnerability is significant. Ethical practice requires timely reporting of serious issues through proper channels rather than waiting to avoid disruption.

    Subdomain 1.4: Understand ISC2 Code of Ethics

    6.An ISC2 member discovers that a colleague has falsified reports to meet project deadlines. What is the most appropriate action according to the ISC2 Code of Ethics?

    1. A.Privately confront the colleague and demand they amend the reports.
    2. B.Disregard the issue to prevent project delays and protect the team.
    3. C.Report the violation to management or the appropriate authority.
    4. D.Assist in hiding the falsified data to ensure project completion.
    Show answer & explanation

    Correct answer: CReport the violation to management or the appropriate authority.

    • A. Incorrect. While confronting the colleague may seem helpful, demanding amendments privately is not the proper ethical resolution when falsification is clear. The ISC2 Code of Ethics requires reporting unethical behavior through appropriate channels, not informal confrontation.
    • B. Incorrect. Ignoring a known violation to avoid project delays conflicts with the ISC2 Code of Ethics, which mandates that professionals act in the public interest and report unethical or illegal activities. Protecting team comfort or timelines does not justify inaction.
    • C. Correct. Reporting the violation to management or the appropriate authority aligns with the ISC2 Code of Ethics, which requires professionals to report unethical, illegal, or suspicious activities. This promotes integrity, public trust, and accountability.
    • D. Incorrect. Assisting in hiding falsified data is a direct violation of the ISC2 Code of Ethics, which prohibits actions that could harm the public, the profession, or the organization. It also increases harm to stakeholders and undermines professional integrity.

    Domain 2: Business Continuity (BC), Disaster Recovery (DR) & Incident Response Concepts

    Subdomain 2.2: Understand disaster recovery (DR)

    7.What is the most effective method to verify the integrity and usability of backup data for disaster recovery?

    1. A.Implement a more frequent full backup schedule
    2. B.Perform periodic restoration tests of backup data
    3. C.Utilize cloud-based storage for backup archives
    4. D.Apply encryption to all backup media for security
    Show answer & explanation

    Correct answer: BPerform periodic restoration tests of backup data

    • A. Incorrect. Increasing backup frequency reduces data loss but does not validate that the backup data is intact or restorable. Without testing, backups may be corrupt or incomplete.
    • B. Correct. Periodic restoration tests directly validate that backup data can be successfully restored, proving both integrity and usability. Disaster recovery requires not just backups but assurance that restoration works within required timeframes.
    • C. Incorrect. Cloud storage improves resilience and offsite availability but does not verify backup integrity or restorability. Restoration testing is still needed to confirm recoverability.
    • D. Incorrect. Encryption protects confidentiality of backup data against unauthorized access but does not confirm that the data is intact or can be restored. It is a security control, not a validation method for disaster recovery.

    Subdomain 2.2: Understand disaster recovery (DR)

    8.What is the most effective way to ensure a hot site remains ready for immediate failover?

    1. A.Replace the hot site with a warm site to reduce operational expenses
    2. B.Use configuration management to keep the hot site synchronized
    3. C.Increase the frequency of data backups to the hot site location
    4. D.Switch to a cold site strategy to minimize configuration drift
    Show answer & explanation

    Correct answer: BUse configuration management to keep the hot site synchronized

    • A. Incorrect. Replacing a hot site with a warm site reduces costs but sacrifices immediate readiness, as warm sites require setup time before becoming operational.
    • B. Correct. Configuration management ensures the hot site remains synchronized with the primary site, maintaining consistency and readiness for rapid failover with minimal disruption.
    • C. Incorrect. Increasing backup frequency improves data currency but does not address synchronization of configurations, applications, or systems needed for immediate hot site operation.
    • D. Incorrect. Switching to a cold site eliminates immediate readiness, as cold sites require significant setup time and are not pre-configured for rapid recovery.

    Subdomain 2.2: Understand disaster recovery (DR)

    9.An organization has a Recovery Time Objective (RTO) of 4 hours. Which of the following is a reason why the organization might fail to meet this RTO?(Select 2)

    1. A.The RPO value is set too low, causing excessive data loss
    2. B.The warm site capability does not support the required RTO
    3. C.The backup data is corrupted and cannot be restored promptly
    4. D.The cold site was not prepared with the necessary hardware
    Show answer & explanation

    Correct answers: B, DThe warm site capability does not support the required RTO; The cold site was not prepared with the necessary hardware

    • A. Incorrect. The Recovery Point Objective (RPO) defines the maximum acceptable data loss, not the time to recover. A low RPO means less acceptable data loss and may increase backup frequency, but it does not directly impact the ability to meet the RTO.
    • B. Correct. A warm site is partially equipped and requires some setup before becoming fully operational. If the required RTO is aggressive, the warm site may not have the necessary resources to restore operations within that timeframe, causing a failure to meet the RTO.
    • C. Incorrect. While corrupted backup data can prevent successful restoration, this is primarily a data integrity issue related to RPO rather than a site capability issue. It would not typically be the reason for failing to meet the RTO based on site type.
    • D. Correct. A cold site has no pre-installed hardware or infrastructure. Setting up the necessary equipment takes significant time, often exceeding tight RTOs. This makes the cold site unsuitable for meeting short recovery time objectives.

    Subdomain 2.1: Understand business continuity (BC)

    10.Which metric defines the maximum acceptable amount of data loss measured in time?

    1. A.Recovery Point Objective (RPO)
    2. B.Recovery Time Objective (RTO)
    3. C.Service Level Agreement (SLA)
    4. D.Maximum Tolerable Downtime (MTD)
    Show answer & explanation

    Correct answer: ARecovery Point Objective (RPO)

    • A. Correct. Recovery Point Objective (RPO) defines the maximum acceptable amount of data loss measured in time, representing the point in time to which data must be recovered after a disruption.
    • B. Incorrect. Recovery Time Objective (RTO) defines the maximum acceptable time to restore a function or service after a disruption, not the amount of data loss.
    • C. Incorrect. Service Level Agreement (SLA) is a contractual agreement that defines expected service levels and responsibilities, but it does not specifically address data loss.
    • D. Incorrect. Maximum Tolerable Downtime (MTD) defines the total time a business process can be disrupted before causing unacceptable damage, not the amount of data loss.

    Subdomain 2.1: Understand business continuity (BC)

    11.Which activity is primarily used to identify and prioritize critical business functions and processes?

    1. A.Running a business impact analysis
    2. B.Performing a detailed risk assessment
    3. C.Reviewing supply chain continuity
    4. D.Evaluating vendor risk management
    Show answer & explanation

    Correct answer: ARunning a business impact analysis

    • A. Correct. A business impact analysis (BIA) is the primary activity for identifying and prioritizing critical business functions and processes. It assesses the potential impact of disruptions on business operations, determining recovery priorities and timeframes. While a BIA may not address all threats, its core purpose is to evaluate the effects of disruptions on critical functions.
    • B. Incorrect. A detailed risk assessment identifies threats, vulnerabilities, likelihood, and impact, but its focus is on evaluating risks rather than specifically identifying and prioritizing critical business functions. The BIA is the appropriate tool for that purpose.
    • C. Incorrect. Reviewing supply chain continuity is important for resilience, particularly for external dependencies, but it does not directly identify and prioritize internal critical business functions. It is a narrower activity within the broader continuity program.
    • D. Incorrect. Evaluating vendor risk management addresses risks from third-party vendors and is relevant to BC, but it is not the primary method for identifying and prioritizing critical business functions. That role belongs to the BIA.

    Subdomain 2.3: Understand incident response

    12.What is the primary goal of incident response?

    1. A.Identify the attacker and hold them accountable.
    2. B.Reduce damage and return to normal operations.
    3. C.Improve disaster recovery plan effectiveness.
    4. D.Comply with all relevant legal regulations.
    Show answer & explanation

    Correct answer: BReduce damage and return to normal operations.

    • A. Incorrect. While identifying the attacker may be part of the investigative process, the primary goal is incident containment and recovery, not attribution.
    • B. Correct. The primary goal of incident response is to contain the incident, minimize damage, and restore normal operations as quickly and safely as possible, thereby reducing business impact.
    • C. Incorrect. Improving disaster recovery plan effectiveness can be a secondary benefit from lessons learned, but incident response focuses on immediate containment and remediation, not plan improvement.
    • D. Incorrect. Compliance with legal regulations is important during incident handling, but the main objective is to mitigate the incident's impact and restore operations.

    Subdomain 2.3: Understand incident response

    13.Which of the following represents the correct sequence of the incident response lifecycle?

    1. A.Detection, Containment, Preparation, Eradication, Recovery, Lessons Learned
    2. B.Preparation, Containment, Detection, Eradication, Recovery, Lessons Learned
    3. C.Preparation, Detection, Containment, Eradication, Recovery, Lessons Learned
    4. D.Detection, Preparation, Containment, Recovery, Eradication, Lessons Learned
    Show answer & explanation

    Correct answer: CPreparation, Detection, Containment, Eradication, Recovery, Lessons Learned

    • A. Incorrect. The sequence should start with Preparation, not Detection. Preparation is a proactive phase that establishes policies, tools, and training before an incident occurs.
    • B. Incorrect. Containment should not occur before Detection. An incident must first be identified before containment can be applied. The correct sequence places Detection before Containment.
    • C. Correct. The standard incident response lifecycle is Preparation, Detection, Containment, Eradication, Recovery, and Lessons Learned. This sequence reflects readiness, identification, containment, removal of threat, restoration, and post-incident review.
    • D. Incorrect. Preparation should be the first phase, not Detection. Additionally, Eradication must occur before Recovery to ensure the root cause is removed before restoring normal operations.

    Subdomain 2.3: Understand incident response

    14.A company experiences a data breach involving personal information. Which group should be notified FIRST according to best practices?

    1. A.Notify the affected customers without delay.
    2. B.Issue a public statement via press release.
    3. C.Notify the legal and compliance teams first.
    4. D.Inform the police or data protection authorities.
    Show answer & explanation

    Correct answer: CNotify the legal and compliance teams first.

    • A. Incorrect. While notifying affected customers is important, it should not be the first step. Premature notification without internal coordination can lead to inaccurate information and may conflict with legal or regulatory obligations.
    • B. Incorrect. A public statement should only be issued after internal teams have assessed the situation and ensured accurate, controlled messaging. The organization should first involve internal legal/compliance stakeholders to assess obligations.
    • C. Correct. Legal and compliance teams must be notified first to assess regulatory obligations (e.g., GDPR, CCPA), potential liabilities, preservation of evidence, and mandatory reporting timelines. This ensures the organization responds appropriately and avoids mishandling the breach.
    • D. Incorrect. While authorities may need to be notified, this usually follows internal legal/compliance review. Best practice is to coordinate through the legal/compliance function first so notifications are accurate, timely, and compliant with applicable laws.

    Domain 3: Access Controls Concepts

    Subdomain 3.2: Understand logical access controls

    15.Which access control model grants permissions based on the roles and responsibilities of users within an organization?

    1. A.Mandatory access control
    2. B.Role-based access control
    3. C.Discretionary access control
    4. D.Principle of least privilege
    Show answer & explanation

    Correct answer: BRole-based access control

    • A. Incorrect. Mandatory access control (MAC) is a restrictive model where access decisions are based on system-enforced security labels and classifications, not on roles. It is commonly used in high-security environments and is not the best fit for permissions granted based on job function.
    • B. Correct. Role-based access control (RBAC) assigns permissions to roles, and users inherit access by being assigned to those roles. This is the standard model used when access is tied to job duties or responsibilities.
    • C. Incorrect. Discretionary access control (DAC) allows the resource owner to decide who can access an object, often using ACLs or permissions set by the owner. While flexible, it is not based on organizational roles.
    • D. Incorrect. The principle of least privilege is a security principle stating that users should have only the access necessary to perform their tasks. It is a guiding concept for access control design, but it is not itself a specific access control model like RBAC.

    Subdomain 3.2: Understand logical access controls

    16.Which access control model allows resource owners to determine who can access their resources?

    1. A.Discretionary access control
    2. B.Segregation of duties
    3. C.Mandatory access control
    4. D.Principle of least privilege
    Show answer & explanation

    Correct answer: ADiscretionary access control

    • A. Discretionary Access Control (DAC) is a model where the owner of a resource determines access permissions based on user identity. This allows resource owners to control who can access their resources.
    • B. Segregation of duties is a security principle that divides critical tasks among multiple people to reduce fraud and error, not an access control model.
    • C. Mandatory Access Control (MAC) uses system-enforced labels and classifications to control access, not owner discretion.
    • D. The principle of least privilege is a security guideline that users should have only the minimum access necessary, but it is not an access control model.

    Subdomain 3.2: Understand logical access controls

    17.Which of the following is an internal control principle designed to prevent fraud and errors by ensuring no single individual controls all critical steps of a process?

    1. A.Mandatory access control
    2. B.Segregation of duties
    3. C.Discretionary access control
    4. D.Role-based access control
    Show answer & explanation

    Correct answer: BSegregation of duties

    • A. Mandatory access control (MAC) is an access control model where system-enforced labels and classifications determine access based on user clearance and data sensitivity. It is not a principle for dividing responsibilities.
    • B. Segregation of duties is a preventive control principle that reduces the risk of fraud and error by splitting critical tasks among different individuals. This ensures that no single person has complete control over a process.
    • C. Discretionary access control (DAC) allows resource owners to set permissions at their discretion. It is about access assignment, not about separating responsibilities to prevent misuse.
    • D. Role-based access control (RBAC) grants permissions based on job roles. While it can help enforce segregation of duties, RBAC itself is a model for access management, not the principle of splitting duties.

    Domain 4: Network Security

    Subdomain 4.3: Understand network security infrastructure

    18.Which fire suppression system is most appropriate for protecting sensitive electronic equipment in a data center?

    1. A.A dry pipe sprinkler system that releases water only when a specific heat threshold is reached.
    2. B.A wet pipe sprinkler system with foam concentrate to accelerate fire extinguishing.
    3. C.A clean agent gas system that suppresses fire without residue and is safe for electronics.
    4. D.A carbon dioxide system that displaces oxygen to quickly extinguish fire in occupied spaces.
    Show answer & explanation

    Correct answer: CA clean agent gas system that suppresses fire without residue and is safe for electronics.

    • A. Incorrect. A dry pipe sprinkler system still uses water, which can damage sensitive electronic equipment. It is more suited to environments where pipes may freeze, not where water exposure must be minimized.
    • B. Incorrect. A wet pipe sprinkler system with foam concentrate introduces water and foam residue, which can damage electronics. Foam systems are typically used for flammable liquid fires, not data center equipment.
    • C. Correct. A clean agent gas system suppresses fire without leaving residue and is safe for electronics. It reduces the risk of damage to servers and other hardware while effectively extinguishing the fire, making it ideal for data centers.
    • D. Incorrect. Carbon dioxide systems extinguish fire by displacing oxygen, but they pose a risk of asphyxiation in occupied spaces. They are not the preferred choice for a data center with personnel present.

    Subdomain 4.3: Understand network security infrastructure

    19.Which security measure would be most effective for securing IoT devices on a corporate network?

    1. A.A virtual private network (VPN) to encrypt all traffic from the IoT devices.
    2. B.Network access control (NAC) with device profiling to enforce access policies.
    3. C.A demilitarized zone (DMZ) to place all IoT devices in a separate subnet.
    4. D.A micro-segmentation solution to create per-device firewall rules for each sensor.
    Show answer & explanation

    Correct answer: BNetwork access control (NAC) with device profiling to enforce access policies.

    • A. Incorrect. A VPN can encrypt traffic in transit, but it does not address whether IoT devices are authorized or enforce access policies. It adds complexity and may not be practical for constrained devices.
    • B. Correct. Network access control (NAC) with device profiling identifies IoT devices and enforces access policies based on device identity, type, behavior, or compliance. This directly addresses the challenge of unauthorized or unknown devices on the network.
    • C. Incorrect. A DMZ is designed to isolate public-facing services, not internal IoT devices. It does not provide device-specific control or dynamic access enforcement like NAC.
    • D. Incorrect. Micro-segmentation can restrict lateral movement but is complex to implement for large-scale IoT and does not directly address device authentication or initial access policy enforcement as effectively as NAC.

    Subdomain 4.3: Understand network security infrastructure

    20.Which cloud deployment model involves resources dedicated exclusively to a single organization?

    1. A.A public cloud deployment where all resources are hosted by a third-party provider.
    2. B.A private cloud deployment where cloud resources are dedicated exclusively to a single tenant.
    3. C.A hybrid cloud deployment combining on-premises and public cloud services.
    4. D.A community cloud deployment shared among several organizations with similar requirements.
    Show answer & explanation

    Correct answer: BA private cloud deployment where cloud resources are dedicated exclusively to a single tenant.

    • A. Incorrect. A public cloud deployment is hosted by a third-party provider and resources are typically shared among multiple tenants, not dedicated to a single organization.
    • B. Correct. A private cloud deployment is designed for exclusive use by one organization or tenant, with resources dedicated to that single entity, offering greater control and security.
    • C. Incorrect. A hybrid cloud combines on-premises and public cloud services but does not inherently mean resources are dedicated to a single tenant; it is defined by the mix of environments, not exclusivity.
    • D. Incorrect. A community cloud is shared among several organizations with common requirements, so its resources are not dedicated to a single tenant.

    Subdomain 4.2: Understand network threats and attacks

    21.Which detection method relies on a database of known attack signatures?

    1. A.Signature-based detection
    2. B.Anomaly-based detection
    3. C.Protocol state analysis
    4. D.Heuristic rule detection
    Show answer & explanation

    Correct answer: ASignature-based detection

    • A. Signature-based detection compares network traffic or system activity against a database of known attack signatures or patterns. It is effective for identifying known threats but cannot detect zero-day attacks.
    • B. Anomaly-based detection identifies deviations from normal behavior rather than relying on known attack patterns. It can detect new or unknown threats but may produce false positives.
    • C. Protocol state analysis examines the state of network protocols to detect deviations from expected behavior, such as malformed packets or unexpected sequences. It does not rely on a database of known attack patterns.
    • D. Heuristic rule detection uses predefined rules or logic to identify suspicious behavior, often based on patterns or thresholds. While it may use some form of pattern matching, it is not primarily based on a database of known attack signatures.

    Subdomain 4.2: Understand network threats and attacks

    22.Which network security device is designed to monitor network traffic for suspicious activity and generate alerts, without taking direct blocking action?

    1. A.A stateful inspection firewall
    2. B.An intrusion detection system
    3. C.An intrusion prevention system
    4. D.A web application firewall
    Show answer & explanation

    Correct answer: BAn intrusion detection system

    • A. Incorrect. A stateful inspection firewall tracks the state of active connections and filters traffic based on connection state and rules, but it is designed to block or allow traffic, not just monitor and alert. It does not primarily function as a detection-only system.
    • B. Correct. An intrusion detection system (IDS) is designed to monitor network or host activity for suspicious or malicious behavior and generate alerts. It does not take direct action to block traffic; its primary purpose is detection and notification.
    • C. Incorrect. An intrusion prevention system (IPS) also monitors traffic and detects threats, but it can take direct action to block or prevent detected threats, such as dropping packets or resetting connections. This goes beyond the monitoring and alerting function of an IDS.
    • D. Incorrect. A web application firewall (WAF) is specifically designed to protect web applications by filtering and monitoring HTTP/HTTPS traffic for application-layer attacks like SQL injection and cross-site scripting. It is specialized for web traffic and not intended for general network attack detection.

    Subdomain 4.2: Understand network threats and attacks

    23.Which of the following is a limitation of a signature-based intrusion detection system (IDS)?(Select 2)

    1. A.It cannot analyze encrypted network traffic packets
    2. B.It cannot detect zero-day attacks lacking known signatures
    3. C.It often produces too many false positive alerts
    4. D.It needs an extended learning period to set up baselines
    Show answer & explanation

    Correct answers: A, BIt cannot analyze encrypted network traffic packets; It cannot detect zero-day attacks lacking known signatures

    • A. Signature-based IDS relies on known attack patterns and cannot inspect encrypted payloads without decryption, making it a limitation.
    • B. Signature-based IDS cannot detect zero-day attacks because these attacks do not have known signatures in its database. This is a classic limitation.
    • C. False positives are more commonly associated with anomaly-based IDS, not signature-based IDS. Signature-based IDS generally produces fewer false positives when properly tuned.
    • D. Requiring a learning period to establish baselines is a characteristic of anomaly-based IDS, not signature-based IDS.

    Domain 5: Security Operations

    Subdomain 5.4: Understand security awareness training

    24.Which description best defines social engineering in the context of cybersecurity?

    1. A.The use of software tools to exploit system vulnerabilities.
    2. B.The manipulation of individuals to disclose confidential information.
    3. C.The interception of network traffic to capture sensitive data.
    4. D.The physical theft of hardware assets such as laptops and servers.
    Show answer & explanation

    Correct answer: BThe manipulation of individuals to disclose confidential information.

    • A. Incorrect. This describes technical exploitation or hacking using software tools to target system vulnerabilities. Social engineering relies on human interaction and psychological manipulation, not software.
    • B. Correct. Social engineering involves manipulating individuals through psychological tactics (e.g., phishing, pretexting) to trick them into revealing confidential information or performing actions that compromise security. It focuses on deceiving people rather than exploiting technical flaws.
    • C. Incorrect. Intercepting network traffic is associated with packet sniffing, man-in-the-middle attacks, or other network-based attacks. These are technical attacks on data in transit and do not involve human manipulation as social engineering does.
    • D. Incorrect. Physical theft of hardware is a form of physical security breach or theft, not social engineering. Social engineering relies on deception and trickery, not physical access or stealing assets.

    Subdomain 5.4: Understand security awareness training

    25.A janitor discovers discarded documents containing customer account numbers in the regular trash bin. What action should the organization take based on this finding?

    1. A.Discipline the janitor for unauthorized inspection of discarded materials.
    2. B.Enforce a clean desk rule and mandate cross-cut shredding for sensitive papers.
    3. C.Relocate all waste receptacles into a secured room accessible only by authorized staff.
    4. D.Take no action, as the items were discarded and no longer confidential.
    Show answer & explanation

    Correct answer: BEnforce a clean desk rule and mandate cross-cut shredding for sensitive papers.

    • A. Incorrect. This action misdirects blame and fails to address the root cause: improper disposal of confidential documents. The janitor's discovery highlights a process weakness; disciplining them would not prevent recurrence.
    • B. Correct. Enforcing a clean desk/clear desk policy and mandating cross-cut shredding for sensitive papers directly prevents confidential information from being placed in regular trash. This addresses the root cause and reduces risk of data exposure.
    • C. Incorrect. While securing waste receptacles might seem helpful, it does not solve the core issue of how sensitive documents are discarded. The better control is to ensure confidential materials are destroyed before disposal, not just moved to a different location.
    • D. Incorrect. Discarded does not mean declassified. Customer account numbers remain sensitive and must be protected from unauthorized disclosure. Taking no action leaves the organization vulnerable to data breaches and regulatory non-compliance.

    Subdomain 5.4: Understand security awareness training

    26.An employee receives a voice call from someone claiming to be from the bank, asking to confirm a recent transaction by providing the one-time code sent to the phone. The employee is not aware of any transaction. What should the employee do?

    1. A.Read the code to the caller to expedite the verification process.
    2. B.Hang up and call the bank's official customer service number to inquire.
    3. C.Ignore the call and delete the voice mail without taking any further action.
    4. D.Share the code only after confirming the caller's name and employee ID.
    Show answer & explanation

    Correct answer: BHang up and call the bank's official customer service number to inquire.

    • A. Incorrect. One-time codes are sensitive authentication data and should never be shared with unsolicited callers. This is a common vishing (voice phishing) attempt designed to bypass account protections.
    • B. Correct. Hanging up and independently contacting the bank using the official customer service number ensures the employee verifies the request through a trusted channel. This prevents falling victim to vishing and confirms whether the request is legitimate.
    • C. Incorrect. Simply ignoring the call and deleting voicemail does not confirm whether there is a real security issue with the account. The employee should verify the situation through a trusted channel, such as calling the bank's official number.
    • D. Incorrect. Confirming the caller's name and employee ID does not prove legitimacy, as such information can be forged or stolen. One-time codes should never be shared over the phone, regardless of the caller's claims.

    Subdomain 5.2: Understand system hardening

    27.After deploying a recent security patch, the IT team receives reports that a critical business application is crashing. What should the team do?

    1. A.Remove the patch immediately from every system that received it.
    2. B.Investigate the crash and consider rolling back the patch on affected systems.
    3. C.Disregard the crash reports because they are probably unrelated.
    4. D.Apply a different patch to mitigate the effects of the bad patch.
    Show answer & explanation

    Correct answer: BInvestigate the crash and consider rolling back the patch on affected systems.

    • A. Incorrect. Removing the patch immediately from every system without investigation could reintroduce vulnerabilities and expose unaffected systems to the original threat. A blanket rollback is not recommended; the team should first assess the scope.
    • B. Correct. The team should investigate the crash to confirm whether the patch is the cause. If so, rolling back the patch only on impacted systems minimizes business disruption while preserving security for unaffected systems. This controlled response aligns with best practices.
    • C. Incorrect. Crash reports, especially for a critical business application, should never be disregarded without investigation. They may indicate a genuine compatibility issue that requires prompt action. Ignoring them could lead to prolonged downtime or hidden security gaps.
    • D. Incorrect. Applying another patch without understanding the root cause is risky and could worsen the problem or introduce new vulnerabilities. Proper troubleshooting should be conducted first to determine the appropriate remediation.

    Subdomain 5.2: Understand system hardening

    28.Which of the following is a key element of an effective patch management policy?

    1. A.Specifying maximum allowable downtime for business applications.
    2. B.Performing regular vulnerability scans and patch prioritization.
    3. C.Defining encryption standards for data at rest and in transit.
    4. D.Setting minimum password length requirements for all users.
    Show answer & explanation

    Correct answer: BPerforming regular vulnerability scans and patch prioritization.

    • A. Incorrect. While specifying maximum allowable downtime is important for business continuity and availability planning, it is not a core component of a patch management policy. Patch management focuses on identifying, testing, and deploying patches, not on defining downtime limits.
    • B. Correct. Performing regular vulnerability scans helps identify systems that require patches and exposes weaknesses, while patch prioritization ensures that the most critical fixes are applied first. This supports timely, risk-based remediation and is a fundamental part of an effective patch management policy.
    • C. Incorrect. Defining encryption standards for data at rest and in transit is an important security control, but it belongs to data protection and cryptographic policies, not to patch management. Patch management deals with software updates, not encryption policies.
    • D. Incorrect. Setting minimum password length requirements is a password policy control under identity and access management, not a patch management requirement. It improves authentication security but does not help manage operating system or application patches.

    Subdomain 5.2: Understand system hardening

    29.An organization's change management process requires multiple approvals for any patch deployment, causing significant delays. What could be implemented to expedite critical security patches while maintaining control?

    1. A.Bypass all approvals for any security-related patch.
    2. B.Create a fast-track for emergency security patch approval.
    3. C.Automatically deploy all patches without any human review.
    4. D.Eliminate the change management process for all patches.
    Show answer & explanation

    Correct answer: BCreate a fast-track for emergency security patch approval.

    • A. Incorrect. Bypassing all approvals removes necessary oversight and governance, increasing the risk of deploying faulty or incompatible patches and undermining auditability.
    • B. Correct. A fast-track or emergency change path allows critical security patches to be reviewed and approved more quickly while still preserving oversight, balancing speed with control for urgent remediation.
    • C. Incorrect. Automatically deploying all patches without human review eliminates accountability and can introduce outages or security issues if a patch is defective or conflicts with existing systems, sacrificing control and validation.
    • D. Incorrect. Eliminating the change management process entirely removes all controls, creating major operational and security risks; change management ensures accountability, testing, and controlled implementation.

    Subdomain 5.3: Understand best practice security policies

    30.Which element is universally required in a change management policy?

    1. A.A mandatory peer code review before any implementation.
    2. B.A formal user acceptance testing sign-off by stakeholders.
    3. C.A documented and tested plan to revert changes if necessary.
    4. D.Exclusive use of automated deployment pipelines for all releases.
    Show answer & explanation

    Correct answer: CA documented and tested plan to revert changes if necessary.

    • A. While peer code reviews are a best practice in software development, they are not universally required in all change management policies, as change management applies to various types of changes beyond code.
    • B. User acceptance testing sign-off is important in many contexts, but it is not universally required for all changes, especially minor or non-customer-facing changes.
    • C. A documented and tested plan to revert changes is a core element of change management, providing a safety net to reverse changes that cause issues, thereby reducing risk and ensuring business continuity. This is universally required across different types of changes.
    • D. Automated deployment pipelines are a modern best practice that can improve consistency, but they are not a universal requirement in change management policies, as many organizations still use manual or hybrid processes.

    Subdomain 5.3: Understand best practice security policies

    31.A contractor connects a personal laptop directly to the corporate LAN port. The laptop does not have antivirus software or a host firewall. Which policy should mandate security requirements for such devices?

    1. A.Bring Your Own Device (BYOD) policy
    2. B.Acceptable Use Policy (AUP)
    3. C.Change management policy
    4. D.Password policy
    Show answer & explanation

    Correct answer: ABring Your Own Device (BYOD) policy

    • A. Correct. A Bring Your Own Device (BYOD) policy specifically defines security requirements for personal devices used on the corporate network, including mandatory antivirus, host firewall, and other controls to mitigate risks.
    • B. Incorrect. An Acceptable Use Policy (AUP) governs how users may use corporate resources but does not typically mandate specific technical security controls for personal devices.
    • C. Incorrect. Change management policy governs the process for approving and implementing changes to systems and configurations; it does not address endpoint security requirements.
    • D. Incorrect. Password policy sets rules for password creation and management, not requirements for device security like antivirus or firewall.

    Subdomain 5.3: Understand best practice security policies

    32.A software developer identifies a bug in production and wants to fix it immediately by editing the code on the live server. According to the change management policy, what is the appropriate first step?

    1. A.Take a complete backup of the production server configuration first.
    2. B.Submit a formal change request for assessment and approval.
    3. C.Replicate the issue in development and create a patch.
    4. D.Notify the change advisory board for an emergency meeting.
    Show answer & explanation

    Correct answer: BSubmit a formal change request for assessment and approval.

    • A. Taking a backup is a prudent measure, but it is not the appropriate first step according to change management policy. The change must first be formally requested and authorized before any modifications, including backups as part of the execution plan, are performed.
    • B. Submitting a formal change request is the correct first step. It ensures the change is documented, assessed for risks, approved by the appropriate authority, and prioritized. This process reduces the risk of introducing instability into the production environment.
    • C. Replicating the issue in a development environment is a good technical troubleshooting practice, but it should occur after the change request is submitted and approved. The change management workflow requires formal authorization before any development or testing related to production fixes.
    • D. Notifying the change advisory board (CAB) may be required for emergency changes, but it is not the first step. The process begins with submitting a formal change request, which triggers any necessary CAB actions. Skipping the request bypasses the control process.

    Subdomain 5.1: Understand data security

    33.In data classification, which label typically denotes information that would cause severe harm to the organization if disclosed?

    1. A.Public
    2. B.Internal
    3. C.Confidential
    4. D.Unclassified
    Show answer & explanation

    Correct answer: CConfidential

    • A. Incorrect. Public data is intended for open distribution and its disclosure poses no harm to the organization.
    • B. Incorrect. Internal data is meant for internal use; its disclosure may cause limited harm, but not typically severe harm.
    • C. Correct. Confidential data is sensitive information whose unauthorized disclosure could cause severe harm, such as financial loss or reputational damage.
    • D. Incorrect. Unclassified data typically has no sensitivity and does not require protection; disclosure would not cause severe harm.

    Subdomain 5.1: Understand data security

    34.A company needs to store sensitive financial data on a hard drive. The data will only be accessed by a single user who possesses the decryption key. Which type of encryption is most appropriate for protecting this data at rest?

    1. A.Use hashing, which produces an irreversible digest for integrity checks.
    2. B.Use symmetric encryption, which relies on a single shared secret key.
    3. C.Use asymmetric encryption, which uses a public and private key pair.
    4. D.Use digital signatures, which verify authenticity through cryptographic signing.
    Show answer & explanation

    Correct answer: BUse symmetric encryption, which relies on a single shared secret key.

    • A. Incorrect. Hashing is a one-way cryptographic function used for integrity verification, not encryption. It produces a fixed-size digest that cannot be reversed to recover the original data, so it does not provide confidentiality for data at rest that must later be decrypted.
    • B. Correct. Symmetric encryption uses a single shared secret key for both encryption and decryption. It is efficient and well-suited for encrypting large amounts of data at rest, especially when only one user needs access and possesses the decryption key.
    • C. Incorrect. Asymmetric encryption uses a public/private key pair and is computationally more expensive than symmetric encryption, making it less practical for encrypting large datasets at rest. It is typically used for key exchange, digital signatures, or scenarios requiring multiple parties.
    • D. Incorrect. Digital signatures provide integrity, authenticity, and nonrepudiation, but they do not encrypt data. They are used to verify the source and integrity of a message, not to protect data confidentiality.

    Subdomain 5.1: Understand data security

    35.A company needs to securely send a confidential document to a partner over an untrusted network. The partner's public key is available. Which method ensures confidentiality?

    1. A.Hash the document and send the hash value to the partner for verification.
    2. B.Encrypt the document using the partner's public key before sending it.
    3. C.Encrypt the document with a shared secret password known only to both parties.
    4. D.Sign the document with the company's private key to prove its origin.
    Show answer & explanation

    Correct answer: BEncrypt the document using the partner's public key before sending it.

    • A. Hashing only provides integrity verification; it does not keep the document contents secret. The original document remains readable if intercepted.
    • B. Encrypting with the partner's public key ensures that only the partner's private key can decrypt it, providing confidentiality over an untrusted network. This is a core principle of asymmetric encryption.
    • C. Using a shared secret password requires a secure key exchange beforehand, which is not guaranteed over an untrusted network. Additionally, this method does not leverage the partner's public key that is already available.
    • D. Signing with the company's private key proves authenticity and integrity, but does not hide the document contents. Anyone can still read the document.

    Want the full experience?

    These are just samples. Practice the full ISC2 Certified in Cybersecurity (CC) question bank in quiz mode — free, no signup, with domain practice and exam simulation.