ISC2 · Certified in Cybersecurity

ISC2 CC Practice Questions & Flashcards

Study every domain of the ISC2 Certified in Cybersecurity (CC) exam with focused flashcards and timed practice quizzes.

One-time $19.95 · 30-day access · no subscription, no auto-renew, no card kept on file

259
Flashcards
195
Practice questions

What is the ISC2 CC certification?

ISC2 Certified in Cybersecurity (CC) is an entry-level, vendor-neutral certification from ISC2 — the organization behind the CISSP. It covers the foundational concepts every cybersecurity professional needs: security principles, access controls, network security, incident response, and day-to-day security operations.

CC is aimed at people starting a cybersecurity career: recent graduates, IT professionals moving into security, and career changers. It requires no prior work experience to sit the exam, which makes it one of the most accessible ways to prove foundational security knowledge to an employer.

ISC2 CC exam overview

FormatComputerized adaptive test (CAT), 100–125 questions
Time2 hours
Passing score700 out of 1,000 (scaled)
Exam feePaid separately to ISC2 — distinct from CertStudio prep, which is a one-time, low-cost study tool

The 5 ISC2 CC exam domains

D1 · 26%

Security Principles

The CIA triad (confidentiality, integrity, availability), risk management vocabulary, security controls, governance documents, and the ISC2 Code of Ethics.

D2 · 10%

Business Continuity

Business continuity and disaster recovery planning, plus the incident response lifecycle: how organizations keep running through disruption and recover from it.

D3 · 22%

Access Controls

Physical and logical access control, authentication factors, authorization models (DAC, MAC, RBAC), and the principle of least privilege.

D4 · 24%

Network Security

Network types and topologies, common threats and attacks, and the secure protocols and devices used to defend a network.

D5 · 18%

Security Operations

Day-to-day security operations: data handling, encryption fundamentals, and system hardening.

Every flashcard and quiz question in CertStudio is tagged to these domains, so you can drill a weak domain directly or study the full exam blueprint.

Sample ISC2 CC practice questions

D1 · Security Principles

A company's marketing pages are already public, so nothing on them is secret, and the site rarely goes down. An attacker manages to deface several pages with false claims about the business. Which security property was the attack MOST directly aimed at?

Confidentiality
Availability
Integrity
Non-repudiation

Defacement is unauthorized modification of published content, the definition of an integrity violation. Confidentiality doesn't apply to content that was already meant to be public. Availability would be the target if the pages went offline, but a defaced page still loads, it's simply wrong.

D3 · Access Controls Concepts

A government agency assigns every piece of data a sensitivity label and centrally enforces which cleared users may access which label, with no ability for even a senior data owner to grant an exception. Which access control model is in use?

DAC
MAC
RBAC
ABAC

Mandatory access control enforces classification labels and clearances centrally; users cannot grant, delegate or downgrade access no matter how senior they are, which matches the 'no exceptions' detail exactly. DAC would let the data owner decide, and RBAC and ABAC assign access by role or attribute rather than a fixed centrally-enforced label.

D4 · Network Security

A network team is choosing between two monitoring appliances: one sits beside the traffic flow and can only alert on suspicious activity, while the other sits inline and can drop malicious packets before they ever reach their destination, at the cost of being able to cause an outage if it misfires. What is the KEY difference between these two devices?

An IPS cannot generate alerts
An IDS is faster than an IPS
An IPS can actively block malicious traffic while an IDS only detects and alerts
An IDS works only on wireless networks

The difference is placement and action: an IPS sits inline and can drop traffic, while an IDS sits beside it and only reports, which is exactly why an IPS false positive can cause the outage described.

What you get with CertStudio

259
Flashcards, term + definition + scenario
195
Practice questions with explanations
5
Domains tracked separately

Every practice question is written as a single-best-answer scenario, the same style you'll see on exam day: a short situation, four plausible options, and an explanation that also covers why the runner-up answers are wrong. Progress tracking shows exactly which domains you've mastered and which still need work.

Pricing

$19.95

one-time payment · 30 days of full access

No subscription, no auto-renew, and no card kept on file. When your access window ends, you decide whether to buy another one — your progress is saved either way.

Create your account to get started

ISC2 CC FAQ

Is the ISC2 CC exam hard?

The CC is designed as an entry-level exam, so it tests foundational concepts rather than deep technical configuration. Most difficulty comes from the breadth of the five domains and the scenario wording. Consistent practice with domain-tagged questions is the most reliable way to prepare.

How many questions are on the ISC2 CC exam?

The CC exam is a computerized adaptive test (CAT) of 100 to 125 questions delivered over 2 hours. Because it's adaptive, the exact number you see depends on your answers.

What score do I need to pass the ISC2 CC exam?

You need a scaled score of 700 out of 1,000. ISC2 does not publish a fixed percentage, and your result is available shortly after you finish.

What are the ISC2 CC exam domains?

Five domains: Security Principles (26%), Business Continuity/Disaster Recovery & Incident Response (10%), Access Controls Concepts (22%), Network Security (24%), and Security Operations (18%).

How much does the ISC2 CC exam cost, and is that the same as CertStudio?

The exam fee is paid directly to ISC2 to sit the official test. CertStudio is separate, low-cost prep: a one-time payment gives you flashcards and practice quizzes to get ready — it is not the exam fee.

Do I need experience to take the ISC2 CC?

No prior work experience is required to sit the CC exam, which is why it's popular as a first cybersecurity certification.

Ready to start studying for the ISC2 CC?

259 flashcards, 195 practice questions, one-time payment.

Create your account to get started

Studying for CompTIA instead? See the CompTIA A+ guide. Have a question first? Visit Help.