ISC2 CC Practice Questions & Flashcards
Study every domain of the ISC2 Certified in Cybersecurity (CC) exam with focused flashcards and timed practice quizzes.
One-time $19.95 · 30-day access · no subscription, no auto-renew, no card kept on file
What is the ISC2 CC certification?
ISC2 Certified in Cybersecurity (CC) is an entry-level, vendor-neutral certification from ISC2 — the organization behind the CISSP. It covers the foundational concepts every cybersecurity professional needs: security principles, access controls, network security, incident response, and day-to-day security operations.
CC is aimed at people starting a cybersecurity career: recent graduates, IT professionals moving into security, and career changers. It requires no prior work experience to sit the exam, which makes it one of the most accessible ways to prove foundational security knowledge to an employer.
ISC2 CC exam overview
| Format | Computerized adaptive test (CAT), 100–125 questions |
|---|---|
| Time | 2 hours |
| Passing score | 700 out of 1,000 (scaled) |
| Exam fee | Paid separately to ISC2 — distinct from CertStudio prep, which is a one-time, low-cost study tool |
The 5 ISC2 CC exam domains
Security Principles
The CIA triad (confidentiality, integrity, availability), risk management vocabulary, security controls, governance documents, and the ISC2 Code of Ethics.
Business Continuity
Business continuity and disaster recovery planning, plus the incident response lifecycle: how organizations keep running through disruption and recover from it.
Access Controls
Physical and logical access control, authentication factors, authorization models (DAC, MAC, RBAC), and the principle of least privilege.
Network Security
Network types and topologies, common threats and attacks, and the secure protocols and devices used to defend a network.
Security Operations
Day-to-day security operations: data handling, encryption fundamentals, and system hardening.
Every flashcard and quiz question in CertStudio is tagged to these domains, so you can drill a weak domain directly or study the full exam blueprint.
Sample ISC2 CC practice questions
A company's marketing pages are already public, so nothing on them is secret, and the site rarely goes down. An attacker manages to deface several pages with false claims about the business. Which security property was the attack MOST directly aimed at?
Defacement is unauthorized modification of published content, the definition of an integrity violation. Confidentiality doesn't apply to content that was already meant to be public. Availability would be the target if the pages went offline, but a defaced page still loads, it's simply wrong.
A government agency assigns every piece of data a sensitivity label and centrally enforces which cleared users may access which label, with no ability for even a senior data owner to grant an exception. Which access control model is in use?
Mandatory access control enforces classification labels and clearances centrally; users cannot grant, delegate or downgrade access no matter how senior they are, which matches the 'no exceptions' detail exactly. DAC would let the data owner decide, and RBAC and ABAC assign access by role or attribute rather than a fixed centrally-enforced label.
A network team is choosing between two monitoring appliances: one sits beside the traffic flow and can only alert on suspicious activity, while the other sits inline and can drop malicious packets before they ever reach their destination, at the cost of being able to cause an outage if it misfires. What is the KEY difference between these two devices?
The difference is placement and action: an IPS sits inline and can drop traffic, while an IDS sits beside it and only reports, which is exactly why an IPS false positive can cause the outage described.
What you get with CertStudio
Every practice question is written as a single-best-answer scenario, the same style you'll see on exam day: a short situation, four plausible options, and an explanation that also covers why the runner-up answers are wrong. Progress tracking shows exactly which domains you've mastered and which still need work.
Pricing
$19.95
one-time payment · 30 days of full access
No subscription, no auto-renew, and no card kept on file. When your access window ends, you decide whether to buy another one — your progress is saved either way.
Create your account to get startedISC2 CC FAQ
Is the ISC2 CC exam hard?
The CC is designed as an entry-level exam, so it tests foundational concepts rather than deep technical configuration. Most difficulty comes from the breadth of the five domains and the scenario wording. Consistent practice with domain-tagged questions is the most reliable way to prepare.
How many questions are on the ISC2 CC exam?
The CC exam is a computerized adaptive test (CAT) of 100 to 125 questions delivered over 2 hours. Because it's adaptive, the exact number you see depends on your answers.
What score do I need to pass the ISC2 CC exam?
You need a scaled score of 700 out of 1,000. ISC2 does not publish a fixed percentage, and your result is available shortly after you finish.
What are the ISC2 CC exam domains?
Five domains: Security Principles (26%), Business Continuity/Disaster Recovery & Incident Response (10%), Access Controls Concepts (22%), Network Security (24%), and Security Operations (18%).
How much does the ISC2 CC exam cost, and is that the same as CertStudio?
The exam fee is paid directly to ISC2 to sit the official test. CertStudio is separate, low-cost prep: a one-time payment gives you flashcards and practice quizzes to get ready — it is not the exam fee.
Do I need experience to take the ISC2 CC?
No prior work experience is required to sit the CC exam, which is why it's popular as a first cybersecurity certification.
Ready to start studying for the ISC2 CC?
259 flashcards, 195 practice questions, one-time payment.
Create your account to get startedStudying for CompTIA instead? See the CompTIA A+ guide. Have a question first? Visit Help.