ISC2 CC Practice Exam Questions & Answers

5 Free Questions · Last reviewed: August 26, 2026 · Prepared & Reviewed by the ValidExamDumps Editorial Team

Exam Facts

ISC2 CC Exam Details

Key details for this exam, checked against the published exam outline

407 Practice Questions (Our Bank)
120 minutes Exam Duration
700 out of 1000 Passing Score
USD 199 Exam Fee
Exam Code
CC
Full Name
Certified in Cybersecurity
Issuing Body
ISC2
Question Format (Our Bank)
Multiple Choice
Delivery
Pearson VUE test centres or online proctored
Eligibility
No prior experience required
Validity
3 years
Practice Questions

Free CC Practice Questions

Each question shows the correct answer and an explanation of why it is right

VA
ValidExamDumps Editorial Team Every question and its answer is checked by our CC exam preparation team, who also write the explanation shown with each one. How we research and review these pages

What is the primary goal of Identity and Access Management (1AM) in cybersecurity?

Correct Answer: A
Explanation Identity and Access Management ensures that only authorized users can access specific resources. The correct answer is wrong in this question. IAM's primary goal is not to achieve 100% security against all threats, which is impossible. Instead, IAM focuses on verifying who users are, confirming they have permission to access resources, and limiting what they can do based on their role and needs. This is core to access control principles.

1________is a weighted factor based on a subjective analysis of the probability

that a given threat or set of threats is capable of exploiting a given vulnerability or set of vulnerabilities.

Correct Answer: A
Explanation Likelihood of occurrence refers to how probable it is that a threat will actually exploit a vulnerability. Risk assessments always involve weighing both the impact if something goes wrong and the chance it will happen. Likelihood is the subjective judgment about probability that a particular threat could actually occur and cause harm. Other options might confuse risk terms but likelihood is the correct label for this probability factor.

Timiting access to resources based on the sensitivity of the information that the resource contains and the authorization of the user to access information with that level of sensitivity.

Correct Answer: B
Explanation MAC stands for Mandatory Access Control, a system where access decisions are based on security labels assigned to both data and users. The resource contains information at a certain classification level, and users have clearance for specific levels. Users can only access resources matching their authorization. This contrasts with discretionary access control where owners decide who gets access. MAC is the method described here.

When Operating in A Cloud Environment, What Cloud Deployment Model Provides Security Teams With The Greatest Access To Forensic Information?

Correct Answer: D
Explanation Infrastructure as a Service gives security teams the most forensic visibility because the cloud provider manages only the underlying hardware and virtualization. The organization controls the operating systems, applications, and data, so they can install monitoring tools and capture logs. With Platform as a Service or Software as a Service, the provider manages more layers, limiting what forensic data you can collect. Private clouds also work but IaaS is the standard answer for forensic access in cloud environments.

Networks are often micro segmented networks, with firewalls at nearly every connecting point

Correct Answer: A
Get Full Access

407 questions covering all exam domains, starting from $20

Study Guide

What the ISC2 CC Exam Covers

Exam domains verified against: Official ISC2 CC exam guide, last checked August 2026.

Domain 1: Security Principles 26%

This domain covers the core concepts that underpin all security work: confidentiality, integrity, availability and authentication. You also need to understand non-repudiation and privacy, the risk management process including identification and treatment of risks, and the three types of security controls that organizations deploy. The ISC2 Code of Ethics is part of this, as are governance processes including policies, procedures, standards, regulations and laws.

Sample question from this domain above: Q2

Domain 2: Business Continuity (BC), Disaster Recovery (DR) & Incident Response Concepts 10%

This domain asks you to understand three related but distinct operational practices. Business continuity keeps the organization running during a disruption. Disaster recovery restores systems and data after a major failure. Incident response detects and contains a security breach. All three have purpose, importance and specific components you need to know.

Domain 3: Access Controls Concepts 22%

Access controls stop unauthorized people reaching assets. Physical access controls include badge systems, gates and environmental design, monitored by guards, cameras and alarms. Logical access controls enforce principle of least privilege and segregation of duties through models like discretionary access control (DAC), mandatory access control (MAC) and role-based access control (RBAC).

Sample questions from this domain above: Q1Q3

Domain 4: Network Security 24%

This domain starts with the fundamentals: the OSI and TCP/IP models, IPv4 and IPv6, WiFi and ports. Then it covers the threats that attack networks including DDoS, viruses, worms and man-in-the-middle attacks, plus how to detect them with IDS and NIDS and prevent them with antivirus, firewalls and IPS. Network security infrastructure includes on-premises considerations like power and HVAC, design patterns like network segmentation and DMZ, and cloud service models such as SaaS, IaaS and PaaS.

Sample questions from this domain above: Q4Q5

Domain 5: Security Operations 18%

This domain covers how organizations keep their systems secure day to day. Data security means encryption (symmetric, asymmetric and hashing), proper data handling including classification and destruction, and continuous logging and monitoring. System hardening requires baselines, patches and updates. Best practice policies cover data handling, passwords, acceptable use, BYOD and change management. Security awareness training teaches everyone to spot social engineering and protect their credentials.

FAQ

CC Exam FAQ

Common questions about the exam itself

Do I need any prior IT or cybersecurity experience to take the CC exam?
The CC is designed for people entering cybersecurity or transitioning from other fields with no prior experience needed. No prior work experience is required to sit for the exam, and anyone can register and test immediately whether you are transitioning from another field or launching your first security role.
How long does it take most people to prepare for the CC exam?
Preparation time varies widely depending on your background and learning style. Most candidates with some IT background take 2 to 4 weeks of focused study, while those coming from non-technical roles may need 6 to 8 weeks. The key is understanding each of the five domains at a foundational level rather than mastering any single area in depth.
What is the hardest domain in the CC exam and how should I approach it?
The difficulty comes from breadth rather than depth, as the exam samples foundational concepts across all five domains rather than probing any one of them deeply. Many candidates find Network Security challenging because it requires knowledge of multiple technologies. Map out the OSI model early and use that as your mental framework for understanding TCP/IP, protocols and network attacks.
What happens on CC exam day and how is the test administered?
The CC exam is administered at Pearson VUE testing centers worldwide as a Computerized Adaptive Testing (CAT) exam with multiple choice and advanced item types. You get 2 hours to answer 100 to 125 questions across five domains. The CAT format adjusts difficulty based on your answers, so the number of questions you see depends on how you perform.
What is the passing score for the CC exam?
You need a scaled score of 700 out of 1000 points to pass. ISC2 does not release your scaled score immediately for a pass result. you will know within minutes whether you passed, but the actual numeric score is confidential.
How much does the CC exam cost and what about recurring costs?
The CC exam fee is USD 199, and upon passing the exam candidates pay USD 50 Annual Maintenance Fee (AMF). After that, the USD 50 AMF is due every year to maintain your membership and certification.
How long is the CC certification valid and what do I need to do to keep it current?
ISC2 certifications are time-limited and must be renewed on a regular three-year cycle. For recertification, you need to earn 45 CPE credits during the three-year certification cycle, though ISC2 provides various free options for maintaining the certification.
What job role does the CC certification prepare me for?
The CC proves you have the foundational knowledge, skills and abilities for an entry- or junior-level cybersecurity role. This includes positions like junior security analyst, SOC analyst, security operations staff, IT security support or compliance assistant roles that do not yet require the deeper expertise of advanced certifications.
How does the CC fit into the ISC2 certification track and what comes next?
ISC2 positioned the CC as the foundational certification in its portfolio, sitting below SSCP, CCSP, CGRC and CISSP, which matters when thinking about long-term career paths and creates a clean track upward into more advanced ISC2 credentials. After CC, most professionals move toward SSCP for system administration or CCSP for cloud security.
What are the rescheduling and cancellation rules if my exam date changes?
Pearson VUE charges a reschedule fee of USD 50 and a cancellation fee of USD 100 if you drop the appointment entirely. rescheduling is usually the cheaper option when you are not ready to sit.