Most of the ISC2 CC practice questions circulating online were written for an exam that no longer exists. ISC2 replaced the Certified in Cybersecurity exam outline on 1 September 2026, and the new version carries a standalone Security Governance domain, dedicated cloud security content and AI topics threaded through all five domains. A question bank built before that date cannot test any of it.
The twenty questions below are mapped to the current outline, domain by domain, in roughly the proportion ISC2 publishes. Each one has a worked explanation that covers why the wrong options are wrong, because on the real exam the distractors are where candidates lose marks.
The domains these ISC2 CC practice questions are built on
ISC2 publishes the weightings in the CC Certification Exam Outline. This set follows them:
| Domain | Weighting | Questions here |
|---|---|---|
| 1. Security Principles | 24% | 5 |
| 2. Security Governance | 17.3% | 4 |
| 3. Identity and Access Management (IAM) Concepts | 20% | 4 |
| 4. Networking and Cloud Security Concepts | 21.3% | 4 |
| 5. Security Operations and Incident Response | 17.3% | 3 |
Two of those domain names are new. Governance was previously scattered across other domains and now has 17.3% of the exam to itself, covering GRC planning, redundancy, security awareness and how you measure whether any of it is working. Domain 4 gained cloud characteristics, deployment models and service models, which the old Network Security domain did not examine. If you want the full picture of what moved, we covered it in ISC2 CC Exam Changes 1 Sept 2026.
Exam Tip: The CC exam is 100 to 125 questions in 2 hours, using multiple choice and advanced item types, and you need 700 out of 1000 scaled points to pass. ISC2 does not publish how many raw questions that equates to, because the scaling varies by form. Anyone quoting you a fixed number of correct answers is guessing.
How to use these questions
Work through a domain in one sitting, write your answer down before you read the explanation, and mark anything you got right by elimination rather than by knowing. Those are the items to revise, not the ones you got wrong outright, which you already know about.
Domain 1: Security Principles (24%)
Question 1
An organisation discovers that an attacker has subtly altered several records in a customer database over six months. The records are still available and were never exposed to anyone outside the company. Which pillar has been breached?
- AConfidentiality
- BIntegrity
- CAvailability
- DNon-repudiation
Answer: B. The data was changed without authorisation, which is an integrity failure. Confidentiality is untouched because nothing was disclosed, and availability is untouched because the records remained accessible. Non-repudiation is about proving who performed an action, not about whether the data is correct.
Question 2
A machine learning model is retrained on data an attacker has deliberately contaminated, and it begins misclassifying malicious traffic as benign. In CC terms, this is primarily an attack on which pillar?
- AAvailability
- BPrivacy
- CIntegrity
- DAuthentication
Answer: C. Model poisoning is an integrity attack on the training data and therefore on the model's outputs. The current outline explicitly brings AI into the core pillars, so expect at least one item of this shape. Privacy is the wrong fit here because the concern is corrupted data rather than exposed personal data.
Question 3
A company writes a policy stating that all staff must complete security awareness training annually. Which type of control is the policy itself?
- ATechnical
- BPhysical
- CAdministrative
- DCompensating
Answer: C. Policies, procedures and training requirements are administrative controls. Technical controls are implemented in hardware or software, physical controls restrict access to premises and equipment, and a compensating control is a category of use rather than a category of implementation.
Question 4
Which term describes the ability to prove that a specific user performed a specific action, so that the user cannot credibly deny it?
- AAccounting
- BAuthorisation
- CAuthentication
- DNon-repudiation
Answer: D. Non-repudiation is the assurance that an action cannot be disowned. Accounting is the closest distractor and often supplies the evidence, but accounting is the recording of activity, while non-repudiation is the property that makes the record binding. Authentication proves identity and authorisation grants access.
Question 5
A security analyst investigates a colleague's personal email account without authorisation, having been asked to look into a policy breach. Which principle from the ISC2 Code of Ethics has the analyst most directly failed?
- AAct honourably, honestly, justly, responsibly and legally
- BProtect society, the common good and the infrastructure
- CAdvance and protect the profession
- DProvide diligent and competent service to principals
Answer: A. Acting outside the authority you were given is a failure to act legally and responsibly. The other canons are real, but the specific failing here is an unauthorised act, not incompetence or harm to the profession. The Code of Ethics is examinable under Domain 1, and ISC2 expects you to know the canons in order.
Domain 2: Security Governance (17.3%)
Question 6
An organisation maps its security controls against a published set of practices so it can demonstrate coverage to an auditor. What is it using?
- AA regulation
- BA framework
- CA procedure
- DA standard
Answer: B. A framework is a structured set of practices used for organising and demonstrating a security programme. A regulation is imposed by law, a standard specifies a required level of implementation, and a procedure is the step-by-step instruction for carrying out one task.
Question 7
A data centre runs two independent power feeds from separate substations, either of which can carry the full load. Which governance concept does this implement?
- AResilience through redundancy
- BSeparation of duties
- CDefence in depth
- DLeast privilege
Answer: A. Redundancy sits under Security Governance in the current outline, which is a change worth noting because candidates used to meet it under business continuity. Defence in depth is the nearest distractor but describes layered differing controls rather than duplicated identical ones.
Question 8
Which measure most directly tells a governance team whether its security awareness programme is working?
- AThe number of staff who completed the training
- BThe percentage of staff who report simulated phishing emails
- CThe budget allocated to the training platform
- DThe number of training modules published
Answer: B. Measuring cybersecurity effectiveness means measuring behaviour change, not activity. Completion counts, budget and module counts all measure effort. Reporting rates on simulated phishing measure whether staff act differently, which is the outcome the programme exists to produce.
Question 9
A company must comply with a data protection law, follow an industry framework, and satisfy its insurer's control requirements. Planning how these overlapping obligations are met together is best described as:
- ARisk avoidance
- BGovernance, Risk and Compliance (GRC)
- CIncident response planning
- DAsset lifecycle management
Answer: B. GRC planning is the coordination of governance direction, risk decisions and compliance obligations so they are handled as one programme. Risk avoidance is a single treatment option within risk management, not the coordinating activity.
Domain 3: Identity and Access Management (IAM) Concepts (20%)
Question 10
An employee moves from finance to procurement. Six months later an audit finds they still hold their finance system permissions alongside their new ones. Which part of the identity lifecycle failed?
- AProvisioning
- BReview
- CDeprovisioning
- DAuthentication
Answer: B. The accumulation of rights across role changes is privilege creep, and the lifecycle stage designed to catch it is review. Provisioning worked, since the new access was granted. Deprovisioning applies when someone leaves the organisation entirely, which is not what happened here.
Question 11
An organisation deploys an AI agent that queries internal systems on behalf of staff. How should the agent's access be handled?
- AIt should inherit the permissions of whichever user invokes it
- BIt should run with administrative rights for reliability
- CIt should have its own managed identity subject to the identity lifecycle
- DIt does not require an identity because it is not a person
Answer: C. The current outline is explicit that AI bots and automated service accounts are managed through formal identity lifecycle management. Giving the agent its own reviewable identity is what makes least privilege and accountability possible. Inheriting user permissions makes the agent's actions untraceable, and administrative rights abandon least privilege outright.
Question 12
In which access control model are permissions determined by labels attached to both the subject and the object, with the system rather than the data owner enforcing the decision?
- ADiscretionary access control
- BRole-based access control
- CMandatory access control
- DAttribute-based access control
Answer: C. Mandatory access control uses system-enforced classification labels and removes the owner's discretion. Under discretionary access control the owner decides. Role-based control keys off job role, and attribute-based control evaluates a wider set of attributes but is not defined by enforced labels.
Question 13
A payments process is configured so that the person who creates a supplier payment cannot also approve it. Which principle is this?
- APrinciple of Least Privilege
- BSeparation of Duties
- CNeed to know
- DDual control
Answer: B. Separation of duties splits a sensitive process so no single person can complete it alone. Least privilege is the closest distractor and is related, but it limits how much access one person holds rather than splitting a process between people.
Domain 4: Networking and Cloud Security Concepts (21.3%)
Question 14
A company uses a cloud provider's managed database, and the provider patches the underlying operating system and database engine. The company remains responsible for who can query the data. Which service model is this?
- AInfrastructure as a Service
- BPlatform as a Service
- CSoftware as a Service
- DFunction as a Service
Answer: B. Under Platform as a Service the provider runs the platform and the customer keeps responsibility for the data and its access. Under Infrastructure as a Service the customer would be patching the operating system. Under Software as a Service the customer would not be administering the database at all.
Question 15
Which cloud characteristic describes a customer being able to provision additional compute capacity without contacting the provider's staff?
- AMeasured service
- BResource pooling
- COn-demand self-service
- DRapid elasticity
Answer: C. On-demand self-service is specifically the absence of human interaction with the provider. Rapid elasticity is the nearest distractor and describes capacity scaling to match demand, but the point of this question is the self-service mechanism rather than the scaling behaviour.
Question 16
An organisation places its public web servers in a network segment that is reachable from the internet but cannot initiate connections into the internal network. What is this segment called?
- AA virtual private network
- BA screened subnet
- CA virtual LAN
- DAn intranet
Answer: B. A screened subnet, historically called a DMZ, isolates internet-facing services so a compromise there does not open a path inwards. A VLAN segments a network logically but carries no inherent internet exposure model, and a VPN provides an encrypted tunnel rather than a segment.
Question 17
Two organisations run separate cloud environments and agree to share a single environment governed by common security requirements, restricted to firms in their regulated sector. Which deployment model is this?
- APublic cloud
- BPrivate cloud
- CCommunity cloud
- DHybrid cloud
Answer: C. A community cloud serves a defined group with shared concerns, which is exactly the regulated-sector arrangement described. A hybrid cloud is the combination of two or more distinct deployment models that remain separate entities, which is not what the two firms have built.
Domain 5: Security Operations and Incident Response (17.3%)
Question 18
An organisation applies a process that replaces real customer card numbers with realistic but fictitious values so developers can work with the dataset. What is this?
- AEncryption
- BHashing
- CMasking
- DSanitisation
Answer: C. Masking substitutes usable but non-sensitive values while keeping the data workable. Encryption is reversible with a key and would leave the data unusable for development. Hashing is one-way and destroys the format. Sanitisation removes data so it cannot be recovered at all.
Question 19
A security team runs a discussion-based exercise in which managers talk through their responses to a simulated ransomware incident, without touching production systems. What is this called?
- AA tabletop exercise
- BA penetration test
- CA red team engagement
- DA vulnerability scan
Answer: A. A tabletop exercise is a discussion-based walkthrough of the incident response plan. The other three are technical testing activities that involve interacting with real systems, and the phrase "without touching production systems" is the discriminator.
Question 20
An analyst receives thousands of low-severity alerts daily and consistently misses the few that matter. Which security operations practice most directly addresses this?
- AThreat intelligence gathering
- BSecurity event triage
- CAsset lifecycle management
- DConfiguration management
Answer: B. Triage is the prioritisation and correlation of events so that analysts work the items that matter first. Threat intelligence informs what to prioritise but does not itself do the prioritising. The current outline names alert fatigue as a problem AI-assisted monitoring is used to reduce.
Scoring yourself
These are not scaled like the real exam, so treat your result as a revision signal rather than a prediction.
| Score | What it suggests |
|---|---|
| 17 to 20 | Your coverage of the current outline is solid. Move to timed full-length practice. |
| 13 to 16 | Domain knowledge is there but the distractors are catching you. Revise the questions you answered by elimination. |
| 12 or fewer | Go back to the source material before more questions. Our 4-week ISC2 CC study plan sequences it. |
Pay attention to which domain your misses cluster in. Governance and cloud carry 38.6% of the exam between them and are the two areas older study material handles worst.
Frequently Asked Questions
How difficult is the ISC2 CC exam?
CC is ISC2's entry-level certification and assumes no prior experience, so the difficulty sits in breadth rather than depth. You are asked to recognise concepts across five domains rather than configure anything. The September 2026 outline raised the difficulty slightly for candidates using older material, because governance and cloud content now carry marks that previous question banks never tested.
How should I study for the ISC2 CC exam?
Work from the current exam outline as your checklist, since it lists every sub-topic ISC2 can examine. Pair reading with practice questions from the start rather than saving them until the end, because the CC's wrong answers are plausible by design and elimination is a skill you have to practise. Two to four weeks of steady study is realistic for someone starting without an IT background.
What score is needed to pass ISC2 CC?
You need 700 out of 1000 scaled points. That is not a straight 70% of the questions, because ISC2 converts raw scores to a scaled score and the conversion varies between exam forms. ISC2 does not publish a required number of correct answers.
Is the ISC2 CC exam worth it?
CC registration is US $199, and the free One Million Certified programme stopped taking new enrolments on 20 May 2026, so it is a paid exam for anyone starting now. It carries weight for people with no cybersecurity experience who need a recognised credential to get past a first screening, and it maps onto SSCP and CISSP later. We compared it directly with the main alternative in ISC2 CC vs CompTIA Security+.
Do older ISC2 CC practice questions still work?
Partly. Questions on the core pillars, controls and access control models remain valid. Anything written against the pre-September domain structure will under-test governance and will not test cloud characteristics, deployment models or service models at all, and those now account for a substantial share of the exam.
Ready to Start Practising?
Twenty questions tells you where the gaps are. Closing them takes a full bank mapped to the current outline, and that is what the ISC2 CC course on CertCrush is for, with questions rebuilt against the 1 September 2026 domains and explanations that teach the distractor logic rather than just naming the answer.
Create a free account and start with the governance and cloud domains, since those are the two the rest of the internet has not caught up on yet.
Official sources: ISC2 CC Certification Exam Outline, ISC2: What's New for Entry-Level Cybersecurity, ISC2 Exam Pricing.
