Back to blog
Exam Guides14 min read

ISC2 CC Practice Questions (2026): 20 Exam-Style Examples for the New 1 September Domains

Twenty ISC2 CC practice questions written to the exam outline that took effect on 1 September 2026, covering the new Security Governance domain and the cloud security content that older question sets miss.

Tom Ashford

Tom Ashford · Security Certifications Lead

20 September 2026

Most of the ISC2 CC practice questions circulating online were written for an exam that no longer exists. ISC2 replaced the Certified in Cybersecurity exam outline on 1 September 2026, and the new version carries a standalone Security Governance domain, dedicated cloud security content and AI topics threaded through all five domains. A question bank built before that date cannot test any of it.

The twenty questions below are mapped to the current outline, domain by domain, in roughly the proportion ISC2 publishes. Each one has a worked explanation that covers why the wrong options are wrong, because on the real exam the distractors are where candidates lose marks.

The domains these ISC2 CC practice questions are built on

ISC2 publishes the weightings in the CC Certification Exam Outline. This set follows them:

DomainWeightingQuestions here
1. Security Principles24%5
2. Security Governance17.3%4
3. Identity and Access Management (IAM) Concepts20%4
4. Networking and Cloud Security Concepts21.3%4
5. Security Operations and Incident Response17.3%3

Two of those domain names are new. Governance was previously scattered across other domains and now has 17.3% of the exam to itself, covering GRC planning, redundancy, security awareness and how you measure whether any of it is working. Domain 4 gained cloud characteristics, deployment models and service models, which the old Network Security domain did not examine. If you want the full picture of what moved, we covered it in ISC2 CC Exam Changes 1 Sept 2026.

Exam Tip: The CC exam is 100 to 125 questions in 2 hours, using multiple choice and advanced item types, and you need 700 out of 1000 scaled points to pass. ISC2 does not publish how many raw questions that equates to, because the scaling varies by form. Anyone quoting you a fixed number of correct answers is guessing.

How to use these questions

Work through a domain in one sitting, write your answer down before you read the explanation, and mark anything you got right by elimination rather than by knowing. Those are the items to revise, not the ones you got wrong outright, which you already know about.

Domain 1: Security Principles (24%)

Question 1

An organisation discovers that an attacker has subtly altered several records in a customer database over six months. The records are still available and were never exposed to anyone outside the company. Which pillar has been breached?

  1. AConfidentiality
  2. BIntegrity
  3. CAvailability
  4. DNon-repudiation

Answer: B. The data was changed without authorisation, which is an integrity failure. Confidentiality is untouched because nothing was disclosed, and availability is untouched because the records remained accessible. Non-repudiation is about proving who performed an action, not about whether the data is correct.

Question 2

A machine learning model is retrained on data an attacker has deliberately contaminated, and it begins misclassifying malicious traffic as benign. In CC terms, this is primarily an attack on which pillar?

  1. AAvailability
  2. BPrivacy
  3. CIntegrity
  4. DAuthentication

Answer: C. Model poisoning is an integrity attack on the training data and therefore on the model's outputs. The current outline explicitly brings AI into the core pillars, so expect at least one item of this shape. Privacy is the wrong fit here because the concern is corrupted data rather than exposed personal data.

Question 3

A company writes a policy stating that all staff must complete security awareness training annually. Which type of control is the policy itself?

  1. ATechnical
  2. BPhysical
  3. CAdministrative
  4. DCompensating

Answer: C. Policies, procedures and training requirements are administrative controls. Technical controls are implemented in hardware or software, physical controls restrict access to premises and equipment, and a compensating control is a category of use rather than a category of implementation.

Question 4

Which term describes the ability to prove that a specific user performed a specific action, so that the user cannot credibly deny it?

  1. AAccounting
  2. BAuthorisation
  3. CAuthentication
  4. DNon-repudiation

Answer: D. Non-repudiation is the assurance that an action cannot be disowned. Accounting is the closest distractor and often supplies the evidence, but accounting is the recording of activity, while non-repudiation is the property that makes the record binding. Authentication proves identity and authorisation grants access.

Question 5

A security analyst investigates a colleague's personal email account without authorisation, having been asked to look into a policy breach. Which principle from the ISC2 Code of Ethics has the analyst most directly failed?

  1. AAct honourably, honestly, justly, responsibly and legally
  2. BProtect society, the common good and the infrastructure
  3. CAdvance and protect the profession
  4. DProvide diligent and competent service to principals

Answer: A. Acting outside the authority you were given is a failure to act legally and responsibly. The other canons are real, but the specific failing here is an unauthorised act, not incompetence or harm to the profession. The Code of Ethics is examinable under Domain 1, and ISC2 expects you to know the canons in order.

Domain 2: Security Governance (17.3%)

Question 6

An organisation maps its security controls against a published set of practices so it can demonstrate coverage to an auditor. What is it using?

  1. AA regulation
  2. BA framework
  3. CA procedure
  4. DA standard

Answer: B. A framework is a structured set of practices used for organising and demonstrating a security programme. A regulation is imposed by law, a standard specifies a required level of implementation, and a procedure is the step-by-step instruction for carrying out one task.

Question 7

A data centre runs two independent power feeds from separate substations, either of which can carry the full load. Which governance concept does this implement?

  1. AResilience through redundancy
  2. BSeparation of duties
  3. CDefence in depth
  4. DLeast privilege

Answer: A. Redundancy sits under Security Governance in the current outline, which is a change worth noting because candidates used to meet it under business continuity. Defence in depth is the nearest distractor but describes layered differing controls rather than duplicated identical ones.

Question 8

Which measure most directly tells a governance team whether its security awareness programme is working?

  1. AThe number of staff who completed the training
  2. BThe percentage of staff who report simulated phishing emails
  3. CThe budget allocated to the training platform
  4. DThe number of training modules published

Answer: B. Measuring cybersecurity effectiveness means measuring behaviour change, not activity. Completion counts, budget and module counts all measure effort. Reporting rates on simulated phishing measure whether staff act differently, which is the outcome the programme exists to produce.

Question 9

A company must comply with a data protection law, follow an industry framework, and satisfy its insurer's control requirements. Planning how these overlapping obligations are met together is best described as:

  1. ARisk avoidance
  2. BGovernance, Risk and Compliance (GRC)
  3. CIncident response planning
  4. DAsset lifecycle management

Answer: B. GRC planning is the coordination of governance direction, risk decisions and compliance obligations so they are handled as one programme. Risk avoidance is a single treatment option within risk management, not the coordinating activity.

Domain 3: Identity and Access Management (IAM) Concepts (20%)

Question 10

An employee moves from finance to procurement. Six months later an audit finds they still hold their finance system permissions alongside their new ones. Which part of the identity lifecycle failed?

  1. AProvisioning
  2. BReview
  3. CDeprovisioning
  4. DAuthentication

Answer: B. The accumulation of rights across role changes is privilege creep, and the lifecycle stage designed to catch it is review. Provisioning worked, since the new access was granted. Deprovisioning applies when someone leaves the organisation entirely, which is not what happened here.

Question 11

An organisation deploys an AI agent that queries internal systems on behalf of staff. How should the agent's access be handled?

  1. AIt should inherit the permissions of whichever user invokes it
  2. BIt should run with administrative rights for reliability
  3. CIt should have its own managed identity subject to the identity lifecycle
  4. DIt does not require an identity because it is not a person

Answer: C. The current outline is explicit that AI bots and automated service accounts are managed through formal identity lifecycle management. Giving the agent its own reviewable identity is what makes least privilege and accountability possible. Inheriting user permissions makes the agent's actions untraceable, and administrative rights abandon least privilege outright.

Question 12

In which access control model are permissions determined by labels attached to both the subject and the object, with the system rather than the data owner enforcing the decision?

  1. ADiscretionary access control
  2. BRole-based access control
  3. CMandatory access control
  4. DAttribute-based access control

Answer: C. Mandatory access control uses system-enforced classification labels and removes the owner's discretion. Under discretionary access control the owner decides. Role-based control keys off job role, and attribute-based control evaluates a wider set of attributes but is not defined by enforced labels.

Question 13

A payments process is configured so that the person who creates a supplier payment cannot also approve it. Which principle is this?

  1. APrinciple of Least Privilege
  2. BSeparation of Duties
  3. CNeed to know
  4. DDual control

Answer: B. Separation of duties splits a sensitive process so no single person can complete it alone. Least privilege is the closest distractor and is related, but it limits how much access one person holds rather than splitting a process between people.

Domain 4: Networking and Cloud Security Concepts (21.3%)

Question 14

A company uses a cloud provider's managed database, and the provider patches the underlying operating system and database engine. The company remains responsible for who can query the data. Which service model is this?

  1. AInfrastructure as a Service
  2. BPlatform as a Service
  3. CSoftware as a Service
  4. DFunction as a Service

Answer: B. Under Platform as a Service the provider runs the platform and the customer keeps responsibility for the data and its access. Under Infrastructure as a Service the customer would be patching the operating system. Under Software as a Service the customer would not be administering the database at all.

Question 15

Which cloud characteristic describes a customer being able to provision additional compute capacity without contacting the provider's staff?

  1. AMeasured service
  2. BResource pooling
  3. COn-demand self-service
  4. DRapid elasticity

Answer: C. On-demand self-service is specifically the absence of human interaction with the provider. Rapid elasticity is the nearest distractor and describes capacity scaling to match demand, but the point of this question is the self-service mechanism rather than the scaling behaviour.

Question 16

An organisation places its public web servers in a network segment that is reachable from the internet but cannot initiate connections into the internal network. What is this segment called?

  1. AA virtual private network
  2. BA screened subnet
  3. CA virtual LAN
  4. DAn intranet

Answer: B. A screened subnet, historically called a DMZ, isolates internet-facing services so a compromise there does not open a path inwards. A VLAN segments a network logically but carries no inherent internet exposure model, and a VPN provides an encrypted tunnel rather than a segment.

Question 17

Two organisations run separate cloud environments and agree to share a single environment governed by common security requirements, restricted to firms in their regulated sector. Which deployment model is this?

  1. APublic cloud
  2. BPrivate cloud
  3. CCommunity cloud
  4. DHybrid cloud

Answer: C. A community cloud serves a defined group with shared concerns, which is exactly the regulated-sector arrangement described. A hybrid cloud is the combination of two or more distinct deployment models that remain separate entities, which is not what the two firms have built.

Domain 5: Security Operations and Incident Response (17.3%)

Question 18

An organisation applies a process that replaces real customer card numbers with realistic but fictitious values so developers can work with the dataset. What is this?

  1. AEncryption
  2. BHashing
  3. CMasking
  4. DSanitisation

Answer: C. Masking substitutes usable but non-sensitive values while keeping the data workable. Encryption is reversible with a key and would leave the data unusable for development. Hashing is one-way and destroys the format. Sanitisation removes data so it cannot be recovered at all.

Question 19

A security team runs a discussion-based exercise in which managers talk through their responses to a simulated ransomware incident, without touching production systems. What is this called?

  1. AA tabletop exercise
  2. BA penetration test
  3. CA red team engagement
  4. DA vulnerability scan

Answer: A. A tabletop exercise is a discussion-based walkthrough of the incident response plan. The other three are technical testing activities that involve interacting with real systems, and the phrase "without touching production systems" is the discriminator.

Question 20

An analyst receives thousands of low-severity alerts daily and consistently misses the few that matter. Which security operations practice most directly addresses this?

  1. AThreat intelligence gathering
  2. BSecurity event triage
  3. CAsset lifecycle management
  4. DConfiguration management

Answer: B. Triage is the prioritisation and correlation of events so that analysts work the items that matter first. Threat intelligence informs what to prioritise but does not itself do the prioritising. The current outline names alert fatigue as a problem AI-assisted monitoring is used to reduce.

Scoring yourself

These are not scaled like the real exam, so treat your result as a revision signal rather than a prediction.

ScoreWhat it suggests
17 to 20Your coverage of the current outline is solid. Move to timed full-length practice.
13 to 16Domain knowledge is there but the distractors are catching you. Revise the questions you answered by elimination.
12 or fewerGo back to the source material before more questions. Our 4-week ISC2 CC study plan sequences it.

Pay attention to which domain your misses cluster in. Governance and cloud carry 38.6% of the exam between them and are the two areas older study material handles worst.

Frequently Asked Questions

How difficult is the ISC2 CC exam?

CC is ISC2's entry-level certification and assumes no prior experience, so the difficulty sits in breadth rather than depth. You are asked to recognise concepts across five domains rather than configure anything. The September 2026 outline raised the difficulty slightly for candidates using older material, because governance and cloud content now carry marks that previous question banks never tested.

How should I study for the ISC2 CC exam?

Work from the current exam outline as your checklist, since it lists every sub-topic ISC2 can examine. Pair reading with practice questions from the start rather than saving them until the end, because the CC's wrong answers are plausible by design and elimination is a skill you have to practise. Two to four weeks of steady study is realistic for someone starting without an IT background.

What score is needed to pass ISC2 CC?

You need 700 out of 1000 scaled points. That is not a straight 70% of the questions, because ISC2 converts raw scores to a scaled score and the conversion varies between exam forms. ISC2 does not publish a required number of correct answers.

Is the ISC2 CC exam worth it?

CC registration is US $199, and the free One Million Certified programme stopped taking new enrolments on 20 May 2026, so it is a paid exam for anyone starting now. It carries weight for people with no cybersecurity experience who need a recognised credential to get past a first screening, and it maps onto SSCP and CISSP later. We compared it directly with the main alternative in ISC2 CC vs CompTIA Security+.

Do older ISC2 CC practice questions still work?

Partly. Questions on the core pillars, controls and access control models remain valid. Anything written against the pre-September domain structure will under-test governance and will not test cloud characteristics, deployment models or service models at all, and those now account for a substantial share of the exam.

Ready to Start Practising?

Twenty questions tells you where the gaps are. Closing them takes a full bank mapped to the current outline, and that is what the ISC2 CC course on CertCrush is for, with questions rebuilt against the 1 September 2026 domains and explanations that teach the distractor logic rather than just naming the answer.

Create a free account and start with the governance and cloud domains, since those are the two the rest of the internet has not caught up on yet.

Official sources: ISC2 CC Certification Exam Outline, ISC2: What's New for Entry-Level Cybersecurity, ISC2 Exam Pricing.

ISC2 CCCertified in CybersecurityPractice QuestionsExam PreparationEntry Level CybersecuritySecurity GovernanceCloud Security
Tom Ashford

Written by

Tom Ashford · Security Certifications Lead

Tom spent over a decade in security operations and consulting before turning to full-time exam-prep writing. He covers the big security certifications — CISSP, CISM, CISA, Security+ and the rest of the alphabet — with a soft spot for the questions everyone gets wrong. His rule for every article: if it doesn’t help you score marks, it doesn’t go in.

All articles by Tom

Practise for ISC2 CC Certified in Cybersecurity — free

10 real exam-style questions with full explanations, no account needed. Then unlock the complete bank with an exam-readiness score and a daily plan built around your exam date.