ISC2 · Practice exam

Free ISC2 CC Practice Test & Questions

The ISC2 CC Certified in Cybersecurity exam is up to 100 questions in 120 minutes, and the voucher costs $199. CertCrush provides 645 syllabus-aligned practice questions across all 5 exam domains, each with a full explanation. Free to try, no account required.

No account · No card · Pass or refund

Try one · Security Governance

An organization experiences a ransomware attack that encrypts all file servers. The security team isolates affected systems and begins recovery from clean backups. Meanwhile, management activates a plan that allows employees to access critical documents from a cloud-based backup service to maintain client deliverables. The plan that allows continued client deliverables is BEST described as part of the:

Practice questions
645
Exam time limit
120 min
Practice pass mark
70%
Exam voucher
$199

In the full course

What you get

  • 645 exam-style questions, each with a full explanation
  • 207 flashcards, filtered by domain
  • The full study guide, 6 chapters
  • Timed mock exams matched to the real exam length
  • A readiness score weighted by the official exam blueprint

Get full access to ISC2 CC Certified in Cybersecurity

All questions, timed exams, flashcards, PDF study guide download & progress tracking.

This course

$9.99

one-time

Pass or refund
Create account and buy

30 seconds, then straight to checkout.

Until 30 November

Lifetime · all courses

$29.99

One payment · future courses included

Create account and buy

30 seconds, then straight to checkout.

PASS GUARANTEEOR MONEY BACK

Pass, or your money back

Reach 85% readiness on this course, sit the real exam, and if you don't pass we refund it in full. Applies to this single-course purchase. Terms.

More free samples

Marked, and passed

Real feedback from people who passed

“I failed my CISSP on the first attempt with another platform. Switched to CertCrush, focused on my weak domains using the tracking feature, and passed three months later. The explanations for wrong answers are genuinely useful, not just 'A is correct because A is correct'.”
MTMarcus T.ISC² CISSP
“Honestly wasn't expecting much but this is probably the best ten bucks I've spent on exam prep. Did 20–30 questions every morning before work for 6 weeks. Passed with a comfortable margin. The timed exam mode is what really got me comfortable with the pressure.”
PSPriya S.CompTIA Security+
“The flashcards are underrated. I used them during my commute and it made a huge difference for the theory-heavy ITIL questions. Passed first try. Already using it again for CISM.”
JRJames R.ITIL 5 Foundation

The ISC2 Certified in Cybersecurity (CC) is an entry-level, vendor-neutral certification designed to validate the foundational knowledge of individuals new to the field by testing their grasp of core principles like network security, access controls, and incident response.

Practice content last updated · Independently written and aligned to ISC2’s published exam objectives.

About the ISC2 CC Certified in Cybersecurity Exam

ISC2 Certified in Cybersecurity (CC) is an entry-level, vendor-neutral certification for people starting a cybersecurity career, and it requires no prior work experience. It validates foundational understanding of security principles, business continuity and incident response, access controls, network security, and security operations — the vocabulary and concepts that every security role assumes you already have. CC is aimed at students, career changers, and IT staff moving into a security function, as well as professionals whose existing roles have picked up security responsibility. Unlike ISC2's advanced credentials, there is no experience prerequisite: you pass the exam, agree to the ISC2 Code of Ethics, and maintain the certification with annual CPE credits. It is a common first step before CompTIA Security+, or on the longer path towards SSCP and CISSP. CertCrush gets you exam-ready with a free ISC2 CC practice test experience: realistic practice questions, timed mock exams and a clear explanation for every answer.

Exam Domains Covered

  • Security Principles24%
  • Security Governance17%
  • Identity and Access Management (IAM) Concepts20%
  • Networking and Cloud Security Concepts21%
  • Security Operations and Incident Response17%

Exam Format & Details

The ISC2 CC exam is delivered as a Computerised Adaptive Test (CAT) of 100 to 125 questions with a two-hour time limit. Because it adapts, the questions get harder or easier in response to your answers, and you cannot skip a question, flag it, or return to an earlier one — so budget your time per question rather than planning a review pass. The passing score is a scaled 700 out of 1000; there is no percentage pass mark. The exam is delivered at Pearson VUE test centres and is available in English, Chinese, Japanese, German and Spanish. Under the outline effective 1 September 2026 it covers five domains: Security Principles (24%), Security Governance (17.3%), Identity and Access Management (IAM) Concepts (20%), Networking and Cloud Security Concepts (21.3%) and Security Operations and Incident Response (17.3%). This replaced the previous outline and moved several topics: business continuity and disaster recovery now sit under Security Governance alongside security awareness and cybersecurity metrics, while encryption, data handling and security testing sit under Security Operations and Incident Response. If you are revising from older material, check which domain a topic now belongs to. Exam registration costs $199 USD. There is no work-experience requirement, but certified members agree to the ISC2 Code of Ethics and maintain the credential with annual CPEs.

Why Practice Questions Matter

CC tests recognition of core concepts rather than hands-on skill, which makes it easy to underestimate. Questions use precise ISC2 terminology, and many turn on telling closely related terms apart — a control type, a recovery objective, an access model — where a plain-English reading of the options will not separate them. Candidates new to the field often understand the idea but not the exact word ISC2 expects for it. CertCrush CC questions drill that vocabulary against the published domain weighting, with explanations that define the term and place it within the concept it belongs to.

Sample Practice Questions

The following questions are a preview of the type of syllabus-aligned questions you will practise in CertCrush. They reflect the format and reasoning style of the ISC2 CC Certified in Cybersecurity exam, not actual exam content.

Q1.An organization experiences a ransomware attack that encrypts all file servers. The security team isolates affected systems and begins recovery from clean backups. Meanwhile, management activates a plan that allows employees to access critical documents from a cloud-based backup service to maintain client deliverables. The plan that allows continued client deliverables is BEST described as part of the:

  • A.Disaster recovery plan
  • B.Business continuity plan
  • C.Incident response plan
  • D.Risk management plan

Domain: Security Governance

Q2.A new helpdesk technician joins the IT department. Rather than manually configuring permissions for each system, the administrator assigns the technician to the 'Helpdesk Technician' role, which automatically grants access to the ticketing system, password reset tools, and account unlock functions. When the technician later transfers to the Network Operations team, the administrator removes them from the Helpdesk role and adds them to the Network Operations role. This process demonstrates a key advantage of RBAC, which is:

  • A.Preventing all insider threats through mandatory classification labels
  • B.Simplifying provisioning and role transitions through role assignment and removal
  • C.Allowing individual resource owners to share access at their own discretion
  • D.Evaluating multiple contextual attributes and conditions before granting access

Domain: Identity and Access Management (IAM) Concepts

Q3.A manufacturing company identifies a critical vulnerability in its production control system. The vendor will not release a patch for three months. Management decides to implement compensating controls to reduce the risk while also purchasing insurance to cover potential losses. Which risk treatment options are being applied? (Select ALL that apply.)

  • A.Risk acceptance
  • B.Risk mitigation
  • C.Risk transfer
  • D.Risk avoidance

Domain: Security Principles

Q4.A development team performs threat modeling on a new web application and identifies that an unauthenticated user could potentially escalate their access to administrator level through a flaw in the session management design. This finding was identified BEFORE any code was written. What is the PRIMARY benefit of discovering this threat at this stage?

  • A.It eliminates the need for any penetration testing once the application has been deployed
  • B.It allows the design to be corrected before code is written, which costs far less than fixing later
  • C.It proves the application is secure by design, so no further security testing will be needed
  • D.It satisfies every regulatory compliance requirement that will apply to the finished application code

Domain: Security Operations and Incident Response

Q5.An organization migrates its database to an IaaS cloud environment but fails to apply operating system patches, assuming the cloud provider handles all security. After a breach exploiting an unpatched OS vulnerability, who bears primary responsibility for this failure?

  • A.The cloud provider, because they host the infrastructure
  • B.The customer, because OS patching is a customer responsibility in IaaS
  • C.Both equally, because security is always a shared responsibility
  • D.Neither, because the vulnerability was in the OS vendor's code

Domain: Networking and Cloud Security Concepts

Q6.The CISO reports to the CEO and presents security strategy to the board of directors. A cross-functional committee including representatives from IT, legal, finance, and HR meets quarterly to review security priorities. What governance roles do these describe?

  • A.Chief Information Security Officer
  • B.Security steering committee
  • C.Incident response team
  • D.Security operations center

Domain: Security Governance

Q7.A user in the RBAC 'Auditor' role has been given temporary access to the 'System Administrator' role to assist with a project. At the end of the project, the System Administrator role is not removed. What principle is violated when this combined access allows the auditor to both configure systems and audit those same configurations?

  • A.Principle of Least Privilege
  • B.Separation of Duties
  • C.Need-to-know principle
  • D.Defense in depth

Domain: Identity and Access Management (IAM) Concepts

Q8.An organization has a general willingness to accept moderate cybersecurity risk. However, for any risk involving customer payment card data, the organization has stated that no data breaches are acceptable and all vulnerabilities must be remediated within 24 hours. The 24-hour remediation requirement for payment card data represents the organization's:

  • A.Risk appetite
  • B.Risk tolerance
  • C.Risk avoidance
  • D.Risk transfer

Domain: Security Principles

Q9.A security team blocks malicious email attachments at the gateway to prevent a threat actor from reaching users. They also monitor outbound DNS traffic for C2 indicators and conduct regular phishing simulations. Which Cyber Kill Chain stages are these defenses designed to disrupt? (Select TWO)

  • A.Reconnaissance
  • B.Delivery
  • C.Installation
  • D.Command and Control

Domain: Security Operations and Incident Response

Q10.A company divides its internal network so that workstations are separated from servers, finance systems are isolated from general workstations, and backup systems are on their own segment with no inbound connections from workstations. What network security concept does this implement?

  • A.Defense in depth
  • B.Network segmentation
  • C.Zero trust architecture
  • D.Encryption at rest

Domain: Networking and Cloud Security Concepts

ISC2 CC Certified in Cybersecurity guides & exam news

Frequently Asked Questions

What is included in the free ISC2 CC Certified in Cybersecurity sample?

The free sample includes 10 syllabus-aligned practice questions, sample flashcards, and a preview chapter from the study guide. No account or payment is required to try the sample.

How many questions are in the full ISC2 CC Certified in Cybersecurity course?

The full ISC2 CC Certified in Cybersecurity course includes 645 practice questions, covering all 5 exam domains. Every question carries a full explanation for the right answer and the wrong ones.

Are these official ISC2 exam questions?

No. CertCrush questions are independently written and syllabus-aligned. They mirror the format, difficulty, and reasoning style of the official exam. We are not affiliated with or endorsed by ISC2.

Which domains does the ISC2 CC Certified in Cybersecurity course cover?

The course covers 5 exam domains: Security Principles, Security Governance, Identity and Access Management (IAM) Concepts, Networking and Cloud Security Concepts, Security Operations and Incident Response.

Can I study on mobile?

Yes. CertCrush is fully responsive and works on phones, tablets, and desktops. The timed exam, flashcards, and study guide all work on mobile without installing an app.

What happens when I create an account?

Creating a free account lets you access full courses, track your weak areas by domain, and resume practice sessions across devices. No credit card is required to register.

Start with 10 free questions

No account, no card. The full ISC2 CC Certified in Cybersecurity course is $9.99, once.

Start freeBuy · $9.99