Try ISC2 CC Certified in Cybersecurity
Get a taste before you commit — no account needed. Then a free account unlocks 25 questions with readiness tracking, no card required.
Get full access to ISC2 CC Certified in Cybersecurity
All questions, timed exams, flashcards, PDF study guide download & progress tracking.
This course
$9.99
one-time
Monthly
$12.99
per month · all courses
Takes 30 seconds — create a free account, then straight to checkout. Already have an account? Sign in
ISC2 · Exam reference
About the ISC2 CC Certified in Cybersecurity exam
The ISC2 Certified in Cybersecurity (CC) is an entry-level, vendor-neutral certification designed to validate the foundational knowledge of individuals new to the field by testing their grasp of core principles like network security, access controls, and incident response.
10
Sample questions
120 min
Exam time limit
70%
Passing score
$392
Exam voucher
CompTIA Security+ (SY0-701) is the most widely held entry-level cybersecurity certification in the world, and the baseline standard for IT security roles across both the private sector and US federal government. It is approved under DoD 8570/8140, making it a mandatory requirement for many defence and government contractor positions. Security+ validates that you can assess the security posture of an enterprise environment, recommend and implement appropriate security solutions, monitor and secure hybrid environments, and respond to security incidents. The exam covers five domains: Security Principles; Security Governance; IAM Concepts; Networking and Cloud Security; and Security Operations and IR. Security+ is vendor-neutral, meaning the skills it certifies apply across all technology platforms and cloud providers. It is the ideal next step after CompTIA Network+ or for IT professionals moving into a dedicated security role.
Exam Domains Covered
Exam Format & Details
The CompTIA Security+ exam (SY0-701) consists of a maximum of 90 questions, including multiple-choice and performance-based questions (PBQs). The time limit is 90 minutes. The passing score is 750 on a scale of 100–900. The exam is available at Pearson VUE test centres worldwide or via online proctoring. The exam voucher costs $392 USD. CompTIA recommends (but does not require) CompTIA Network+ certification and two years of IT experience with a security focus before sitting Security+. Results are available immediately for computer-based testing.
Why Practice Questions Matter
Security+ uses performance-based questions (PBQs) alongside multiple-choice, which means some questions require you to interact with simulated environments — configuring firewalls, analysing logs, or identifying vulnerabilities in a network diagram. You cannot pass Security+ through memorisation alone. Timed practice builds the fluency you need to move through scenario questions quickly and confidently. CertCrush questions are written to match the SY0-701 domain weighting, so your practice time targets the areas that actually appear on the exam.
Sample Practice Questions
The following questions are a preview of the type of syllabus-aligned questions you will practise in CertCrush. They reflect the format and reasoning style of the ISC2 CC Certified in Cybersecurity exam — not actual exam content.
Q1.An organization experiences a ransomware attack that encrypts all file servers. The security team isolates affected systems and begins recovery from clean backups. Meanwhile, management activates a plan that allows employees to access critical documents from a cloud-based backup service to maintain client deliverables. The plan that allows continued client deliverables is BEST described as part of the:
- A.Disaster recovery plan
- B.Business continuity plan
- C.Incident response plan
- D.Risk management plan
Domain: Security Governance
Q2.A new helpdesk technician joins the IT department. Rather than manually configuring permissions for each system, the administrator assigns the technician to the 'Helpdesk Technician' role, which automatically grants access to the ticketing system, password reset tools, and account unlock functions. When the technician later transfers to the Network Operations team, the administrator removes them from the Helpdesk role and adds them to the Network Operations role. This process demonstrates a key advantage of RBAC, which is:
- A.Preventing all insider threats through mandatory classification labels
- B.Simplifying provisioning and role transitions through role assignment and removal
- C.Allowing resource owners to share access at their discretion
- D.Evaluating multiple contextual attributes before granting access
Domain: IAM Concepts
Q3.A manufacturing company identifies a critical vulnerability in its production control system. The vendor will not release a patch for three months. Management decides to implement compensating controls to reduce the risk while also purchasing insurance to cover potential losses. Which risk treatment options are being applied? (Select ALL that apply.)
- A.Risk acceptance
- B.Risk mitigation
- C.Risk transfer
- D.Risk avoidance
Domain: Security Principles
Q4.A development team performs threat modeling on a new web application and identifies that an unauthenticated user could potentially escalate their access to administrator level through a flaw in the session management design. This finding was identified BEFORE any code was written. What is the PRIMARY benefit of discovering this threat at this stage?
- A.It eliminates the need for penetration testing after deployment
- B.It allows the design to be corrected before code is written, which is more cost-effective than fixing it after deployment
- C.It proves the application is secure and no further testing is needed
- D.It satisfies all regulatory compliance requirements for the application
Domain: Security Operations and IR
Q5.An organization migrates its database to an IaaS cloud environment but fails to apply operating system patches, assuming the cloud provider handles all security. After a breach exploiting an unpatched OS vulnerability, who bears primary responsibility for this failure?
- A.The cloud provider, because they host the infrastructure
- B.The customer, because OS patching is a customer responsibility in IaaS
- C.Both equally, because security is always a shared responsibility
- D.Neither, because the vulnerability was in the OS vendor's code
Domain: Networking and Cloud Security
Frequently Asked Questions
What is included in the free ISC2 CC Certified in Cybersecurity sample?
The free sample includes 10 syllabus-aligned practice questions, sample flashcards, and a preview chapter from the study guide. No account or payment is required to try the sample.
How many questions are in the full ISC2 CC Certified in Cybersecurity course?
The full course includes a comprehensive question bank covering all exam domains. You can see the total question count on the ISC2 CC Certified in Cybersecurity course page.
Are these official ISC2 exam questions?
No. CertCrush questions are independently written and syllabus-aligned — they mirror the format, difficulty, and reasoning style of the official exam. We are not affiliated with or endorsed by ISC2.
Which domains does the ISC2 CC Certified in Cybersecurity course cover?
The course covers 5 exam domains: Security Principles, Security Governance, IAM Concepts, Networking and Cloud Security, Security Operations and IR.
Can I study on mobile?
Yes. CertCrush is fully responsive and works on phones, tablets, and desktops. The timed exam, flashcards, and study guide all work on mobile without installing an app.
What happens when I create an account?
Creating a free account lets you access full courses, track your weak areas by domain, and resume practice sessions across devices. No credit card is required to register.