Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-COUNCIL

EC-Council Certified Cybersecurity Technician

CCT

The EC-Council Certified Cybersecurity Technician (CCT) is an entry-level certification that validates hands-on technical skills across network defense, ethical hacking, digital forensics, and security operations. Designed for aspiring cybersecurity technicians and IT professionals transitioning into cyber roles, it features 85 hands-on labs and a performance-based, CTF-style exam delivered in a live cyber range. Earning the CCT proves you have the practical, job-ready skills to contribute to a cybersecurity team from day one.

1060 practice questions · Updated 2025-01-01

8Domains
22Objectives
203Concepts
1060Questions

CCT Curriculum

Every domain, objective, and concept the CCT exam measures.

  1. Threat Landscape
  2. Vulnerability Fundamentals
  3. Attack Vectors and Surfaces
  4. Threat Actors and Motivations
  5. Vulnerability Assessment
  6. Risk and Impact Analysis
  7. Mitigation Strategies

Information Security Attacks

6 concepts · 41 questions
  1. Attack Vectors
  2. Attack Types
  3. Attack Lifecycle
  4. Threat Actors
  5. Attack Motivations
  6. Impact of Attacks

Network Security Fundamentals

7 concepts · 43 questions
  1. Network Fundamentals
  2. Network Devices
  3. Network Protocols
  4. Network Addressing
  5. Network Security Threats
  6. Network Security Controls
  7. Secure Network Design

  1. Identification
  2. Authentication
  3. Authorization
  4. Authentication Factors
  5. Multi-Factor Authentication (MFA)
  6. Authentication Methods
  7. Access Control Models
  8. Identity and Access Management (IAM)
  1. Administrative Controls Overview
  2. Security Policies
  3. Security Standards and Baselines
  4. Security Procedures
  5. Security Guidelines
  6. Risk Management
  7. Security Awareness Training
  8. Separation of Duties
  9. Least Privilege Principle
  10. Change Management
  11. Incident Response Planning
  12. Business Continuity and Disaster Recovery
  13. Compliance and Auditing
  1. Physical Security Controls Overview
  2. Access Control Mechanisms
  3. Surveillance Systems
  4. Environmental Controls
  5. Perimeter Security
  6. Physical Security Policies
  1. Technical Controls Overview
  2. Access Control Mechanisms
  3. Firewalls
  4. Intrusion Detection and Prevention Systems
  5. Virtual Private Networks
  6. Network Segmentation
  7. Network Access Control
  8. Proxy Servers
  9. Honeypots and Honeynets
  10. Security Information and Event Management
  11. Endpoint Security Controls
  12. Wireless Security Controls
  13. Data Loss Prevention
  14. Unified Threat Management

  1. Network Security Assessment Overview
  2. Assessment Types
  3. Assessment Methodology
  4. Reconnaissance Techniques
  5. Scanning Tools
  6. Enumeration Techniques
  7. Vulnerability Scanning Tools
  8. Exploitation Frameworks
  9. Password Attacks
  10. Wireless Assessment Tools
  11. Web Application Assessment Tools
  12. Reporting and Remediation

Application Security

10 concepts · 51 questions
  1. Application Security Fundamentals
  2. Common Application Threats
  3. Secure Coding Practices
  4. Authentication and Authorization
  5. Data Protection and Encryption
  6. Application Security Testing
  7. Web Application Firewalls (WAF)
  8. API Security
  9. Secure Deployment and Configuration
  10. Incident Response for Applications

Virtualization and Cloud Computing

8 concepts · 41 questions
  1. Virtualization Fundamentals
  2. Types of Virtualization
  3. Cloud Computing Models
  4. Cloud Deployment Models
  5. Cloud Security Considerations
  6. Virtualization Security
  7. Cloud Architecture Components
  8. Cloud Service Providers and Offerings

Wireless Network Security

7 concepts · 48 questions
  1. Wireless Network Fundamentals
  2. Wireless Security Protocols
  3. Wireless Authentication Methods
  4. Wireless Encryption Mechanisms
  5. Wireless Threats and Attacks
  6. Wireless Security Best Practices
  7. Wireless Network Monitoring and Auditing

Mobile Device Security

8 concepts · 43 questions
  1. Mobile Device Security Fundamentals
  2. Mobile Device Management (MDM)
  3. Mobile Application Security
  4. Mobile Device Encryption and Data Protection
  5. Mobile Device Authentication and Access Control
  6. Mobile Device Network Security
  7. Mobile Device Compliance and Policy Enforcement
  8. Mobile Device Incident Response and Forensics

IoT and OT Security

12 concepts · 51 questions
  1. IoT Architecture
  2. OT Architecture
  3. IoT Communication Protocols
  4. OT Protocols
  5. IoT Attack Surface
  6. OT Attack Surface
  7. IoT Security Challenges
  8. OT Security Challenges
  9. IoT Security Best Practices
  10. OT Security Best Practices
  11. IoT and OT Risk Management
  12. IoT and OT Compliance

Cryptography

8 concepts · 45 questions
  1. Cryptography Fundamentals
  2. Symmetric Encryption
  3. Asymmetric Encryption
  4. Hash Functions
  5. Digital Signatures
  6. Key Management
  7. Public Key Infrastructure (PKI)
  8. Cryptographic Attacks

Data Security

10 concepts · 49 questions
  1. Data Security Fundamentals
  2. Data Classification
  3. Data States
  4. Data Encryption
  5. Data Masking
  6. Data Erasure
  7. Data Backup and Recovery
  8. Data Retention Policies
  9. Data Loss Prevention (DLP)
  10. Data Privacy and Compliance

Network Troubleshooting

10 concepts · 51 questions
  1. Troubleshooting Methodology
  2. Common Network Issues
  3. Troubleshooting Tools
  4. Physical Layer Troubleshooting
  5. Data Link Layer Troubleshooting
  6. Network Layer Troubleshooting
  7. Transport Layer Troubleshooting
  8. Application Layer Troubleshooting
  9. Wireless Network Troubleshooting
  10. Documentation and Reporting

Network Traffic Monitoring

8 concepts · 45 questions
  1. Traffic Monitoring Fundamentals
  2. Traffic Capture Techniques
  3. Packet Analysis Basics
  4. Flow Data Analysis
  5. Monitoring Tools
  6. Traffic Metrics and KPIs
  7. Anomaly Detection
  8. Troubleshooting with Traffic Data

Network Logs Monitoring and Analysis

10 concepts · 56 questions
  1. Log Sources and Types
  2. Log Collection and Aggregation
  3. Log Normalization and Parsing
  4. Log Retention and Storage
  5. Log Analysis Techniques
  6. Correlation of Log Events
  7. Log Monitoring Tools
  8. Alerting and Reporting
  9. Troubleshooting with Logs
  10. Security and Privacy Considerations

Incident Response

8 concepts · 50 questions
  1. Incident Response Fundamentals
  2. Incident Response Phases
  3. Incident Response Team Roles
  4. Incident Classification and Prioritization
  5. Incident Response Procedures
  6. Evidence Handling in Incident Response
  7. Incident Documentation and Reporting
  8. Post-Incident Activities

Computer Forensics

13 concepts · 56 questions
  1. Forensic Fundamentals
  2. Forensic Investigation Process
  3. Evidence Collection and Preservation
  4. Chain of Custody
  5. Forensic Imaging and Duplication
  6. Data Acquisition Methods
  7. Forensic Analysis Techniques
  8. File System Forensics
  9. Memory Forensics
  10. Network Forensics
  11. Mobile Device Forensics
  12. Anti-Forensics and Countermeasures
  13. Forensic Reporting and Testimony

  1. Business Continuity Planning (BCP) Fundamentals
  2. Disaster Recovery Planning (DRP) Fundamentals
  3. Business Impact Analysis (BIA)
  4. Risk Assessment in BCP/DRP
  5. Recovery Time Objective (RTO)
  6. Recovery Point Objective (RPO)
  7. BCP/DRP Strategies
  8. BCP/DRP Plan Development
  9. BCP/DRP Testing and Maintenance
  10. Incident Response and Communication

Risk Management

8 concepts · 39 questions
  1. Risk Management Fundamentals
  2. Risk Identification
  3. Risk Assessment Methodologies
  4. Risk Analysis Techniques
  5. Risk Response Strategies
  6. Risk Monitoring and Review
  7. Risk Management Frameworks
  8. Risk Documentation and Reporting
Ready to practice?Test your knowledge with exam-style questions or take an intelligent quiz tailored to your level.

Percentages reflect share of the current practice bank, not official exam weightings — no structured per-skill weight is published for CCT, so none is invented.