Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISC2

Certified in Cybersecurity

CCCertified In Cybersecurity (CC)

The Certified in Cybersecurity (CC) from ISC2 is the entry-level credential for anyone starting a career in cybersecurity — no prior experience required. It validates foundational knowledge across security principles, network security, access controls, and security operations. Earning the CC demonstrates to employers that you have the core skills and passion to succeed in an entry- or junior-level cybersecurity role, and it opens a clear pathway to advanced ISC2 certifications like the CISSP.

417 practice questions · Updated 2026-07-30

5Domains
17Objectives
99Concepts
417Questions

CC Curriculum

Every domain, objective, and concept the CC exam measures.

  1. Confidentiality
  2. Integrity
  3. Availability
  4. Authentication Methods
  5. Multi-Factor Authentication (MFA)
  6. Non-repudiation
  7. Privacy
  1. Risk management process
  2. Risk priorities
  3. Risk tolerance
  4. Risk identification
  5. Risk assessment
  6. Risk treatment

1.3 - Understand security controls

3 concepts · 12 questions
  1. Technical controls
  2. Administrative controls
  3. Physical controls

1.4 - Understand ISC2 Code of Ethics

4 concepts · 23 questions
  1. ISC2 Code of Ethics overview
  2. Four canons of the ISC2 Code of Ethics
  3. Application of the Code of Ethics
  4. Consequences of ethical violations

1.5 - Understand governance processes

4 concepts · 16 questions
  1. Policies
  2. Procedures
  3. Standards
  4. Regulations and Laws

  1. Purpose of Business Continuity
  2. Importance of Business Continuity
  3. Components of Business Continuity

2.2 - Understand disaster recovery (DR)

3 concepts · 13 questions
  1. Purpose of Disaster Recovery
  2. Importance of Disaster Recovery
  3. Components of Disaster Recovery

2.3 - Understand incident response

9 concepts · 34 questions
  1. Purpose of Incident Response
  2. Importance of Incident Response
  3. Components of Incident Response
  4. Incident Response Phases
  5. Incident Response Team Roles
  6. Incident Response Plan Development
  7. Incident Detection and Analysis
  8. Containment, Eradication, and Recovery
  9. Post-Incident Activities

  1. Physical security controls
  2. Monitoring systems
  3. Authorized vs. unauthorized personnel
  1. Principle of least privilege
  2. Segregation of duties
  3. Discretionary access control (DAC)
  4. Mandatory access control (MAC)
  5. Role-based access control (RBAC)

4.1 - Understand computer networking

7 concepts · 24 questions
  1. OSI model
  2. TCP/IP model
  3. IPv4 addressing
  4. IPv6 addressing
  5. WiFi fundamentals
  6. Common network ports
  7. Network applications
  1. DDoS
  2. Virus
  3. Worm
  4. Trojan
  5. Man-in-the-Middle (MITM)
  6. Side-channel attack
  7. Intrusion Detection System (IDS)
  8. Host-based IDS (HIDS)
  9. Network-based IDS (NIDS)
  10. Antivirus
  11. Vulnerability scanning
  12. Firewalls
  13. Intrusion Prevention System (IPS)
  1. On-premises infrastructure components
  2. MOU/MOA in network security
  3. Network segmentation concepts
  4. Defense in depth strategy
  5. Network Access Control (NAC)
  6. Cloud service models
  7. Cloud deployment and agreements

5.1 - Understand data security

9 concepts · 35 questions
  1. Symmetric Encryption
  2. Asymmetric Encryption
  3. Hashing
  4. Data Classification
  5. Data Labeling
  6. Data Retention
  7. Data Destruction
  8. Logging Security Events
  9. Monitoring Security Events

5.2 - Understand system hardening

6 concepts · 26 questions
  1. Configuration management fundamentals
  2. Security baselines
  3. Baseline implementation
  4. Patch management
  5. Update management
  6. Configuration change control
  1. Data handling policy
  2. Password policy
  3. Acceptable Use Policy (AUP)
  4. Bring your own device (BYOD) policy
  5. Change management policy
  6. Privacy policy
  1. Purpose of security awareness training
  2. Social engineering awareness
  3. Password protection best practices
  4. Importance of security awareness training
Ready to practice?Test your knowledge with exam-style questions or take an intelligent quiz tailored to your level.

Percentages reflect share of the current practice bank, not official exam weightings — no structured per-skill weight is published for CC, so none is invented.