
Certified in Cybersecurity
The Certified in Cybersecurity (CC) from ISC2 is the entry-level credential for anyone starting a career in cybersecurity — no prior experience required. It validates foundational knowledge across security principles, network security, access controls, and security operations. Earning the CC demonstrates to employers that you have the core skills and passion to succeed in an entry- or junior-level cybersecurity role, and it opens a clear pathway to advanced ISC2 certifications like the CISSP.
417 practice questions · Updated 2026-07-30
CC Curriculum
Every domain, objective, and concept the CC exam measures.
- Confidentiality
- Integrity
- Availability
- Authentication Methods
- Multi-Factor Authentication (MFA)
- Non-repudiation
- Privacy
- Risk management process
- Risk priorities
- Risk tolerance
- Risk identification
- Risk assessment
- Risk treatment
- Technical controls
- Administrative controls
- Physical controls
- ISC2 Code of Ethics overview
- Four canons of the ISC2 Code of Ethics
- Application of the Code of Ethics
- Consequences of ethical violations
- Policies
- Procedures
- Standards
- Regulations and Laws
- Purpose of Business Continuity
- Importance of Business Continuity
- Components of Business Continuity
- Purpose of Disaster Recovery
- Importance of Disaster Recovery
- Components of Disaster Recovery
- Purpose of Incident Response
- Importance of Incident Response
- Components of Incident Response
- Incident Response Phases
- Incident Response Team Roles
- Incident Response Plan Development
- Incident Detection and Analysis
- Containment, Eradication, and Recovery
- Post-Incident Activities
- Physical security controls
- Monitoring systems
- Authorized vs. unauthorized personnel
- Principle of least privilege
- Segregation of duties
- Discretionary access control (DAC)
- Mandatory access control (MAC)
- Role-based access control (RBAC)
- OSI model
- TCP/IP model
- IPv4 addressing
- IPv6 addressing
- WiFi fundamentals
- Common network ports
- Network applications
- DDoS
- Virus
- Worm
- Trojan
- Man-in-the-Middle (MITM)
- Side-channel attack
- Intrusion Detection System (IDS)
- Host-based IDS (HIDS)
- Network-based IDS (NIDS)
- Antivirus
- Vulnerability scanning
- Firewalls
- Intrusion Prevention System (IPS)
- On-premises infrastructure components
- MOU/MOA in network security
- Network segmentation concepts
- Defense in depth strategy
- Network Access Control (NAC)
- Cloud service models
- Cloud deployment and agreements
- Symmetric Encryption
- Asymmetric Encryption
- Hashing
- Data Classification
- Data Labeling
- Data Retention
- Data Destruction
- Logging Security Events
- Monitoring Security Events
- Configuration management fundamentals
- Security baselines
- Baseline implementation
- Patch management
- Update management
- Configuration change control
- Data handling policy
- Password policy
- Acceptable Use Policy (AUP)
- Bring your own device (BYOD) policy
- Change management policy
- Privacy policy
- Purpose of security awareness training
- Social engineering awareness
- Password protection best practices
- Importance of security awareness training
Percentages reflect share of the current practice bank, not official exam weightings — no structured per-skill weight is published for CC, so none is invented.