
Certified in Cybersecurity
Domain 5Objective 3
5.3 - Understand Best Practice Security Policies CC Practice Questions (Page 6)
Part of the Security Operations domain, which accounts for 18% of the CC exam. ISC2 does not publish an official question count, but from its 120-minute exam (~50–80 total, ~9–14 in this domain), expect 2–4 from this objective — we provide 30 practice questions to prepare you well beyond it. (estimate)
30questions here
6free pages
6concepts
18%of the exam
Questions 26–30
- 26
How does a privacy policy help an organization ensure compliance?
Select an answer first - 27
A government agency handles sensitive citizen data. The agency is required to retain certain records for a specific period and then securely destroy them. The agency also needs to ensure that data is only accessible to authorized personnel. Which data handling policy elements are most critical to implement?
Select an answer first - 28
A marketing firm allows employees to use their personal smartphones for work email and calendar. The firm wants to ensure that if a device is lost or stolen, the corporate data on it can be protected. They also want to prevent employees from storing sensitive client files on personal cloud storage. Which BYOD policy controls should be implemented?
Select an answer first - 29
Why is multi-factor authentication (MFA) often included in a strong password policy?
Select an answer first - 30
What is the primary purpose of a privacy policy?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to CC
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CC” is a trademark of its owner, used for identification only.