
Certified in Cybersecurity
Domain 5Objective 4
5.4 - Understand Security Awareness Training CC Practice Questions (Page 2)
Part of the Security Operations domain, which accounts for 18% of the CC exam. ISC2 does not publish an official question count, but from its 120-minute exam (~50–80 total, ~9–14 in this domain), expect 2–4 from this objective — we provide 23 practice questions to prepare you well beyond it. (estimate)
23questions here
5free pages
4concepts
18%of the exam
Questions 6–10
- 6
A financial services firm is required by industry regulations to provide security awareness training to all employees. The training must be documented and completed annually. Which action best demonstrates compliance?
Select an answer first - 7
A company's security team is designing a training module to help employees recognize social engineering. Which scenario should be included to cover the technique of baiting?
Select an answer first - 8
An organization is implementing multi-factor authentication (MFA) for all user accounts. During training, an employee asks why MFA is necessary if they already use a strong password. Which response best explains the value of MFA?
Select an answer first - 9
Which of the following best describes the primary purpose of security awareness training in an organization?
Select an answer first - 10
An employee receives a text message that appears to be from their bank, asking them to click a link to verify their account. The employee is unsure if it is legitimate. What should the employee do?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CC” is a trademark of its owner, used for identification only.