
Certified in Cybersecurity
Domain 1Objective 3
1.3 - Understand Security Controls CC Practice Questions (Page 1)
Part of the Security Principles domain, which accounts for 26% of the CC exam. ISC2 does not publish an official question count, but from its 120-minute exam (~50–80 total, ~13–21 in this domain), expect 3–4 from this objective — we provide 12 practice questions to prepare you well beyond it. (estimate)
12questions here
3free pages
3concepts
26%of the exam
Questions 1–5
- 1
A startup wants to ensure that only authorized employees can access its cloud-based project management tool. The CEO approves a policy requiring all employees to use single sign-on (SSO) with the company's identity provider. Which control is the SSO implementation?
Select an answer first - 2
An online retailer stores customer payment data. To protect this data, the company encrypts the database and requires all employees to use a password manager. The security team also conducts quarterly access reviews to ensure only current employees have database credentials. Which control is the quarterly access review?
Select an answer first - 3
Which of the following is the best example of a technical control?
Select an answer first - 4
A data center operator wants to prevent unauthorized individuals from physically accessing the server racks. They install biometric scanners on the doors to the server room and require a valid employee badge to enter the building. Which control category is the biometric scanner primarily considered?
Select an answer first - 5
Which of the following is an example of an administrative control?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CC” is a trademark of its owner, used for identification only.