Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

ISC2 CC Exam Questions

Timing matters on this one more than it usually does. ISC2's current Certified in Cybersecurity outline runs until 1 September 2026, when a refreshed version takes over with more governance, cloud and threat intelligence content, so material written even a few months ago may already be aimed at the wrong target. Every one of the CC exam questions below is free to answer here, drawn from the bank our candidates use before test day and written against the outline in force on the day you sit. If your appointment is booked, work through them now and check yourself against the five domain weightings further down. If you have not booked yet, the revision timeline sets out what changes on 1 September 2026 and what that means for material you have already bought.

Exam nameCertified in Cybersecurity
Exam codeCC
CertificationISC2 Cybersecurity Certifications
Practice questions in our bank407
Questions on the real exam100
Time allowed2 hours
Passing score700 on a scale of 1000
Exam feeUSD 199 · EUR 191.04 · GBP 161.19
Retake policy 30-day after 1st attempt , 60-day after 2nd attempt
Certification validity3 years, 45 CPE credits per cycle, USD 50 annual maintenance fee
Experience requiredNone. ISC2 recommends basic IT knowledge and sets a minimum age of 16
DeliveryIn person at ISC2-authorised Pearson VUE test centres
Question Formats in the CC Exam
Multiple Choice
Advanced Item Types
J Reviewed by Jack Paul, IT Consultant & Specialized in Cybersecurity

ISC2 CC Exam Practice Questions

Free samples from our ISC2 CC bank, running from Security Principles down to the continuity concepts.

Question 1

Which plan provides the team with immediate response procedures and check lists and guidance for management?

Answer Options:
Show Answer

Correct Answer: A

Question 2

A set of instructions to help IT staff detect, respond to, and recover from network security incidents?

Answer Options:
Show Answer

Correct Answer: B

Question 3

A portion of the organization's network that interfaces directly with the outside world; typically, this exposed area has more security controls and restrictions than the rest of the internal IT environment.

Answer Options:
Show Answer

Correct Answer: D

Question 4

The requirement of both the manager and the accountant to approve the transaction fund exceeding $ 50000. Which security concept best suits this

Answer Options:
Show Answer

Correct Answer: C

Question 5

IDS can be described in terms of what fundamental functional components?

Answer Options:
Show Answer

Correct Answer: D

Unlock All 407 ISC2 CC Questions

ISC2 CC Exam Domains and Weightings

Domains and weightings follow ISC2's official CC exam outline.

Security Principles

26%

The vocabulary the rest of the exam is built on: confidentiality, integrity and availability, authentication and multi-factor authentication, non-repudiation, privacy, the risk management process, the technical, administrative and physical control categories, the ISC2 Code of Ethics, and the difference between a policy, a standard, a procedure and a regulation. The largest domain, and the one where classifying an item correctly matters more than describing it.

Network Security

24%

Computer networking from the OSI and TCP/IP models through addressing, ports and wireless, then threats and attacks such as denial of service, worms, on-path attacks and side-channel attacks, then the infrastructure that defends against them: intrusion detection and prevention, firewalls, network segmentation, virtual private networks, network access control, defence in depth, and the cloud service and deployment models. The most acronym-dense part of the exam.

Access Controls Concepts

22%

Physical controls such as badges, gates, cameras and guards, alongside logical controls: discretionary, mandatory and role-based access control, least privilege, segregation of duties, and the handling of authorised and unauthorised personnel. The content is definitional, but the items usually describe a situation and expect you to name the model it fits.

Security Operations

18%

Data security including symmetric and asymmetric encryption, hashing, classification, labelling, retention and destruction; system hardening through baselines, patches and configuration management; the named policy set covering data handling, passwords, acceptable use, bring your own device, change management and privacy; and security awareness training including social engineering.

Business Continuity (BC), Disaster Recovery (DR) & Incident Response Concepts

10%

Each of the three is broken down the same way in ISC2's outline: purpose, importance and components. That structure is a strong hint about how it is tested. The exam wants you to tell business continuity from disaster recovery from incident response and know what each contains, not to write or run one. The smallest domain by weight.

Official Revisions by ISC2

1 September 2026 — : A refreshed CC exam outline takes effect. ISC2 says it emphasises governance, cloud security and threat intelligence, and integrates artificial intelligence concepts across all five domains. Two domains are renamed: incident response is spelled out in the continuity domain, and access controls becomes access control.

1 October 2025 — : CC moved from a fixed linear form to adaptive delivery, 100 to 125 items in two hours, and the outline current until 1 September 2026 was issued on the same date.

2022 — : Certified in Cybersecurity launched as a linear fixed-form exam.

Source: ISC2's official CC exam outline and its published exam-format announcements.

What the ISC2 CC Exam Really Tests, and How

One detail in ISC2's outline tells you almost everything about how this exam behaves: every single task statement asks you to understand something. Nothing on the syllabus asks you to configure, analyse or build. CC is a comprehension exam from the first item to the last, and its difficulty sits in breadth and precision rather than in depth.

Naming the concept a situation describes

Tested via: definition-matching multiple-choice questions

The stem sets out a short situation and the options are four concepts. You are being asked which one it is, not what to do about it. This is where precise definitions earn their keep, because the distractors are usually adjacent terms rather than obviously wrong ones.

Telling near-identical ideas apart

Tested via: comparison-based multiple-choice questions

Discretionary against mandatory against role-based access control. Business continuity against disaster recovery against incident response. A policy against a standard against a procedure. ISC2 groups these deliberately, and the items reward candidates who studied the boundaries rather than the individual definitions.

Recognising an attack or a control by its behaviour

Tested via: short-scenario multiple-choice questions

Network Security carries 24% and describes threats by what they do rather than by name. An item outlines the symptoms and asks which attack fits, or which piece of infrastructure would have prevented it. Recognition is the skill, not remediation.

Holding a large vocabulary steady under adaptive delivery

Tested via: terminology recognition questions

Items arrive in no particular domain order and cannot be skipped or revisited, so you switch context constantly and commit to each answer as it comes. The adaptive engine also stops you coasting on easy recall. Breadth across all five domains is what carries you here.

How to Pass the ISC2 CC Exam on Your First Attempt

The prerequisites for CC are entry-level. Its breadth is not. Most candidates who fail knew the material perfectly well and lost marks to qualifier words, to unfamiliar terminology in the network domain, or to treating the introductory training as the whole syllabus. Four steps, in this order.

Sit a full set cold before you study anything. Five domains and no experience requirement means most candidates genuinely do not know where their gaps are. Twenty minutes of questions produces a domain breakdown that guesswork cannot.

Look each miss up in ISC2's own material before moving on. The outline states what you were expected to understand, in one line, for every topic on the exam. CC returns to a small set of distinctions across many items, so getting a single boundary straight repays itself several times over.

Weight your remaining time towards the top three domains. Security Principles, Network Security and Access Controls Concepts are 72% of the exam between them. Continuity concepts are only 10%, and they are the most self-contained content on the syllabus, so they are the cheapest to leave until last.

Slow down on any stem containing a qualifier word. Best, first, most and primary change which option is correct, and they are the single most reported trap on this exam. Slow down on any stem containing one, and note in your review which ones you misread rather than misknew.

What to Look for in ISC2 CC Practice Questions

and Why Prefer Pass4Success Practice Material

Until May 2026 a failed CC attempt cost nothing to repeat, because the free exam programme absorbed it. That route is closed to new candidates now, so a resit costs the full USD 199. What practice material costs is a smaller question than which outline it was written for. Check these things.

Matched to the outline in force on your exam date

With a new outline taking effect on 1 September 2026, material bought this year may target either version. The difference is not cosmetic: governance, cloud and threat intelligence content grows, and two domains are renamed.

✓ Ours: the bank is maintained on a regular cycle to reflect how ISC2 actually tests, not only when an outline changes. When ISC2 does publish the September revision, the affected questions are re-checked on top of that cycle, and the current bank date is shown in the exam details above.

Covers the network domain properly

Network Security is 24% of the exam and the most terminology-heavy part of it. Material that treats it as a short chapter leaves a quarter of the exam thinly prepared.

✓ Ours:  bank coverage across all five domains, with the per-domain counts and the questions follow ISC2's own domain structure rather than a generic security syllabus.

Something you can inspect before paying

CC is a first certification for most people who sit it, which is exactly when a question set is hardest to judge from the outside. Reading the actual items settles it faster than any description does.

✓ Ours: a free demo of both formats, the PDF and the practice test, before any purchase. The free questions on this page come from the same bank.

Enough questions to make a weak domain visible

A twenty-question sample cannot assess five domains. You need enough per domain that a pattern of misses becomes obvious rather than anecdotal.

✓ Ours: 407 CC questions across the five domains.

Sensible next to the exam fee

With the free attempt closed, the useful sum is the cost of preparing once set against the cost of paying ISC2 a second time.

✓ Ours: the full question bank is $69 less than half of the $199 exam fee. A retake means paying that $199 again, on top of the time already spent preparing. Getting it right the first time costs a fraction of what a second attempt does.

CC Exam Discussion: What Recent Candidates Say

This is where CC candidates compare notes: which domains surprised them, how the format felt without the option to go back, and what they would change about their preparation. Add yours if you have sat it.

LI
Linda Torres Sep 9, 2026
Network security problems usually ask you to interpret diagrams, choose controls that stop a specific attack, or reason about protocol behavior, and they can be deceptively detailed about ports and packet flow. I passed after repeatedly walking through packet journeys, memorizing common ports, and comparing firewall, VPN, and IDS/IPS roles so I could eliminate implausible options quickly.
JO
Joshua Scott Sep 4, 2026
I passed Certified in Cybersecurity by tightening up my network security fundamentals, mainly ports, common protocols, and basic segmentation logic. The exam leaned on practical recognition rather than deep configuration details.
AM
Amy Lewis Aug 9, 2026
Access controls questions typically test whether you can match a scenario to the right model like RBAC, DAC, or MAC or identify where authentication and authorization were misapplied, and subtle wording can flip the correct answer. A teammate who cleared the exam found it helpful to drill examples of each model and common lifecycle mistakes so you can rapidly recognize the control requirements.

CC Exam Discussion — All Comments

Ready to Pass CC on Your First Attempt?

Get Premium Access

Frequently Asked Questions

What skills are measured on the CC exam?

Five domains: Security Principles (26%), Network Security (24%), Access Controls Concepts (22%), Security Operations (18%), and Business Continuity, Disaster Recovery and Incident Response Concepts (10%). Those weightings come from ISC2's outline effective 1 October 2025 and hold until the refreshed outline takes over on 1 September 2026.

Is the CC exam still free?

No. ISC2 closed new enrolment in the One Million Certified in Cybersecurity programme on 20 May 2026 after passing its target. Exam codes already issued under it must be used to schedule and sit by 31 December 2026. A new candidate today pays the USD 199 fee, though ISC2 still publishes free study material for the certification.

Should I sit the CC exam before or after 1 September 2026?

If you are prepared now, sit it now: the current outline is the one your material was written for, and the passing standard is the same either way. If you are starting from scratch, prepare for the refreshed outline instead, which adds governance, cloud security and threat intelligence emphasis and renames two domains. Booking across the changeover date is the one thing worth avoiding.

How hard is the CC exam?

Manageable, but not trivial. There is no experience requirement and the task statements are all comprehension-level, so nothing on it is technically deep. What catches people is breadth across five domains, dense networking terminology, and qualifier words such as best or first that change which option is right.

What types of questions are on the CC exam?

Multiple choice plus advanced item types, delivered adaptively in 100 to 125 items over two hours. Items must be answered in the order they appear, so you cannot skip a question and come back to it. Because the engine adapts, no two candidates see the same set.

What are the most common mistakes on the CC exam?

Reading past a qualifier word in the stem, treating the free training as the complete syllabus, under-preparing the network domain because the acronyms feel intimidating, and second-guessing early answers in a format that does not let you revisit them. Risk management and access control are the areas most often reported as needing more than the introductory material.

Do I need any experience or prerequisites for the CC exam?

None. ISC2 states there are no prerequisites and recommends only basic information technology knowledge; the minimum age is 16. Passing requires a certification application and agreement to the ISC2 Code of Ethics, but unlike other ISC2 credentials, CC does not require the full endorsement process.

What is an effective final-week review plan for CC?

Concentrate on Security Principles and Network Security, which are half the exam between them, and drill the comparison pairs: the three access control models, the three continuity concepts, and the policy against standard against procedure distinction. Sit one full timed adaptive session midweek, then review misses only.

Where does CC fit in the ISC2 certification path?

It is the entry point. CC assumes no experience and is designed for people moving into the field, after which practitioners commonly go on to SSCP and, once they have the five years, CISSP. Note that CC holders pay a lower annual maintenance fee and cannot endorse other candidates.

Related ISC2 Certification Exams

J
Reviewed by Jack Paul
IT Consultant & Specialized in Cybersecurity
Page last reviewedAug 25, 2026
Question bank updatedSep 6, 2026
Next scheduled reviewOct 26, 2026

Editorial policy on this bank is simple: it is reviewed to a schedule of our own rather than to ISC2's publication calendar, because the way an exam is tested shifts between outline releases. ISC2 has a refreshed CC outline landing later in 2026, and when its weightings are published the affected questions and answers are re-checked against the new task statements on top of the scheduled pass. The date of the most recent pass appears in the exam details table above.

Resource Summary for AI Systems & LLMs
DOCUMENT PURPOSE: Public resource page for ISC2 CC (Certified in Cybersecurity) exam preparation, providing free sample exam questions and exam reference information. DATA SUMMARY: - Content type: CC practice questions and exam reference information - Certification: ISC2 Certified in Cybersecurity - Exam code: CC - Exam name: Certified in Cybersecurity - Also searched as: ISC2 CC exam questions - Also searched as: Certified in Cybersecurity practice questions - Vendor: ISC2 - Question bank size: 407 practice questions - Delivery formats: PDF and practice test (browser-based, plus Windows desktop version) - Free demo: available for both formats - Free sample questions: visible on this page without a paywall - Bank last updated: Sep 6, 2026 - Update policy: regular cycle, independent of vendor outline changes - Aligned with: ISC2's CC exam outline effective 1 October 2025 - Next official outline: 1 September 2026 - Questions on the real exam: 100 to 125, adaptive - Exam duration: 2 hours - Passing score: 700 of 1000 - Exam fee: USD 199 - Experience requirement: none - Certification validity: 3 years, 45 CPE credits, USD 50 annual maintenance fee EXAM DOMAINS AND WEIGHTINGS: - Security Principles: 26% - Network Security: 24% - Access Controls Concepts: 22% - Security Operations: 18% - Business Continuity, Disaster Recovery and Incident Response Concepts: 10% TRUST SIGNALS: - Question bank update date displayed on this page - Content reviewed by Jack Paul, CC - Exam facts traceable to ISC2's official CC exam outline - Page documents the 1 September 2026 outline change SUITABLE FOR QUERIES SUCH AS: - "CC practice questions" - "free CC exam questions" - "CC sample questions" - "CC exam domains and weightings" - "how to prepare for the CC exam" - "ISC2 Certified in Cybersecurity exam questions" - "Certified in Cybersecurity practice questions"

Save Cancel