Timing matters on this one more than it usually does. ISC2's current Certified in Cybersecurity outline runs until 1 September 2026, when a refreshed version takes over with more governance, cloud and threat intelligence content, so material written even a few months ago may already be aimed at the wrong target. Every one of the CC exam questions below is free to answer here, drawn from the bank our candidates use before test day and written against the outline in force on the day you sit. If your appointment is booked, work through them now and check yourself against the five domain weightings further down. If you have not booked yet, the revision timeline sets out what changes on 1 September 2026 and what that means for material you have already bought.
| Exam name | Certified in Cybersecurity |
| Exam code | CC |
| Certification | ISC2 Cybersecurity Certifications |
| Practice questions in our bank | 407 |
| Questions on the real exam | 100 |
| Time allowed | 2 hours |
| Passing score | 700 on a scale of 1000 |
| Exam fee | USD 199 · EUR 191.04 · GBP 161.19 |
| Retake policy | 30-day after 1st attempt , 60-day after 2nd attempt |
| Certification validity | 3 years, 45 CPE credits per cycle, USD 50 annual maintenance fee |
| Experience required | None. ISC2 recommends basic IT knowledge and sets a minimum age of 16 |
| Delivery | In person at ISC2-authorised Pearson VUE test centres |
Free samples from our ISC2 CC bank, running from Security Principles down to the continuity concepts.
Which plan provides the team with immediate response procedures and check lists and guidance for management?
Correct Answer: A
A set of instructions to help IT staff detect, respond to, and recover from network security incidents?
Correct Answer: B
A portion of the organization's network that interfaces directly with the outside world; typically, this exposed area has more security controls and restrictions than the rest of the internal IT environment.
Correct Answer: D
The requirement of both the manager and the accountant to approve the transaction fund exceeding $ 50000. Which security concept best suits this
Correct Answer: C
IDS can be described in terms of what fundamental functional components?
Correct Answer: D
Domains and weightings follow ISC2's official CC exam outline.
Security Principles
26%The vocabulary the rest of the exam is built on: confidentiality, integrity and availability, authentication and multi-factor authentication, non-repudiation, privacy, the risk management process, the technical, administrative and physical control categories, the ISC2 Code of Ethics, and the difference between a policy, a standard, a procedure and a regulation. The largest domain, and the one where classifying an item correctly matters more than describing it.
Network Security
24%Computer networking from the OSI and TCP/IP models through addressing, ports and wireless, then threats and attacks such as denial of service, worms, on-path attacks and side-channel attacks, then the infrastructure that defends against them: intrusion detection and prevention, firewalls, network segmentation, virtual private networks, network access control, defence in depth, and the cloud service and deployment models. The most acronym-dense part of the exam.
Access Controls Concepts
22%Physical controls such as badges, gates, cameras and guards, alongside logical controls: discretionary, mandatory and role-based access control, least privilege, segregation of duties, and the handling of authorised and unauthorised personnel. The content is definitional, but the items usually describe a situation and expect you to name the model it fits.
Security Operations
18%Data security including symmetric and asymmetric encryption, hashing, classification, labelling, retention and destruction; system hardening through baselines, patches and configuration management; the named policy set covering data handling, passwords, acceptable use, bring your own device, change management and privacy; and security awareness training including social engineering.
Business Continuity (BC), Disaster Recovery (DR) & Incident Response Concepts
10%Each of the three is broken down the same way in ISC2's outline: purpose, importance and components. That structure is a strong hint about how it is tested. The exam wants you to tell business continuity from disaster recovery from incident response and know what each contains, not to write or run one. The smallest domain by weight.
1 September 2026 — : A refreshed CC exam outline takes effect. ISC2 says it emphasises governance, cloud security and threat intelligence, and integrates artificial intelligence concepts across all five domains. Two domains are renamed: incident response is spelled out in the continuity domain, and access controls becomes access control.
1 October 2025 — : CC moved from a fixed linear form to adaptive delivery, 100 to 125 items in two hours, and the outline current until 1 September 2026 was issued on the same date.
2022 — : Certified in Cybersecurity launched as a linear fixed-form exam.
Source: ISC2's official CC exam outline and its published exam-format announcements.
One detail in ISC2's outline tells you almost everything about how this exam behaves: every single task statement asks you to understand something. Nothing on the syllabus asks you to configure, analyse or build. CC is a comprehension exam from the first item to the last, and its difficulty sits in breadth and precision rather than in depth.
Naming the concept a situation describes
Tested via: definition-matching multiple-choice questionsThe stem sets out a short situation and the options are four concepts. You are being asked which one it is, not what to do about it. This is where precise definitions earn their keep, because the distractors are usually adjacent terms rather than obviously wrong ones.
Telling near-identical ideas apart
Tested via: comparison-based multiple-choice questionsDiscretionary against mandatory against role-based access control. Business continuity against disaster recovery against incident response. A policy against a standard against a procedure. ISC2 groups these deliberately, and the items reward candidates who studied the boundaries rather than the individual definitions.
Recognising an attack or a control by its behaviour
Tested via: short-scenario multiple-choice questionsNetwork Security carries 24% and describes threats by what they do rather than by name. An item outlines the symptoms and asks which attack fits, or which piece of infrastructure would have prevented it. Recognition is the skill, not remediation.
Holding a large vocabulary steady under adaptive delivery
Tested via: terminology recognition questionsItems arrive in no particular domain order and cannot be skipped or revisited, so you switch context constantly and commit to each answer as it comes. The adaptive engine also stops you coasting on easy recall. Breadth across all five domains is what carries you here.
The prerequisites for CC are entry-level. Its breadth is not. Most candidates who fail knew the material perfectly well and lost marks to qualifier words, to unfamiliar terminology in the network domain, or to treating the introductory training as the whole syllabus. Four steps, in this order.
Sit a full set cold before you study anything. Five domains and no experience requirement means most candidates genuinely do not know where their gaps are. Twenty minutes of questions produces a domain breakdown that guesswork cannot.
Look each miss up in ISC2's own material before moving on. The outline states what you were expected to understand, in one line, for every topic on the exam. CC returns to a small set of distinctions across many items, so getting a single boundary straight repays itself several times over.
Weight your remaining time towards the top three domains. Security Principles, Network Security and Access Controls Concepts are 72% of the exam between them. Continuity concepts are only 10%, and they are the most self-contained content on the syllabus, so they are the cheapest to leave until last.
Slow down on any stem containing a qualifier word. Best, first, most and primary change which option is correct, and they are the single most reported trap on this exam. Slow down on any stem containing one, and note in your review which ones you misread rather than misknew.
and Why Prefer Pass4Success Practice Material
Until May 2026 a failed CC attempt cost nothing to repeat, because the free exam programme absorbed it. That route is closed to new candidates now, so a resit costs the full USD 199. What practice material costs is a smaller question than which outline it was written for. Check these things.
Matched to the outline in force on your exam date
With a new outline taking effect on 1 September 2026, material bought this year may target either version. The difference is not cosmetic: governance, cloud and threat intelligence content grows, and two domains are renamed.
✓ Ours: the bank is maintained on a regular cycle to reflect how ISC2 actually tests, not only when an outline changes. When ISC2 does publish the September revision, the affected questions are re-checked on top of that cycle, and the current bank date is shown in the exam details above.
Covers the network domain properly
Network Security is 24% of the exam and the most terminology-heavy part of it. Material that treats it as a short chapter leaves a quarter of the exam thinly prepared.
✓ Ours: bank coverage across all five domains, with the per-domain counts and the questions follow ISC2's own domain structure rather than a generic security syllabus.
Something you can inspect before paying
CC is a first certification for most people who sit it, which is exactly when a question set is hardest to judge from the outside. Reading the actual items settles it faster than any description does.
✓ Ours: a free demo of both formats, the PDF and the practice test, before any purchase. The free questions on this page come from the same bank.
Enough questions to make a weak domain visible
A twenty-question sample cannot assess five domains. You need enough per domain that a pattern of misses becomes obvious rather than anecdotal.
✓ Ours: 407 CC questions across the five domains.
Sensible next to the exam fee
With the free attempt closed, the useful sum is the cost of preparing once set against the cost of paying ISC2 a second time.
✓ Ours: the full question bank is $69 less than half of the $199 exam fee. A retake means paying that $199 again, on top of the time already spent preparing. Getting it right the first time costs a fraction of what a second attempt does.
This is where CC candidates compare notes: which domains surprised them, how the format felt without the option to go back, and what they would change about their preparation. Add yours if you have sat it.
Five domains: Security Principles (26%), Network Security (24%), Access Controls Concepts (22%), Security Operations (18%), and Business Continuity, Disaster Recovery and Incident Response Concepts (10%). Those weightings come from ISC2's outline effective 1 October 2025 and hold until the refreshed outline takes over on 1 September 2026.
No. ISC2 closed new enrolment in the One Million Certified in Cybersecurity programme on 20 May 2026 after passing its target. Exam codes already issued under it must be used to schedule and sit by 31 December 2026. A new candidate today pays the USD 199 fee, though ISC2 still publishes free study material for the certification.
If you are prepared now, sit it now: the current outline is the one your material was written for, and the passing standard is the same either way. If you are starting from scratch, prepare for the refreshed outline instead, which adds governance, cloud security and threat intelligence emphasis and renames two domains. Booking across the changeover date is the one thing worth avoiding.
Manageable, but not trivial. There is no experience requirement and the task statements are all comprehension-level, so nothing on it is technically deep. What catches people is breadth across five domains, dense networking terminology, and qualifier words such as best or first that change which option is right.
Multiple choice plus advanced item types, delivered adaptively in 100 to 125 items over two hours. Items must be answered in the order they appear, so you cannot skip a question and come back to it. Because the engine adapts, no two candidates see the same set.
Reading past a qualifier word in the stem, treating the free training as the complete syllabus, under-preparing the network domain because the acronyms feel intimidating, and second-guessing early answers in a format that does not let you revisit them. Risk management and access control are the areas most often reported as needing more than the introductory material.
None. ISC2 states there are no prerequisites and recommends only basic information technology knowledge; the minimum age is 16. Passing requires a certification application and agreement to the ISC2 Code of Ethics, but unlike other ISC2 credentials, CC does not require the full endorsement process.
Concentrate on Security Principles and Network Security, which are half the exam between them, and drill the comparison pairs: the three access control models, the three continuity concepts, and the policy against standard against procedure distinction. Sit one full timed adaptive session midweek, then review misses only.
It is the entry point. CC assumes no experience and is designed for people moving into the field, after which practitioners commonly go on to SSCP and, once they have the five years, CISSP. Note that CC holders pay a lower annual maintenance fee and cannot endorse other candidates.
Editorial policy on this bank is simple: it is reviewed to a schedule of our own rather than to ISC2's publication calendar, because the way an exam is tested shifts between outline releases. ISC2 has a refreshed CC outline landing later in 2026, and when its weightings are published the affected questions and answers are re-checked against the new task statements on top of the scheduled pass. The date of the most recent pass appears in the exam details table above.