ISC2 · CC
The ISC2 Certified in Cybersecurity (CC) validates foundational knowledge and skills required for entry- or junior-level cybersecurity roles. It covers security principles, access controls, network security, and incident response concepts.
Practice Questions
838
≈ 6 practice exams
Duration
120 minutes
Passing Score
700/1000
Difficulty
FoundationalLast Updated
Mar 2026
Use this CC practice exam to prepare for Certified in Cybersecurity (CC) with realistic questions, detailed explanations, and focused study modes. The practice bank includes 838 questions for ISC2 CC, so you can review the exam steadily instead of relying on one long cram session.
As you practice, pay extra attention to recurring topics such as Security Principles, Business Continuity, Disaster Recovery & Incident Response, Access Controls Concepts, Network Security, and Security Operations. Start with short sessions to identify weak areas, then move into timed quizzes once your accuracy is consistent.
The explanations are especially useful when you want to connect exam wording to the responsibilities and scenarios described in the official certification guidance. Use the free preview first, then unlock the full question bank when you are ready to build a complete study routine.
The ISC2 Certified in Cybersecurity (CC) is an entry-level certification developed by ISC2 — the world's largest association of certified cybersecurity professionals — to validate foundational knowledge and skills required for junior cybersecurity roles. The credential covers five core domains: Security Principles (including the CIA triad, risk management, and governance), Business Continuity and Disaster Recovery, Access Controls, Network Security, and Security Operations. It is accredited by ANAB to ISO/IEC Standard 17024, signifying its adherence to internationally recognized standards for personnel certification.
The CC was created specifically to address the global cybersecurity workforce shortage, which ISC2 estimated at nearly 4.8 million unfilled positions in 2024. It serves as both a standalone entry-level credential and a structured pathway to advanced ISC2 certifications such as the CISSP. Uniquely among professional certifications, ISC2 has offered free training and exam vouchers to qualifying candidates as part of its One Million Certified in Cybersecurity initiative, significantly lowering the barrier to entry for career changers and new graduates.
The CC is designed for individuals at the beginning of their cybersecurity careers, including career changers transitioning from unrelated fields, recent college graduates or current students in IT or computer science programs, and IT generalists looking to formalize their security knowledge. ISC2 explicitly states that no prior work experience in cybersecurity or IT is required to sit for the exam, making it one of the most accessible professional certifications available.
The credential is particularly well-suited for individuals in roles such as help desk technician, IT support specialist, or junior systems administrator who want to move into dedicated security positions like SOC Analyst, Security Analyst, or IT Security Specialist. Analytical, problem-solving individuals who are new to the field but want a recognized credential to validate their foundational knowledge will benefit most from pursuing the CC.
ISC2 does not impose any formal prerequisites for the CC exam — there is no minimum work experience requirement, no prior certifications required, and no educational prerequisites. This policy sets the CC apart from nearly all other professional security credentials and makes it accessible to complete newcomers to the field.
While not required, ISC2 recommends familiarity with basic IT concepts before studying for the exam. Candidates who have completed coursework in networking fundamentals, operating systems, or general IT principles will find the material easier to absorb. After passing the exam, candidates must pay a $50 Annual Maintenance Fee (AMF) to complete certification and gain ISC2 member status; no endorsement from an existing ISC2 member is required, unlike the CISSP process.
The CC exam consists of 100 to 125 items, which include multiple-choice questions and advanced item types such as drag-and-drop and hotspot questions. The time limit is 2 hours (120 minutes). The exam is delivered via Pearson VUE in a computerized adaptive testing (CAT) format, available at authorized testing centers worldwide or via online proctoring. The exam is offered in English, Chinese, Japanese, German, and Spanish.
Scoring is on a scale of 0 to 1000, and the passing score is 700. The adaptive format means the difficulty of questions adjusts dynamically based on candidate performance, and the total number of questions delivered may vary within the 100–125 range depending on the test engine's assessment of candidate ability. Candidates should be prepared for both straightforward knowledge-recall questions and scenario-based items that require applying concepts to real-world situations.
Earning the CC positions candidates for entry-level and junior cybersecurity roles in a field that the U.S. Bureau of Labor Statistics projects will grow 32% by 2032 — more than ten times the average growth rate across all occupations. Common job titles pursued by CC holders include SOC Analyst, Security Analyst, IT Security Specialist, and Cybersecurity Technician, with entry-level salaries in the United States typically ranging from $60,000 to $85,000 annually. ISC2 reports that its certified members earn 35% higher salaries than non-members, and survey data shows that 10% of CC holders received a salary increase and 7% received a promotion within their first certification cycle.
Beyond immediate job placement, the CC serves as the foundational step in the ISC2 certification pathway, familiarizing candidates with ISC2's exam format and professional standards before advancing toward credentials such as the SSCP or CISSP. Compared to alternatives like CompTIA Security+, the CC's lack of prerequisites and free exam availability make it a lower-risk entry point, while ISC2's brand recognition — as the organization behind CISSP, the most recognized advanced security certification globally — lends the CC meaningful credibility with hiring managers and HR systems that filter for ISC2 credentials.
5 sample questions with answers and explanations. The full bank has 838 questions, enough for 6 full-length practice exams.
Preview — answers shown1. A global e-commerce company is selecting a disaster recovery site for their transaction processing systems. Business requirements specify that end-users should experience no service interruption even during a complete primary site failure, and the solution must support real-time transaction synchronization. Budget approval has been granted for the most robust solution available. Which recovery site type meets these requirements? (Select one!)
Explanation
A redundant site provides fully mirrored infrastructure with real-time synchronization and automatic failover, resulting in zero perceived downtime for end-users. This is the only option that meets the requirement of no service interruption. A hot site recovers in minutes to an hour but has a brief switchover period. A warm site requires hours to days for data restoration. Cloud DRaaS can be configured for various recovery times but typically involves some service interruption during failover unless specifically configured as a redundant architecture.
2. An organization assigns private IP addresses to all internal workstations and uses a network device to translate multiple internal private IP addresses to a single public IP address, distinguishing return traffic by using different port numbers for each internal host. Which two technologies are being implemented? (Select two!)
Multiple correct answersExplanation
Network Address Translation translates private IP addresses to public IP addresses for internet communication. Port Address Translation, also called NAT Overload, is the specific NAT technique that allows multiple internal private addresses to share a single public IP address by using different port numbers to track connections. This is the most common form of NAT in modern networks. VPN creates encrypted tunnels for secure remote communications. DHCP dynamically assigns IP addresses to hosts. IPSec provides network layer encryption and authentication for secure communications.
3. During an active ransomware incident, the incident response team must choose between immediately isolating infected systems to prevent spread (which will disrupt operations) or taking time to collect detailed forensic evidence (which risks further encryption). According to incident response best practices, which action should be prioritized? (Select one!)
Explanation
Containment is the highest priority during active incident response, especially during ransomware attacks where the threat is actively spreading and encrypting additional data. The first responder's immediate action should be to contain the threat by isolating infected systems from the network, even if this means some forensic evidence may be lost or operations will be disrupted. After containment, evidence can be collected from the isolated systems in a more controlled manner. Waiting to collect complete forensic evidence before containment allows the ransomware to continue spreading and encrypting more systems, causing greater damage. While evidence preservation is important, it cannot take priority over stopping active damage. Legal counsel involvement is important but should not delay critical containment actions. Investigating the attack vector is part of the analysis phase but cannot delay immediate containment when active encryption is occurring.
4. A security incident response team discovers unauthorized access to a database server at 2:00 PM on Friday. The team must decide on the next action. Following NIST SP 800-61 guidance, which action should take the highest priority during the active incident? (Select one!)
Explanation
During active incident response, containment is the highest priority to prevent further damage and limit the scope of the incident. Isolating the compromised system from the network stops the attacker from accessing additional systems or exfiltrating more data. According to NIST SP 800-61, the Containment, Eradication, and Recovery phase includes short-term containment actions like immediate network isolation. Documenting lessons learned occurs during the Post-Incident Activity phase after the incident is resolved. Detailed log analysis is part of Detection and Analysis but should not delay containment. Restoration occurs after eradication ensures all threats are removed. The scenario presents an active, ongoing compromise requiring immediate containment.
5. A financial services company discovers that customer transaction records were modified without authorization, causing incorrect account balances. The integrity of the data has been compromised, but no data was disclosed to unauthorized parties. Which element of the CIA triad was primarily violated? (Select one!)
Explanation
Integrity ensures data has not been altered in an unauthorized manner. When transaction records are modified without authorization, the accuracy and trustworthiness of the data is compromised, which directly violates integrity. Confidentiality would be violated if data was disclosed to unauthorized parties. Availability would be violated if authorized users could not access the data. Non-repudiation is not part of the CIA triad and relates to proving the origin of actions.
Information Systems Security Engineering Professional (ISSEP)
ISSEP · 850 questions
Systems Security Certified Practitioner (SSCP)
SSCP · 849 questions
Certified Cloud Security Professional (CCSP)
CCSP · 850 questions
Certified Secure Software Lifecycle Professional (CSSLP)
CSSLP · 841 questions
Certified in Governance, Risk and Compliance (CGRC)
CGRC · 850 questions
Certified Information Systems Security Professional (CISSP)
CISSP · 850 questions
$17.99
One-time access to this exam