ISC2 · CC
The ISC2 Certified in Cybersecurity (CC) validates foundational knowledge and skills required for entry- or junior-level cybersecurity roles. It covers security principles, access controls, network security, and incident response concepts.
Practice Questions
838
≈ 6 practice exams
Duration
120 minutes
Passing Score
700/1000
Difficulty
FoundationalLast Updated
Mar 2026
Use this CC practice exam to prepare for Certified in Cybersecurity (CC) with realistic questions, detailed explanations, and focused study modes. The practice bank includes 838 questions for ISC2 CC, so you can review the exam steadily instead of relying on one long cram session.
As you practice, pay extra attention to recurring topics such as Security Principles, Business Continuity, Disaster Recovery & Incident Response, Access Controls Concepts, Network Security, and Security Operations. Start with short sessions to identify weak areas, then move into timed quizzes once your accuracy is consistent.
The explanations are especially useful when you want to connect exam wording to the responsibilities and scenarios described in the official certification guidance. Use the free preview first, then unlock the full question bank when you are ready to build a complete study routine.
The ISC2 Certified in Cybersecurity (CC) is an entry-level certification developed by ISC2 — the world's largest association of certified cybersecurity professionals — to validate foundational knowledge and skills required for junior cybersecurity roles. The credential covers five core domains: Security Principles (including the CIA triad, risk management, and governance), Business Continuity and Disaster Recovery, Access Controls, Network Security, and Security Operations. It is accredited by ANAB to ISO/IEC Standard 17024, signifying its adherence to internationally recognized standards for personnel certification.
The CC was created specifically to address the global cybersecurity workforce shortage, which ISC2 estimated at nearly 4.8 million unfilled positions in 2024. It serves as both a standalone entry-level credential and a structured pathway to advanced ISC2 certifications such as the CISSP. Uniquely among professional certifications, ISC2 has offered free training and exam vouchers to qualifying candidates as part of its One Million Certified in Cybersecurity initiative, significantly lowering the barrier to entry for career changers and new graduates.
The CC is designed for individuals at the beginning of their cybersecurity careers, including career changers transitioning from unrelated fields, recent college graduates or current students in IT or computer science programs, and IT generalists looking to formalize their security knowledge. ISC2 explicitly states that no prior work experience in cybersecurity or IT is required to sit for the exam, making it one of the most accessible professional certifications available.
The credential is particularly well-suited for individuals in roles such as help desk technician, IT support specialist, or junior systems administrator who want to move into dedicated security positions like SOC Analyst, Security Analyst, or IT Security Specialist. Analytical, problem-solving individuals who are new to the field but want a recognized credential to validate their foundational knowledge will benefit most from pursuing the CC.
ISC2 does not impose any formal prerequisites for the CC exam — there is no minimum work experience requirement, no prior certifications required, and no educational prerequisites. This policy sets the CC apart from nearly all other professional security credentials and makes it accessible to complete newcomers to the field.
While not required, ISC2 recommends familiarity with basic IT concepts before studying for the exam. Candidates who have completed coursework in networking fundamentals, operating systems, or general IT principles will find the material easier to absorb. After passing the exam, candidates must pay a $50 Annual Maintenance Fee (AMF) to complete certification and gain ISC2 member status; no endorsement from an existing ISC2 member is required, unlike the CISSP process.
The CC exam consists of 100 to 125 items, which include multiple-choice questions and advanced item types such as drag-and-drop and hotspot questions. The time limit is 2 hours (120 minutes). The exam is delivered via Pearson VUE in a computerized adaptive testing (CAT) format, available at authorized testing centers worldwide or via online proctoring. The exam is offered in English, Chinese, Japanese, German, and Spanish.
Scoring is on a scale of 0 to 1000, and the passing score is 700. The adaptive format means the difficulty of questions adjusts dynamically based on candidate performance, and the total number of questions delivered may vary within the 100–125 range depending on the test engine's assessment of candidate ability. Candidates should be prepared for both straightforward knowledge-recall questions and scenario-based items that require applying concepts to real-world situations.
Earning the CC positions candidates for entry-level and junior cybersecurity roles in a field that the U.S. Bureau of Labor Statistics projects will grow 32% by 2032 — more than ten times the average growth rate across all occupations. Common job titles pursued by CC holders include SOC Analyst, Security Analyst, IT Security Specialist, and Cybersecurity Technician, with entry-level salaries in the United States typically ranging from $60,000 to $85,000 annually. ISC2 reports that its certified members earn 35% higher salaries than non-members, and survey data shows that 10% of CC holders received a salary increase and 7% received a promotion within their first certification cycle.
Beyond immediate job placement, the CC serves as the foundational step in the ISC2 certification pathway, familiarizing candidates with ISC2's exam format and professional standards before advancing toward credentials such as the SSCP or CISSP. Compared to alternatives like CompTIA Security+, the CC's lack of prerequisites and free exam availability make it a lower-risk entry point, while ISC2's brand recognition — as the organization behind CISSP, the most recognized advanced security certification globally — lends the CC meaningful credibility with hiring managers and HR systems that filter for ISC2 credentials.
5 sample questions with answers and explanations. The full bank has 838 questions, enough for 6 full-length practice exams.
Preview — answers shown1. Which of the following represents a MAC address rather than an IP address? (Select one!)
Explanation
MAC addresses are 48-bit physical addresses displayed as six pairs of hexadecimal digits separated by hyphens or colons, used at Layer 2 for device identification on local networks. A4-5E-60-E2-91-C7 follows this format. The address 192.168.15.200 is an IPv4 address using dotted-decimal notation. The address 2001:0db8:85a3:0000:0000:8a2e:0370:7334 is an IPv6 address using hexadecimal colon notation. The address 172.16.254.1 is a private IPv4 address. Understanding address formats is essential for network troubleshooting and security analysis.
2. Which network device operates at OSI Layer 2 and forwards traffic based on MAC addresses, creating separate collision domains for each port? (Select one!)
Explanation
Switches operate at Layer 2 (Data Link Layer) and use MAC addresses to intelligently forward frames only to the destination port, creating separate collision domains for each port and improving network performance. Hubs operate at Layer 1 and broadcast all traffic to every port without intelligence. Routers operate at Layer 3 and use IP addresses for routing decisions across networks. Firewalls can operate at multiple layers (3-7) and filter traffic based on security rules rather than just forwarding based on MAC addresses.
3. Which combination of IP address and port number identifies a secure protocol that should be permitted through a firewall to allow encrypted web traffic? (Select one!)
Explanation
TCP port 443 is used for HTTPS, which provides encrypted web traffic using TLS/SSL protocols. This is the standard secure alternative to HTTP. TCP port 80 is used for unencrypted HTTP traffic. TCP port 22 is used for SSH secure shell connections, not web traffic. UDP port 53 is used for DNS queries. The question specifically asks for encrypted web traffic, which is exclusively HTTPS on port 443.
4. A web server administrator needs to enable secure remote management access. Which port and protocol combination should be used instead of Telnet on port 23? (Select one!)
Explanation
SSH (Secure Shell) on port 22 provides encrypted remote command-line access and is the secure replacement for Telnet. Telnet transmits all data including credentials in plaintext, making it highly vulnerable to interception. SSH encrypts the entire session including authentication and commands. FTP on port 21 is for file transfer, not remote management, and also transmits credentials in plaintext. RDP on port 3389 provides remote desktop access for Windows systems but is designed for graphical interfaces rather than command-line server management. HTTPS on port 443 secures web traffic but does not provide remote terminal access for server administration.
5. A government agency must ensure that when officials digitally sign documents, they cannot later deny having signed them. Which security principle addresses this requirement? (Select one!)
Explanation
Non-repudiation prevents individuals from denying their actions or the authenticity of their signatures. Digital signatures provide non-repudiation by cryptographically binding the signer's identity to the document. Confidentiality protects information from unauthorized disclosure. Integrity ensures data has not been altered. Availability ensures timely access to information. While digital signatures also support integrity, the specific requirement to prevent denial of signing is non-repudiation.
Information Systems Security Engineering Professional (ISSEP)
ISSEP · 850 questions
Systems Security Certified Practitioner (SSCP)
SSCP · 849 questions
Certified Cloud Security Professional (CCSP)
CCSP · 850 questions
Certified Secure Software Lifecycle Professional (CSSLP)
CSSLP · 841 questions
Certified in Governance, Risk and Compliance (CGRC)
CGRC · 850 questions
Certified Information Systems Security Professional (CISSP)
CISSP · 850 questions
$17.99
One-time access to this exam