ISC2 CC sample questions with answers
10 free ISC2 CC sample questions across the exam's domains, each with its answer and an explanation. No account needed.
ISC2 CC sample questions
ISC2 Certified in Cybersecurity (CC), ISC2.
Question 1
Domain: Security Principles
Which pairing correctly classifies a mandatory background check performed before a new employee is given system access?
- Administrative category, preventive type
- Technical category, detective type
- Physical category, preventive type
- Administrative category, corrective type
Show the answer
Answer: A. Administrative category, preventive type
A background check is a personnel policy and procedure, so it is administrative, and it aims to stop unsuitable people from gaining access, so it is preventive. Corrective is wrong because corrective controls act after an incident to fix its effects, not before access is granted.
Checked against: https://csrc.nist.gov/pubs/sp/800/53/r5/upd1/final
Question 2
Domain: Security Principles
An employee types a username at a login prompt before entering a password. Which part of IAAA does typing the username represent?
- Authentication
- Authorization
- Identification
- Accountability
Show the answer
Answer: C. Identification
Identification is the claim of an identity, such as supplying a username. Authentication is the next step, where the claim is proven with a factor such as a password; the username alone proves nothing.
Checked against: https://csrc.nist.gov/glossary/term/identification
Question 3
Domain: Security Governance
Which type of security document offers recommended practices that staff are encouraged, but not required, to follow?
- Guideline
- Policy
- Standard
- Procedure
Show the answer
Answer: A. Guideline
Guidelines are discretionary recommendations that help people apply policies and standards sensibly. Policies, standards and procedures are all mandatory within their scope; a standard in particular is often confused with a guideline, but it states requirements rather than advice.
Checked against: https://csrc.nist.gov/pubs/sp/800/12/r1/final
Question 4
Domain: Security Governance
An attacker phones the service desk pretending to be a traveling sales director, gives the director's name and job title from a professional networking site, and persuades the agent to reset the director's password.
Which control most directly reduces the risk of this attack succeeding again?
- A stronger password complexity requirement for all users
- Verify callers by calling back on the number held in HR records
- Full-disk encryption on every service desk workstation
- A web application firewall in front of the corporate website
Show the answer
Answer: B. Verify callers by calling back on the number held in HR records
The attacker exploited the reset process by pretexting over the phone, so the fix is a verification step that the caller cannot satisfy with public information, such as a call back to a number on record. Stronger password complexity is tempting but irrelevant: the attacker simply had the new password issued to them.
Checked against: https://csrc.nist.gov/glossary/term/social_engineering
Question 5
Domain: Identity and Access Management (IAM) Concepts
Attackers send employees to a lookalike login page that relays everything they type to the real site in real time, including one-time codes, and captures the resulting session.
Which type of authenticator best resists this attack?
- A six-digit one-time code delivered by SMS text message
- A time-based one-time password from an authenticator app
- A longer password with more complex character rules
- A FIDO2 security key or passkey bound to the site's origin
Show the answer
Answer: D. A FIDO2 security key or passkey bound to the site's origin
Phishing-resistant authenticators such as FIDO2/WebAuthn sign a challenge tied to the genuine site's origin, so a lookalike proxy site cannot obtain a usable response. An authenticator-app TOTP is the tempting upgrade from SMS, but the user can still type that code into the fake page, where the proxy relays it in real time.
Checked against: https://csrc.nist.gov/pubs/sp/800/63/b/4/final
Question 6
Domain: Identity and Access Management (IAM) Concepts
Policy: users may view quarterly forecasts only if their department is Finance, they are on a company-managed device, and the request is made between 07:00 and 19:00 local time.
Which access control model best supports this policy?
- Role-based access control (RBAC)
- Discretionary access control (DAC)
- Attribute-based access control (ABAC)
- Mandatory access control (MAC)
Show the answer
Answer: C. Attribute-based access control (ABAC)
ABAC evaluates policies against attributes of the subject, object, action and environment, such as department, device state and time, at the moment of the request. RBAC is tempting because 'Finance' sounds like a role, but pure RBAC cannot natively express conditions like managed device and time of day without creating many role variants.
Checked against: https://csrc.nist.gov/pubs/sp/800/162/upd2/final
Question 7
Domain: Networking and Cloud Security Concepts
A company is launching public web servers that must be reachable from the internet and must query a database on the internal network.
Where should the new public web servers be placed?
- On the internal user network, so staff can reach them quickly
- In a screened subnet (DMZ) with firewalls on both sides
- Directly on the internet with no firewall, relying on host hardening only
- On the same segment as the internal database servers they query
Show the answer
Answer: B. In a screened subnet (DMZ) with firewalls on both sides
A DMZ, or screened subnet, hosts internet-facing services in a separate segment, so a compromised web server does not give direct access to internal systems. Placing them next to the database servers is tempting for performance, but it removes the segmentation that limits an attacker's lateral movement.
Checked against: https://csrc.nist.gov/glossary/term/demilitarized_zone
Question 8
Domain: Networking and Cloud Security Concepts
A healthcare firm storing records in the cloud must be able to control who can use its encryption keys and be able to revoke access to the data by disabling those keys.
Which approach best meets this requirement?
- Rely on the provider's default encryption with provider-owned keys
- Store the encryption keys in a text file on the same virtual machine
- Compress the data before uploading it to cloud storage
- Encrypt with customer-managed keys in a key management service
Show the answer
Answer: D. Encrypt with customer-managed keys in a key management service
Customer-managed keys in a key management service let the customer control key policies, rotation and revocation, so disabling the key makes the data unreadable. Provider-owned default encryption is the tempting option because it is already on, but the customer then has no say over key use or revocation.
Checked against: https://docs.aws.amazon.com/kms/latest/developerguide/overview.html
Question 9
Domain: Security Operations and Incident Response
An investigator must image a hard drive removed from a suspect's computer without changing a single bit on the original disk.
Which tool should be placed between the suspect drive and the forensic workstation during imaging?
- A network tap
- A write blocker
- A KVM switch
- A USB hub with external power
Show the answer
Answer: B. A write blocker
A write blocker allows data to be read from the suspect drive while preventing any writes, so the original evidence is not modified during acquisition. A network tap is tempting because it is also a passive monitoring device, but it copies network traffic and does nothing to protect a connected storage device.
Checked against: https://csrc.nist.gov/glossary/term/write_blocker
Question 10
Domain: Security Operations and Incident Response
A user reports that files on their laptop are being renamed with a strange extension and a ransom note has appeared. The laptop is still connected to the corporate network.
What is the most appropriate immediate action?
- Wipe and reinstall the laptop immediately to remove the ransomware
- Shut the laptop down and send it back to the user once it restarts cleanly
- Isolate the laptop from the network but keep it powered on
- Pay the ransom quickly before the encryption spreads further
Show the answer
Answer: C. Isolate the laptop from the network but keep it powered on
Containment limits the spread and damage, and network isolation stops communication with other systems and the attacker while preserving volatile evidence in memory. Wiping immediately is the tempting 'fast fix', but it destroys evidence and skips the analysis needed to find the root cause and other infected systems.
Checked against: https://csrc.nist.gov/pubs/sp/800/61/r3/final
More practice
A 20-question practice sampler is free with an account; Pro adds the full question bank and timed mock exams.
ISC2 CC course and practice exam: Certified in Cybersecurity: the exam guide, with the format, cost, pass mark and domains from the vendor.