CC – Certified in Cybersecurity

Back to exams page

Practice exam for the CC from ISC2.

Take our Certified in Cybersecurity course here.

1. Which of the following is an example of a corrective security control?

Question 1 of 50

2. A company is about to start a new project and needs to determine the potential risks it might face. What type of risk assessment tool would be the most appropriate to use in this scenario?

Question 2 of 50

3. What is the purpose of having a disaster recovery plan in an organization?

Question 3 of 50

4. What is the process of protecting confidential information called?

Question 4 of 50

5. What are the rights of individuals under the General Data Protection Regulation (GDPR)?

Question 5 of 50

6. What are the key components of a non-repudiation system?

Question 6 of 50

7. How does separation of duties enhance cybersecurity?

Question 7 of 50

8. What is the first step in the risk management process?

Question 8 of 50

9. What are some advantages of using a quantitative risk assessment tool?

Question 9 of 50

10. What is the definition of integrity in the context of information security?

Question 10 of 50

11. What is the primary difference between a hot site and a warm site?

Question 11 of 50

12. What is the purpose of the containment step in incident response?

Question 12 of 50

13. What is a containment plan in the context of incident response?

Question 13 of 50

14. What is the role of a risk assessment in an IT disaster recovery plan?

Question 14 of 50

15. What is the difference between a hot site, warm site, and cold site?

Question 15 of 50

16. What is a supply chain disruption disaster?

Question 16 of 50

17. What is the purpose of testing a BCP?

Question 17 of 50

18. What is the first step in incident response?

Question 18 of 50

19. What is a communication plan in the context of incident response?

Question 19 of 50

20. What is the primary purpose of an IT business continuity plan?

Question 20 of 50

21. What should be considered when developing a physical security control plan?

Question 21 of 50

22. What is the main purpose of using a badge system in a cybersecurity setting?

Question 22 of 50

23. What is the main difference between fail-safe and fail-secure mechanisms?

Question 23 of 50

24. How does the use of surveillance cameras improve physical security?

Question 24 of 50

25. Company XYZ is concerned about the potential for fraud or errors in their accounting department. Which security control should be implemented to reduce this risk?

Question 25 of 50

26. What is the purpose of Crime Prevention Through Environmental Design (CPTED)?

Question 26 of 50

27. In a DAC system, who has control over the access permissions of a resource?

Question 27 of 50

28. Which of the following is a limitation of MAC?

Question 28 of 50

29. In an organization that uses Role-based access control (RBAC), a user has been promoted to a new position. Which action should be taken to adjust the user's access permissions?

Question 29 of 50

30. What are the 4 principles of CPTED (Crime Prevention Through Environmental Design)?

Question 30 of 50

31. What type of firewall is typically used to protect an entire network?

Question 31 of 50

32. Which of the following is a key element of an effective SLA?

Question 32 of 50

33. What is a region in cloud computing?

Question 33 of 50

34. What is WPA2, a common security protocol used for Wi-Fi networks?

Question 34 of 50

35. What is the primary disadvantage of a packet filtering firewall?

Question 35 of 50

36. What is the main difference between signature-based detection and anomaly-based detection in IDS?

Question 36 of 50

37. What is the Open Systems Interconnection (OSI) model?

Question 37 of 50

38. Which of the following is a common technique used in DDoS attacks?

Question 38 of 50

39. Which of the following ports is typically used for secure communication?

Question 39 of 50

40. Which of the following is a defense strategy against zero-day attacks?

Question 40 of 50

41. Which of the following is NOT a component of a digital signature?

Question 41 of 50

42. How can data classification and labelling help with data governance and compliance?

Question 42 of 50

43. What is the main purpose of an Acceptable Use Policy (AUP)?

Question 43 of 50

44. Which of the following is an important consideration when implementing system hardening measures?

Question 44 of 50

45. Which of the following is an example of an asymmetric encryption algorithm?

Question 45 of 50

46. What are the six main phases of the data lifecycle?

Question 46 of 50

47. Which of the following is an example of a key exchange algorithm used in symmetric encryption?

Question 47 of 50

48. What is the purpose of software updates and patches in configuration management?

Question 48 of 50

49. Which of the following is NOT a benefit of maintaining an accurate information asset inventory?

Question 49 of 50

50. What is the difference between a log and an event?

Question 50 of 50


40+ IT Certifications · One Membership

Stop Watching. Start Doing.

Unlimited IT certification training with videos, labs, PBQs, live Cisco racks and practice exams — everything you need to pass and actually know your stuff.

  • Video theory lessons
  • Follow-along labs
  • Performance-based questions
  • Practice exams
  • Live Cisco rack access
  • 40+ certs including CompTIA, Cisco, Linux, Microsoft, AWS, CEH
Join Now — From $29

Cancel anytime. No contracts. Instant access on signup.

content-filler