ISC2 Certified in Cybersecurity (CC) Practice Test
Free ISC2 CC practice questions in English, Chinese, and Spanish — security principles, governance, identity and access management, networking and cloud security, and security operations and incident response, with an explanation for every answer.
Choose a domain
Study resources
- ISC2 Certified in Cybersecurity CC prep books →
- ISC2 Certified in Cybersecurity CC flashcards →
- ISC2 Certified in Cybersecurity CC practice questions →
Links open Amazon search results. As an Amazon Associate, Quibank earns from qualifying purchases.
Practice questions based on the ISC2 Certified in Cybersecurity (CC) Exam Outline. This site is not affiliated with or endorsed by ISC2, and these are not real exam questions. ISC2 revises the domains and their weights periodically and sets the exam length, passing standard and eligibility terms — confirm the current outline and requirements with ISC2 before you register.
About the ISC2 Certified in Cybersecurity (CC) exam
Certified in Cybersecurity, or CC, is ISC2's entry-level certification, and it is unusual in one respect that matters enormously: it asks for no prior work experience. Most security credentials are gated behind years on the job, so CC is the rare door that opens for a career changer, a student, or someone already in IT who wants to move toward security. The exam covers five domains — security principles, security governance, identity and access management, networking and cloud security, and security operations and incident response — and it tests whether you understand the concepts, not whether you have already done the job.
How to study for the CC exam
Start with the vocabulary, because almost every CC question is really a vocabulary question wearing a scenario. If you can say precisely what confidentiality protects and how it differs from privacy, what separates authentication from authorization from accounting, and which of the three control categories a described safeguard belongs to, a large share of the exam becomes straightforward. Beginners lose points less often because a topic was obscure and more often because two terms blurred together under time pressure.
Practise classifying rather than memorising lists. The exam rarely asks you to recite the four access control models; it describes an arrangement and asks which model it is. It rarely asks what the phases of incident response are called; it describes an action and asks which phase it belongs to. So when you study a list, immediately invent two or three short scenarios for each item and sort them. That habit converts passive recall into the skill the questions actually measure, and it exposes the boundaries between items, which is exactly where the distractors live.
Give deliberate attention to the two ideas that beginners most reliably invert. The first is the document hierarchy: a policy states intent and is mandatory, a standard makes it specific and is mandatory, a procedure gives the steps, and a guideline is advisory. Being handed a sentence and asked which one it is, is a standard question shape. The second is the cloud shared responsibility model, where the split between what the provider secures and what the customer secures shifts as you move between service models. Work through that boundary for each model until it is automatic rather than reasoned out under time pressure.
Finally, treat the concepts as durable and the packaging as not. The ideas this exam tests — least privilege, defence in depth, the difference between business continuity and disaster recovery, why hashing is not encryption — have been stable for decades and will still be true whichever revision of the outline you sit. The exam's administration is the part that moves: ISC2 revises the domains and their weights periodically, and the delivery details are set by the testing provider. So learn the concepts from any good source, but take the domain list, the weights and the current exam arrangements from ISC2's own published outline rather than from a study guide or a practice site, including this one.
FAQ
Do I need work experience or an IT background to take the CC exam?
No work experience is required, which is the main reason this certification exists. ISC2 designed CC for people entering the field, so there is no prerequisite exam and no minimum time on the job. Basic familiarity with computers and networks makes the material easier, but it is not a formal requirement. Once you pass, becoming a certified member involves an endorsement step and ongoing requirements — check ISC2's current candidate information for those, since the administrative details change more often than the exam content does.
How is CC different from CompTIA Security+?
They sit at different altitudes. CC tests whether you understand a concept: what a control is, what least privilege means, what the shared responsibility model divides. Security+ tests whether you can act like a practitioner: analysing a threat, designing an architecture, working an incident. CC is the better first step if you are new to security, and the two complement each other rather than competing — many people take CC first and Security+ next. We keep a separate Security+ bank on this site, and the two banks are deliberately scoped so they do not repeat each other.
What does adaptive testing mean for how I should prepare?
The CC exam is delivered as a computerized adaptive test, which means the questions you see depend on how you have answered so far and the total number of items is not fixed. Two practical consequences follow. You cannot skip a question and come back to it, so you have to commit to an answer and move on. And you should not try to read anything into whether the questions feel hard — an adaptive test aims to sit near the edge of your ability, so feeling challenged throughout is normal and is not a signal that you are failing. ISC2 publishes the current exam length and passing standard in its exam outline.
Which domain should I spend the most time on?
Weight your study roughly to the published domain weights rather than to what feels interesting. Security principles is the largest single domain and it also underpins the other four, so the vocabulary you learn there — confidentiality, integrity and availability, the control categories, the risk terms — pays off everywhere else. Beyond that, the two topics beginners most reliably get backwards are the policy-standard-procedure-guideline hierarchy and the cloud shared responsibility model, so those repay deliberate attention. ISC2 publishes the current weights in the exam outline, and they do change between revisions.
Can I sit the exam in Chinese or Spanish?
ISC2 offers the CC exam in several languages, and both Chinese and Spanish have been among them, though availability and appointment windows differ by language and by testing region. Confirm what is offered for your language and location with ISC2 and the testing provider before you book. That is part of why this bank is trilingual: learning the concepts in your strongest language first is worthwhile regardless of which language you ultimately sit the exam in, because the ideas are what the exam tests.