Free sampler

Try 12 free ISC2 CC practice questions

Real exam-style questions taken word for word from the ISC2 CC study guide. Three are below, with the full answer explanation. Enter your email and the full 12-question PDF is yours.

Unlock the full sampler
ISC2 CC cover
12 questions in the PDF Taken verbatim from the book One email, no spam, unsubscribe any time

Three questions to try right now

Work each one before you open the answer. These are the same style and depth as the Certified in Cybersecurity (CC) exam expects.

Question 1. A healthcare provider collects patient birthdates and diagnoses for billing. Regulations require limiting who can view that data and how long it is retained. This requirement is MOST closely aligned with which information assurance concept?

  • A. Availability
  • B. Non-repudiation
  • C. Privacy
  • D. Integrity
Show the answer

Answer: C. Privacy governs the appropriate collection, use, retention, and protection of personal information. Regulations restricting who may view patient data and mandating retention limits are classic privacy controls applied to personal and health information.

  • A: Availability concerns whether systems are accessible, not who may view personal data or for how long.

Question 2. A software developer digitally signs each code release before it is deployed. The signature verifies that the code has not been modified since it was signed. Which information assurance principle does digital signing MOST directly support?

  • A. Availability
  • B. Authentication
  • C. Integrity
  • D. Privacy
Show the answer

Answer: C. Integrity ensures data has not been altered or tampered with. A digital signature is built over a hash of the content; if anything changes after signing, the signature no longer verifies, which confirms whether the data remains unmodified.

  • A: Availability relates to uptime and access, not to detecting modification.

Question 3. A security manager is designing a layered defense for a server room and wants exactly one control from each of the three control types in objective 1.3, technical, administrative, and physical. Which option BEST provides one of each?

  • A. Firewall, security policy, and badge-reader door lock
  • B. Firewall, antivirus, and password policy
  • C. Encryption, mantrap, and intrusion detection system
  • D. Security camera, mantrap, and door lock
Show the answer

Answer: A. A firewall is a technical control (hardware/software enforcing network rules). A security policy is an administrative control (a management directive). A badge-reader door lock is a physical control (it restricts physical access). Option A provides exactly one control from each of the three categories.

  • B: A firewall and antivirus are both technical; a password policy is administrative. Two technical, one administrative, no physical control, so the set is incomplete.

Unlock the full 12-question sampler

All 12 come with the same written explanations the book uses, covering why the right answer is right. We email you the PDF, nothing else.

One email with the PDF. Unsubscribe any time.

What you get

The sampler is free. Here is exactly what lands in your inbox.

The 12-question PDF

Print it or work it on screen, then score yourself against the answer key.

Questions from the real book

Nothing is written for marketing. Every question is lifted from the study guide itself.

A one-time discount

A few days later we send one email with a code for the full study guide. That is the entire sequence.

ISC2 CC cover

The full ISC2 CC study guide

The complete guide covers the Certified in Cybersecurity (CC) exam objective by objective in plain English, with the full practice question bank behind these samples.

From $17.99

See the study guide   All ISC2 guides