Try 12 free ISC2 CC practice questions
Real exam-style questions taken word for word from the ISC2 CC study guide. Three are below, with the full answer explanation. Enter your email and the full 12-question PDF is yours.
Unlock the full sampler
Three questions to try right now
Work each one before you open the answer. These are the same style and depth as the Certified in Cybersecurity (CC) exam expects.
Question 1. A healthcare provider collects patient birthdates and diagnoses for billing. Regulations require limiting who can view that data and how long it is retained. This requirement is MOST closely aligned with which information assurance concept?
- A. Availability
- B. Non-repudiation
- C. Privacy
- D. Integrity
Show the answer
Answer: C. Privacy governs the appropriate collection, use, retention, and protection of personal information. Regulations restricting who may view patient data and mandating retention limits are classic privacy controls applied to personal and health information.
- A: Availability concerns whether systems are accessible, not who may view personal data or for how long.
Question 2. A software developer digitally signs each code release before it is deployed. The signature verifies that the code has not been modified since it was signed. Which information assurance principle does digital signing MOST directly support?
- A. Availability
- B. Authentication
- C. Integrity
- D. Privacy
Show the answer
Answer: C. Integrity ensures data has not been altered or tampered with. A digital signature is built over a hash of the content; if anything changes after signing, the signature no longer verifies, which confirms whether the data remains unmodified.
- A: Availability relates to uptime and access, not to detecting modification.
Question 3. A security manager is designing a layered defense for a server room and wants exactly one control from each of the three control types in objective 1.3, technical, administrative, and physical. Which option BEST provides one of each?
- A. Firewall, security policy, and badge-reader door lock
- B. Firewall, antivirus, and password policy
- C. Encryption, mantrap, and intrusion detection system
- D. Security camera, mantrap, and door lock
Show the answer
Answer: A. A firewall is a technical control (hardware/software enforcing network rules). A security policy is an administrative control (a management directive). A badge-reader door lock is a physical control (it restricts physical access). Option A provides exactly one control from each of the three categories.
- B: A firewall and antivirus are both technical; a password policy is administrative. Two technical, one administrative, no physical control, so the set is incomplete.
Unlock the full 12-question sampler
All 12 come with the same written explanations the book uses, covering why the right answer is right. We email you the PDF, nothing else.
What you get
The sampler is free. Here is exactly what lands in your inbox.
Print it or work it on screen, then score yourself against the answer key.
Nothing is written for marketing. Every question is lifted from the study guide itself.
A few days later we send one email with a code for the full study guide. That is the entire sequence.
The full ISC2 CC study guide
The complete guide covers the Certified in Cybersecurity (CC) exam objective by objective in plain English, with the full practice question bank behind these samples.
From $17.99
Simply Certified is an independent publisher. CC is a trademark of ISC2, which does not sponsor or endorse this product. This page and the sampler are independent study material and are not affiliated with, endorsed by, or sponsored by ISC2.