Certified In Cybersecurity CC Exam Questions & Answers

Practice 100 free Certified In Cybersecurity CC exam questions with answers and community-discussed explanations. Each question has its own page where you can reveal the correct answer and debate it in the comments.

All 100 questions

  1. Q1 What is the difference between risk assessment and risk management in the context of information security?
  2. Q2 Which of the following authentication methods is considered to be the MOST secure?
  3. Q3 Which of the following is NOT a common application of public key cryptography?
  4. Q4 What is the term for a security model that focuses on a single point of control for all security functions and policies?
  5. Q5 Who dictates the access controls rules in a Discretionary Access Control (DAC)?
  6. Q6 Which of the following is the FIRST step in implementing a software update?
  7. Q7 Which of these is a type of detective access control?
  8. Q8 When we experience a power surge, what is happening?
  9. Q9 Which of the following is NOT a requirement for HIPAA (Health Insurance Portability and Accountability Act) compliance?
  10. Q10 What does SaaS offer consumers?
  11. Q11 An organization wants to gauge its readiness for a disaster by shutting down its main operational site to imitate a genuine disaster…
  12. Q12 Which of the following is a type of security testing that involves deliberately trying to breach the security of a system to…
  13. Q13 In IT Security, we are talking about something as an event; what does that mean?
  14. Q14 Security cameras and motion sensors are examples of which type of access control that helps in identifying and recording unauthorized activities?
  15. Q15 What is the BEST control to implement in order to prevent unauthorized access to sensitive data on a network?
  16. Q16 A company is looking to improve its IT security practices to better protect sensitive data and systems. The CEO (Chief Executive Officer)…
  17. Q17 Which of the following is the MOST important indicator for ensuring compliance with legislative and regulatory requirements?
  18. Q18 Which of the following tools would be the BEST to prevent unauthorized data exfiltration from a corporate network? (★)
  19. Q19 What type of attack involves attackers intercepting a connection between a user and a genuine website?
  20. Q20 What is the purpose of implementing multi-factor authentication?
  21. Q21 Which of the following is the WORST approach to cloud security?
  22. Q22 Which of these is the PRIMARY objective of the PCI-DSS standard? (★)
  23. Q23 What is the primary purpose of using hashing for password storage?
  24. Q24 Which of these has the PRIMARY objective of identifying and prioritizing critical business processes?
  25. Q25 Risk Management is:
  26. Q26 What type of security control is the biometric reader that grants access to the data center building?
  27. Q27 The PRIMARY objective of a Business Continuity Plan (BCP) is:
  28. Q28 In which of the following scenarios is the use of a digital signature MOST appropriate?
  29. Q29 A best practice of patch management is to:
  30. Q30 Which of the following is the MOST effective method for establishing and maintaining security awareness among employees?
  31. Q31 You can MOST LIKELY be held liable when you display which of these?
  32. Q32 ThorTeaches.com has recently undergone a merger and acquisition, resulting in a significant increase in the number of employees and access points to…
  33. Q33 Which of these is NOT a characteristic of the cloud?
  34. Q34 Which of the following is the PRIMARY difference between a Type 1 and Type 2 hypervisor?
  35. Q35 Which of the following statements is the PRIMARY indicator that risk assessment is an iterative process?
  36. Q36 What is the PRIMARY goal of risk mitigation?
  37. Q37 What types of cards can be used as a tool to grant access?
  38. Q38 In the context of IT and cybersecurity, what is the primary purpose of a Disaster Recovery (DR) plan?
  39. Q39 We are looking at lowering our risk profile, and we are doing our quantitative risk analysis. What would EF tell us?
  40. Q40 Which of the following is NOT an example of a cybersecurity attack?
  41. Q41 As the Chief Information Security Officer (CISO) of ThorTeaches.com, Edward has been informed that the company's networks have been breached and sensitive…
  42. Q42 Which of the following is the BEST way to implement a DRP (Disaster Recovery Plan)?
  43. Q43 Which security control is the FIRST to be implemented for a wiring closet?
  44. Q44 Which of the following is the HIGHEST level of concern for a security professional?
  45. Q45 What is the term for the GDPR requirement allowing individuals to request the termination of their data dissemination? (★)
  46. Q46 When key distribution is not adequately secured, a cryptographic system becomes vulnerable to which security threat?
  47. Q47 John, a network administrator, is concerned about single points of failure in his company's data center. What principle can John apply to…
  48. Q48 Which of the following properties is NOT guaranteed by Digital Signatures?
  49. Q49 What does the acronym APT stand for?
  50. Q50 What historical encryption was written on a thin piece of parchment that was wrapped around a round stick of a certain diameter?
  51. Q51 What is the European Union's General Data Protection Regulation (GDPR)?
  52. Q52 What is the purpose of a security control assessment?
  53. Q53 In the risk management process, which of the following best describes the concept of 'risk acceptance'?
  54. Q54 As the lead security consultant for a large corporation, you are working with the HR department to educate employees on cybersecurity best…
  55. Q55 Which of the following is the MOST effective way to combat complexity as an enemy of security?
  56. Q56 Which of the following is the MOST effective way to protect privacy in an organization?
  57. Q57 Which of the following is the MOST common physical topology for a local area network?
  58. Q58 Which physical perimeter security control is the MOST effective at preventing unauthorized entry?
  59. Q59 In which access control model does the data owner decide who can access the data?
  60. Q60 You are the IT security manager at a large financial institution. Your company has recently implemented a new change management process to…
  61. Q61 Which of the following is the MOST effective managed services offering for a small business?
  62. Q62 Which of the following is the MOST effective way to implement forced encryption on an organization's network?
  63. Q63 Which of the following is the PRIMARY indicator that a secured door in an access control system is functioning properly?
  64. Q64 Which of the following technologies allows data to be written across multiple media for enhanced performance and redundancy, and can be used…
  65. Q65 A company provides a document outlining recommended best practices for employees to follow when creating strong passwords. What type of document is…
  66. Q66 Which of the following is the BEST way to implement Discretionary Access Control (DAC)?
  67. Q67 Which of the following is considered the FIRST federal law to address computer crime in the United States?
  68. Q68 Which of the following is the BEST way to ensure proper information and asset ownership?
  69. Q69 Which of the following is the MOST effective way to align the security function with business strategy?
  70. Q70 Which requirement is NOT necessary for a cryptographic hash function?
  71. Q71 Which of the following is the BEST way to ensure privacy in online transactions?
  72. Q72 Which of the following practices is the most effective at mitigating the risk of data breaches in an organization?
  73. Q73 What is a common security measure used to protect sensitive information from unauthorized access?
  74. Q74 What is the purpose of non-repudiation?
  75. Q75 We have an employee who is moving from IT to HR. If we are using Role Based Access Control (RBAC) access control,…
  76. Q76 Which of these is an example of a privacy breach?
  77. Q77 Which of the following is the FIRST covered entity of the Health Insurance Portability and Accountability Act (HIPAA)?
  78. Q78 Which of the following is a PRIMARY objective of implementing physical access controls in an organization?
  79. Q79 Which is the BEST security measure for protecting sensitive data in the event of a natural disaster?
  80. Q80 What is ensured by an information security policy? (★)
  81. Q81 You are configuring an Access Control List (ACL) for a file on a Linux server. The system administrators should be able to…
  82. Q82 As the IT security manager for a financial institution, you are constantly looking for ways to prevent unauthorized access to sensitive systems…
  83. Q83 What is the ULTIMATE goal of a risk assessment?
  84. Q84 Which of the following is the MOST important indicator to consider when evaluating the effectiveness of a log management system?
  85. Q85 ThorTeaches.com has recently experienced a major power outage that disrupted business operations for several days. Kundai has been asked to review the…
  86. Q86 Which of the following is the FIRST step in implementing encryption for data at rest?
  87. Q87 Mary, an HR manager at XYZ Corp., has been granted access to the HR department's confidential files but not to the finance…
  88. Q88 What are the key differences between access control and authentication?
  89. Q89 Which term describes monitoring and managing the deployment and verification of software updates?
  90. Q90 Which of these techniques will ensure the property of 'non-repudiation'?
  91. Q91 Which of the following is the MOST important characteristic of HA (High Availability)?
  92. Q92 You are a network administrator for your company and have been asked to restrict access to a particular network segment. Only the…
  93. Q93 Which of these types of layers is NOT part of the TCP/IP model?
  94. Q94 For a rack in a data center, how many temperature sensors are recommended?
  95. Q95 We are discussing our risk responses, and we are considering not issuing our employees laptops. What type of risk response would that…
  96. Q96 Which of the following is the MOST effective data retention policy?
  97. Q97 Which of these tools is commonly used to crack passwords? (★)
  98. Q98 Which of the following is an example of biometric authentication?
  99. Q99 As the new head of cybersecurity at your organization, you are tasked with preparing a Business Impact Analysis (BIA). What is the…
  100. Q100 We are in a court where the proof must be "more likely than not." Which court are we in?

More ISC2 certifications

Preparing For

Your Certification?

255+ certifications
Detailed explanations
Free PDF samples

Has All The Questions You Need