ISC2

ISC2 Certified in Cybersecurity (CC) (CC)
exam objectives

ISC2's entry-level cybersecurity credential validating foundational knowledge across security principles, business continuity/disaster recovery/incident response, access controls, network security, and security operations. No prior work experience or degree required.

Questions
60
Duration
120 min
Passing score
700
Domains
5

198 practice questions available for CC on CertPilot AI, mapped to the domains below.

CC exam domains and weightings

The CC exam is split into 5 domains. The percentage next to each is the share of the exam it accounts for — study time is best spent proportionally.

1.0Security Principles

26%

52 practice questions in this domain

  • 1.1Understand the security concepts of information assurance (confidentiality, integrity, availability, authentication including MFA, non-repudiation, privacy)
  • 1.2Understand the risk management process (risk identification/assessment/treatment, qualitative vs. quantitative analysis, risk treatment options: accept/transfer/avoid/mitigate, inherent vs. residual risk)
  • 1.3Understand security controls (categories: technical/administrative/physical; types: preventative/detective/corrective/deterrent/compensating)
  • 1.4Understand the (ISC)² Code of Ethics (the four canons and their purpose)
  • 1.5Understand governance processes (regulations, policies, procedures, standards, guidelines, and how they relate)

2.0Business Continuity (BC), Disaster Recovery (DR) & Incident Response Concepts

10%

24 practice questions in this domain

  • 2.1Understand business continuity (BC) (purpose, business impact analysis, BC plan components, testing)
  • 2.2Understand disaster recovery (DR) (purpose, DR plan components, backup types: full/incremental/differential, recovery sites: hot/warm/cold, RTO/RPO)
  • 2.3Understand incident response (purpose, runbooks/playbooks, SOAR, incident response process: preparation/detection-analysis/containment/eradication/recovery/lessons learned)

3.0Access Controls Concepts

22%

42 practice questions in this domain

  • 3.1Understand physical access controls (badge systems, fencing/gates, mantraps, biometrics, lighting, CCTV, security guards/alarms, authorized vs. unauthorized personnel)
  • 3.2Understand logical access controls (least privilege, need-to-know, separation of duties, MAC, DAC, RBAC, rule-based/attribute-based access control)

4.0Network Security

24%

48 practice questions in this domain

  • 4.1Understand computer networking (OSI and TCP/IP models, network types: LAN/WAN/WLAN, IP addressing, common ports/protocols/services, network topologies)
  • 4.2Understand network threats and attacks (DoS/DDoS, spoofing, on-path/MITM, malware types, social engineering, insider threats)
  • 4.3Understand network security infrastructure (firewalls, VPNs, network segmentation, IDS/IPS, NAC, defense in depth, zero trust, secure network design)

5.0Security Operations

18%

32 practice questions in this domain

  • 5.1Understand data security (encryption at rest/in transit, symmetric vs. asymmetric encryption, data handling and classification, data destruction/retention)
  • 5.2Understand system hardening (configuration/change management, patch management, disabling unnecessary services, baselining)
  • 5.3Understand best-practice security policies (acceptable use policy, password policy, BYOD policy)
  • 5.4Understand security awareness training (phishing, shoulder surfing, social engineering, security champions/gamification)

How to prepare for ISC2 Certified in Cybersecurity (CC)

Most candidates fail CC not because they didn't know the material, but because they couldn't tell which material they were weakest on. Reading the objectives end to end treats every domain as equally important — the exam doesn't. On CC, Security Principles alone is 26% of your score.

CertPilot AI works the other way around. It tracks your accuracy per domain, weights each domain by its real exam share, and pulls most of each practice session from wherever you're currently weakest. The result is a single readiness score — at 90% you're in the range where candidates typically pass, so you book the exam on evidence instead of a hunch.

Every question comes with an AI explanation of why the right answer is right and why each distractor is wrong. The Exam Decoder goes further and breaks down how to read a question — the qualifiers, the scenario framing, and the trap options — which is the skill that separates a 740 from a 700.

ISC2 Certified in Cybersecurity (CC) (CC) FAQ

How many questions are on the ISC2 Certified in Cybersecurity (CC) (CC) exam?

The CC exam has up to 60 questions and you get 120 minutes to complete it.

What score do you need to pass ISC2 Certified in Cybersecurity (CC)?

ISC2 Certified in Cybersecurity (CC) requires a scaled score of 700. Scaled scoring means the raw number of correct answers is adjusted for the difficulty of the specific question set you were served, so there is no fixed percentage that guarantees a pass.

What domains does the CC exam cover?

ISC2 Certified in Cybersecurity (CC) is divided into 5 domains: Security Principles (26%), Business Continuity (BC), Disaster Recovery (DR) & Incident Response Concepts (10%), Access Controls Concepts (22%), Network Security (24%), Security Operations (18%). The heaviest weighted domain is Security Principles at 26% of the exam.

How do I know when I'm ready to book the CC exam?

CertPilot AI calculates a readiness score by weighting your accuracy in each domain by that domain's share of the real exam, then scaling it by how many questions you've actually answered — so a domain you've barely touched can't inflate the number. At 90% you're in the range where candidates typically pass.

How much does the CC exam cost?

The ISC2 Certified in Cybersecurity (CC) exam voucher typically costs around $199 USD. Pricing varies by region and vendors periodically adjust it, so confirm on the official vendor site before booking.

Free to start

Start practising CC questions

Adaptive sessions weighted to the domains above, AI explanations on every question, and a readiness score that tells you when to book.

Start free

Other ISC2 certifications