CHEAT SHEET · CC

CC Cheat Sheet.
The night-before summary, built like the exam.

Weighted to the current exam outline·15-minute scan
By Vincent Ruan, EA, CFP®Published July 21, 2026
Drill weak spots →

ISC2 Certified in Cybersecurity (CC) Cheat Sheet

A dense, last-mile review for the ISC2 CC exam — logistics, domains, vocabulary, and traps to check the night before.

Exam Logistics At-a-Glance

ItemDetail
FormatMultiple choice + advanced item types, Computerized Adaptive Testing (CAT)
Duration2 hours (120 minutes)
Questions100–125
Passing score700 out of 1000
Registration costU.S. $199
Testing providerPearson VUE (worldwide testing centers)
Experience requiredNone — open to entry-level candidates
Reschedule feeU.S. $50
Cancellation feeU.S. $100
Annual Maintenance Fee (AMF)U.S. $50/year, with a 90-day grace period from the due date

The Five Domains (Quick List)

  • Domain 1: Security Principles — 26%
  • Domain 2: Business Continuity (BC), Disaster Recovery (DR) & Incident Response Concepts — 10%
  • Domain 3: Access Controls Concepts — 22%
  • Domain 4: Network Security — 24%
  • Domain 5: Security Operations — 18%

Domains 1, 3, and 4 together make up over 70% of the exam — prioritize study time there, but don't neglect Domain 2 and Domain 5 since every domain is independently testable.

Key Terms and Concepts to Memorize

Domain 1: Security Principles

  • CIA Triad: Confidentiality, Integrity, Availability
  • AAA framework: Authentication, Authorization, Accounting
  • Non-repudiation, least privilege, separation of duties, defense in depth
  • Risk terminology: threat, vulnerability, risk, likelihood, impact, risk appetite vs. risk tolerance
  • Governance basics: policies, standards, procedures, guidelines (know the hierarchy and which is mandatory vs. discretionary)
  • Legal/ethical concepts: (ISC)² Code of Ethics canons and their priority order

Domain 2: BC, DR & Incident Response

  • Business Continuity Plan (BCP) vs. Disaster Recovery Plan (DRP) — BCP keeps the business running, DRP restores IT systems
  • RTO (Recovery Time Objective) vs. RPO (Recovery Point Objective) — time to restore vs. acceptable data loss
  • Incident response lifecycle: preparation, detection/analysis, containment, eradication, recovery, lessons learned
  • Backup types: full, incremental, differential — know restore-speed and storage tradeoffs

Domain 3: Access Controls

  • Access control models: DAC, MAC, RBAC, ABAC — know who sets permissions in each
  • Physical vs. logical access controls
  • Multi-factor authentication (MFA) factor categories: something you know/have/are
  • Privileged access management, provisioning/deprovisioning

Domain 4: Network Security

  • OSI model layers and common attacks/devices at each layer
  • Firewalls, IDS vs. IPS (detect vs. actively block), VPNs, network segmentation
  • Common ports/protocols conceptually (HTTP/HTTPS, DNS, secure vs. insecure protocol pairs)
  • Wireless security basics, Zero Trust concept

Domain 5: Security Operations

  • Data lifecycle and data handling (classification, retention, destruction)
  • Logging and monitoring, SIEM concept
  • Change management and configuration management basics
  • Security awareness training purpose

Common Gotchas and Traps

  • Don't confuse IDS (detects and alerts) with IPS (detects and blocks) — a frequent trick on network security items.
  • DAC lets the data owner grant access; MAC is enforced by a central authority/system based on classification labels — test-writers love swapping these.
  • RTO answers "how fast must we recover," RPO answers "how much data can we lose" — read the question stem carefully for which one is asked.
  • CAT exams adapt in real time: once you submit an answer, you cannot go back and review or change previous questions.
  • "Best" or "most appropriate" answer questions often have multiple technically-correct options — pick the one most aligned with (ISC)²'s risk-averse, least-privilege philosophy rather than the most technically advanced one.
  • Policies are mandatory; guidelines are recommendations — mixing these up is a classic governance-question trap.
  • The CC has no work-experience prerequisite, unlike CISSP — don't assume you need professional experience to sit for it.

Night-Before Checklist

  1. Confirm Pearson VUE appointment time, testing center address, and required photo ID match exactly.
  2. Review the five domain weights once more, focusing extra minutes on Security Principles, Network Security, and Access Controls given their higher exam share.
  3. Skim the CIA triad, AAA, DAC/MAC/RBAC/ABAC, IDS vs. IPS, and RTO vs. RPO definitions one final time — these are the highest-frequency trap areas.
  4. Get full sleep; CAT format rewards steady focus over 2 hours since there is no backtracking.
  5. Arrive early with two forms of valid ID if required, and plan for the reschedule/cancellation fee windows in case of emergencies.
  6. Remind yourself: no prior experience is required to pass, so trust your domain review rather than assuming you need field experience to answer correctly.

Frequently asked questions

How much does the ISC2 Certified in Cybersecurity (CC) exam cost, and are there other fees to plan for?

The exam registration itself is U.S. $199. Beyond that, budget for a few situational and ongoing costs. If you need to reschedule your appointment, Pearson VUE charges a U.S. $50 reschedule fee; cancelling outright costs U.S. $100. Once you certify, the Annual Maintenance Fee (AMF) for members who only hold CC is U.S. $50 per year, and you're given a 90-day window from the due date to pay it. So the true first-year cost for most candidates is the $199 exam plus the $50 AMF — assuming you don't reschedule or cancel.

What score do I need to pass the CC exam, and how is it structured?

You need 700 out of 1000 points to pass — that's a scaled score, not a raw percentage of questions answered correctly. The exam contains 100–125 questions and you have 2 hours (120 minutes) to complete it. It's delivered as a Computerized Adaptive Testing (CAT) exam using multiple choice and advanced item types, so the difficulty of each question adapts based on your prior answers. Because it's adaptive, the exact number of questions you see can vary within that 100–125 range.

Which domains does the CC exam cover, and where should I focus my study time?

The CC exam covers 5 domains of foundational cybersecurity knowledge, each weighted differently: Domain 1 – Security Principles (26%); Domain 2 – Business Continuity (BC), Disaster Recovery (DR) & Incident Response Concepts (10%); Domain 3 – Access Controls Concepts (22%); Domain 4 – Network Security (24%); and Domain 5 – Security Operations (18%). Because Security Principles, Network Security, and Access Controls together make up 72% of the exam, those three domains deserve the bulk of your study time, while Business Continuity/Disaster Recovery is the lowest-weighted at just 10%.

Do I need work experience to take the CC exam, and where do I take it?

No — no prior work experience is required to sit for the CC exam, which makes it a genuine entry point for people new to cybersecurity. The exam is administered at Pearson VUE testing centers worldwide. Because there's no experience prerequisite, students and career-changers can register and test as soon as they feel prepared, without first logging time in a security role.

Sources

  1. 1.CC Certification Exam OutlineISC2 (accessed Jul 18, 2026)
  2. 2.How to Register, Schedule, Cancel, Pay For Your ISC2 ExamISC2 (accessed Jul 18, 2026)
  3. 3.Certified in Cybersecurity (CC) Certification OverviewISC2 (accessed Jul 18, 2026)
  4. 4.ISC2 Annual Maintenance Fees (AMF) OverviewISC2 (accessed Jul 18, 2026)
  5. 5.ISC2 Exam PricingISC2 (accessed Jul 18, 2026)