CC Cheat Sheet.
The night-before summary, built like the exam.
ISC2 Certified in Cybersecurity (CC) Cheat Sheet
A dense, last-mile review for the ISC2 CC exam — logistics, domains, vocabulary, and traps to check the night before.
Exam Logistics At-a-Glance
| Item | Detail |
|---|---|
| Format | Multiple choice + advanced item types, Computerized Adaptive Testing (CAT) |
| Duration | 2 hours (120 minutes) |
| Questions | 100–125 |
| Passing score | 700 out of 1000 |
| Registration cost | U.S. $199 |
| Testing provider | Pearson VUE (worldwide testing centers) |
| Experience required | None — open to entry-level candidates |
| Reschedule fee | U.S. $50 |
| Cancellation fee | U.S. $100 |
| Annual Maintenance Fee (AMF) | U.S. $50/year, with a 90-day grace period from the due date |
The Five Domains (Quick List)
- Domain 1: Security Principles — 26%
- Domain 2: Business Continuity (BC), Disaster Recovery (DR) & Incident Response Concepts — 10%
- Domain 3: Access Controls Concepts — 22%
- Domain 4: Network Security — 24%
- Domain 5: Security Operations — 18%
Domains 1, 3, and 4 together make up over 70% of the exam — prioritize study time there, but don't neglect Domain 2 and Domain 5 since every domain is independently testable.
Key Terms and Concepts to Memorize
Domain 1: Security Principles
- CIA Triad: Confidentiality, Integrity, Availability
- AAA framework: Authentication, Authorization, Accounting
- Non-repudiation, least privilege, separation of duties, defense in depth
- Risk terminology: threat, vulnerability, risk, likelihood, impact, risk appetite vs. risk tolerance
- Governance basics: policies, standards, procedures, guidelines (know the hierarchy and which is mandatory vs. discretionary)
- Legal/ethical concepts: (ISC)² Code of Ethics canons and their priority order
Domain 2: BC, DR & Incident Response
- Business Continuity Plan (BCP) vs. Disaster Recovery Plan (DRP) — BCP keeps the business running, DRP restores IT systems
- RTO (Recovery Time Objective) vs. RPO (Recovery Point Objective) — time to restore vs. acceptable data loss
- Incident response lifecycle: preparation, detection/analysis, containment, eradication, recovery, lessons learned
- Backup types: full, incremental, differential — know restore-speed and storage tradeoffs
Domain 3: Access Controls
- Access control models: DAC, MAC, RBAC, ABAC — know who sets permissions in each
- Physical vs. logical access controls
- Multi-factor authentication (MFA) factor categories: something you know/have/are
- Privileged access management, provisioning/deprovisioning
Domain 4: Network Security
- OSI model layers and common attacks/devices at each layer
- Firewalls, IDS vs. IPS (detect vs. actively block), VPNs, network segmentation
- Common ports/protocols conceptually (HTTP/HTTPS, DNS, secure vs. insecure protocol pairs)
- Wireless security basics, Zero Trust concept
Domain 5: Security Operations
- Data lifecycle and data handling (classification, retention, destruction)
- Logging and monitoring, SIEM concept
- Change management and configuration management basics
- Security awareness training purpose
Common Gotchas and Traps
- Don't confuse IDS (detects and alerts) with IPS (detects and blocks) — a frequent trick on network security items.
- DAC lets the data owner grant access; MAC is enforced by a central authority/system based on classification labels — test-writers love swapping these.
- RTO answers "how fast must we recover," RPO answers "how much data can we lose" — read the question stem carefully for which one is asked.
- CAT exams adapt in real time: once you submit an answer, you cannot go back and review or change previous questions.
- "Best" or "most appropriate" answer questions often have multiple technically-correct options — pick the one most aligned with (ISC)²'s risk-averse, least-privilege philosophy rather than the most technically advanced one.
- Policies are mandatory; guidelines are recommendations — mixing these up is a classic governance-question trap.
- The CC has no work-experience prerequisite, unlike CISSP — don't assume you need professional experience to sit for it.
Night-Before Checklist
- Confirm Pearson VUE appointment time, testing center address, and required photo ID match exactly.
- Review the five domain weights once more, focusing extra minutes on Security Principles, Network Security, and Access Controls given their higher exam share.
- Skim the CIA triad, AAA, DAC/MAC/RBAC/ABAC, IDS vs. IPS, and RTO vs. RPO definitions one final time — these are the highest-frequency trap areas.
- Get full sleep; CAT format rewards steady focus over 2 hours since there is no backtracking.
- Arrive early with two forms of valid ID if required, and plan for the reschedule/cancellation fee windows in case of emergencies.
- Remind yourself: no prior experience is required to pass, so trust your domain review rather than assuming you need field experience to answer correctly.
Frequently asked questions
How much does the ISC2 Certified in Cybersecurity (CC) exam cost, and are there other fees to plan for?
The exam registration itself is U.S. $199. Beyond that, budget for a few situational and ongoing costs. If you need to reschedule your appointment, Pearson VUE charges a U.S. $50 reschedule fee; cancelling outright costs U.S. $100. Once you certify, the Annual Maintenance Fee (AMF) for members who only hold CC is U.S. $50 per year, and you're given a 90-day window from the due date to pay it. So the true first-year cost for most candidates is the $199 exam plus the $50 AMF — assuming you don't reschedule or cancel.
What score do I need to pass the CC exam, and how is it structured?
You need 700 out of 1000 points to pass — that's a scaled score, not a raw percentage of questions answered correctly. The exam contains 100–125 questions and you have 2 hours (120 minutes) to complete it. It's delivered as a Computerized Adaptive Testing (CAT) exam using multiple choice and advanced item types, so the difficulty of each question adapts based on your prior answers. Because it's adaptive, the exact number of questions you see can vary within that 100–125 range.
Which domains does the CC exam cover, and where should I focus my study time?
The CC exam covers 5 domains of foundational cybersecurity knowledge, each weighted differently: Domain 1 – Security Principles (26%); Domain 2 – Business Continuity (BC), Disaster Recovery (DR) & Incident Response Concepts (10%); Domain 3 – Access Controls Concepts (22%); Domain 4 – Network Security (24%); and Domain 5 – Security Operations (18%). Because Security Principles, Network Security, and Access Controls together make up 72% of the exam, those three domains deserve the bulk of your study time, while Business Continuity/Disaster Recovery is the lowest-weighted at just 10%.
Do I need work experience to take the CC exam, and where do I take it?
No — no prior work experience is required to sit for the CC exam, which makes it a genuine entry point for people new to cybersecurity. The exam is administered at Pearson VUE testing centers worldwide. Because there's no experience prerequisite, students and career-changers can register and test as soon as they feel prepared, without first logging time in a security role.
Sources
- 1.CC Certification Exam Outline — ISC2 (accessed Jul 18, 2026)
- 2.How to Register, Schedule, Cancel, Pay For Your ISC2 Exam — ISC2 (accessed Jul 18, 2026)
- 3.Certified in Cybersecurity (CC) Certification Overview — ISC2 (accessed Jul 18, 2026)
- 4.ISC2 Annual Maintenance Fees (AMF) Overview — ISC2 (accessed Jul 18, 2026)
- 5.ISC2 Exam Pricing — ISC2 (accessed Jul 18, 2026)