Every Exam PrepFREE EXAM PREP
Ask AI
CHEAT SHEET · ISC2 CC

ISC2 CC Cheat Sheet.

The ISC2 CC numbers, rules and traps that decide questions, on one page. Review them here, then download the free PDF for offline study.

Download the PDF
Weighted to the current exam outline·15-minute scanVerified against the official content outline
Written by Every Exam Prep Editorial TeamSource and review policyPublished July 18, 2026Updated September 16, 2026
Drill weak spots →
01

Quick facts

the numbers to know before exam day
Time limit
2h
Passing score
700 out of 1000 points
Exam fee
$199
Governing body
ISC2
02

Full write-up

the complete guide, in prose

ISC2 Certified in Cybersecurity (CC) Cheat Sheet

A dense, last-mile review for the ISC2 CC exam — logistics, domains, vocabulary, and traps to check the night before.

Exam Logistics At-a-Glance

ItemDetail
FormatMultiple choice + advanced item types, Computerized Adaptive Testing (CAT)
Duration2 hours (120 minutes)
Questions100–125
Passing score700 out of 1000
Registration costU.S. $199
Testing providerPearson VUE (worldwide testing centers)
Experience requiredNone — open to entry-level candidates
Reschedule feeU.S. $50
Cancellation feeU.S. $100
Annual Maintenance Fee (AMF)U.S. $50/year, with a 90-day grace period from the due date

The Five Domains (Quick List)

  • Domain 1: Security Principles — 24%
  • Domain 2: Security Governance — 17.3%
  • Domain 3: Identity And Access Management (IAM) Concepts — 20%
  • Domain 4: Networking and Cloud Security Concepts — 21.3%
  • Domain 5: Security Operations and Incident Response — 17.3%

Domains 1, 4, and 3 together make up close to two-thirds of the exam — prioritize study time there, but don't neglect Domain 2 and Domain 5, which are tied for the lowest weight and still independently testable.

Key Terms and Concepts to Memorize

Domain 1: Security Principles

  • CIA Triad: Confidentiality, Integrity, Availability
  • AAA framework: Authentication, Authorization, Accounting
  • Non-repudiation and privacy
  • Risk terminology: threat, vulnerability, risk, likelihood, impact, risk appetite vs. risk tolerance
  • Controls typing: technical, administrative, physical (physical access controls now live here, not in Domain 3)
  • Legal/ethical concepts: (ISC)² Code of Ethics canons and their priority order, plus due care and due diligence

Domain 2: Security Governance

  • Governance basics: policies, standards, procedures, guidelines (know the hierarchy and which is mandatory vs. discretionary)
  • Security awareness training purpose
  • Redundancy and business continuity: Business Continuity Plan (BCP) vs. Disaster Recovery Plan (DRP) — BCP keeps the business running, DRP restores IT systems; RTO (Recovery Time Objective) vs. RPO (Recovery Point Objective); backup types (full, incremental, differential) — this is now a redundancy sub-topic here, not its own domain
  • Measuring cybersecurity effectiveness: key metrics, Key Risk Indicators (KRI), dashboards and reports

Domain 3: Identity And Access Management (IAM) Concepts

  • Access control models: DAC, MAC, RBAC, ABAC — know who sets permissions in each
  • Least privilege and separation of duties (SoD)
  • Multi-factor authentication (MFA) factor categories: something you know/have/are
  • Identity lifecycle management: roles definition, provisioning, review, deprovisioning
  • Privileged access management

Domain 4: Networking and Cloud Security Concepts

  • OSI model layers and common attacks/devices at each layer
  • Firewalls, VPNs, network segmentation, defense in depth, and Zero Trust
  • Cloud service models (SaaS/PaaS/IaaS), deployment models, and the shared responsibility model between provider and customer
  • Common ports/protocols conceptually (HTTP/HTTPS, DNS, secure vs. insecure protocol pairs)
  • Wireless security basics

Domain 5: Security Operations and Incident Response

  • Data lifecycle and data handling (classification, retention, destruction), encryption, hashing, and quantum resistant cryptography
  • Logging and monitoring, SIEM concept
  • Incident response lifecycle: preparation, detection/analysis, containment, eradication, recovery, lessons learned
  • Threat intelligence and triage: security event triage, threat actors and motivations, threat frameworks
  • Security testing: blue/purple/red teaming, vulnerability scanning, threat modeling, physical penetration testing (phishing, tailgating, impersonation)
  • Asset protection: asset lifecycle management, End Of Life (EOL) software and devices, configuration and change management

Common Gotchas and Traps

  • Domain 2 changed from Business Continuity/Disaster Recovery to Security Governance — BC, DR, and backups now live inside Governance as a redundancy sub-topic, not their own domain, so don't assume Domain 2 questions are about RTOs and backup types.
  • DAC lets the data owner grant access; MAC is enforced by a central authority/system based on classification labels — test-writers love swapping these.
  • RTO answers "how fast must we recover," RPO answers "how much data can we lose" — read the question stem carefully for which one is asked.
  • CAT exams adapt in real time: once you submit an answer, you cannot go back and review or change previous questions.
  • "Best" or "most appropriate" answer questions often have multiple technically-correct options — pick the one most aligned with (ISC)²'s risk-averse, least-privilege philosophy rather than the most technically advanced one.
  • Policies are mandatory; guidelines are recommendations — mixing these up is a classic governance-question trap.
  • The CC has no work-experience prerequisite, unlike CISSP — don't assume you need professional experience to sit for it.

Night-Before Checklist

  1. Confirm Pearson VUE appointment time, testing center address, and required photo ID match exactly.
  2. Review the five domain weights once more, focusing extra minutes on Security Principles, Networking and Cloud Security Concepts, and IAM Concepts given their higher exam share.
  3. Skim the CIA triad, AAA, DAC/MAC/RBAC/ABAC, Zero Trust vs. defense in depth, and RTO vs. RPO definitions one final time — these are the highest-frequency trap areas.
  4. Get full sleep; CAT format rewards steady focus over 2 hours since there is no backtracking.
  5. Arrive early with two forms of valid ID if required, and plan for the reschedule/cancellation fee windows in case of emergencies.
  6. Remind yourself: no prior experience is required to pass, so trust your domain review rather than assuming you need field experience to answer correctly.

Frequently asked questions

How much does the ISC2 Certified in Cybersecurity (CC) exam cost, and are there other fees to plan for?

The exam registration itself is U.S. $199. Beyond that, budget for a few situational and ongoing costs. If you need to reschedule your appointment, Pearson VUE charges a U.S. $50 reschedule fee; cancelling outright costs U.S. $100. Once you certify, the Annual Maintenance Fee (AMF) for members who only hold CC is U.S. $50 per year, and you're given a 90-day window from the due date to pay it. So the true first-year cost for most candidates is the $199 exam plus the $50 AMF — assuming you don't reschedule or cancel.

What score do I need to pass the CC exam, and how is it structured?

You need 700 out of 1000 points to pass — that's a scaled score, not a raw percentage of questions answered correctly. The exam contains 100–125 questions and you have 2 hours (120 minutes) to complete it. It's delivered as a Computerized Adaptive Testing (CAT) exam using multiple choice and advanced item types, so the difficulty of each question adapts based on your prior answers. Because it's adaptive, the exact number of questions you see can vary within that 100–125 range.

Which domains does the CC exam cover, and where should I focus my study time?

The CC exam covers 5 domains of foundational cybersecurity knowledge, each weighted differently: Domain 1 – Security Principles (24%); Domain 2 – Security Governance (17.3%); Domain 3 – Identity And Access Management (IAM) Concepts (20%); Domain 4 – Networking and Cloud Security Concepts (21.3%); and Domain 5 – Security Operations and Incident Response (17.3%). Because Security Principles, Networking and Cloud Security Concepts, and IAM Concepts together make up about 65% of the exam, those three domains deserve the bulk of your study time, while Security Governance and Security Operations and Incident Response are the lowest-weighted at 17.3% each.

Do I need work experience to take the CC exam, and where do I take it?

No — no prior work experience is required to sit for the CC exam, which makes it a genuine entry point for people new to cybersecurity. The exam is administered at Pearson VUE testing centers worldwide. Because there's no experience prerequisite, students and career-changers can register and test as soon as they feel prepared, without first logging time in a security role.

Sources

  1. 1.CC Certification Exam OutlineISC2 (accessed Jul 18, 2026)
  2. 2.How to Register, Schedule, Cancel, Pay For Your ISC2 ExamISC2 (accessed Jul 18, 2026)
  3. 3.Certified in Cybersecurity (CC) Certification OverviewISC2 (accessed Jul 18, 2026)
  4. 4.ISC2 Annual Maintenance Fees (AMF) OverviewISC2 (accessed Jul 18, 2026)
  5. 5.ISC2 Exam PricingISC2 (accessed Jul 18, 2026)

Official sources

Primary documents used to verify the exam details shown on this page.

Last verified against the official exam content outline: