ISC2 Certified in Cybersecurity (CC) Study Guide
- Time limit
- 2h
- Passing score
- 700 out of 1000 points
- Exam fee
- $199
- Governing body
- ISC2
The ISC2 Certified in Cybersecurity (CC) is an entry-level credential designed to validate foundational knowledge of cybersecurity concepts, terminology, and best practices. It is issued by ISC2, the same organization behind the CISSP, and is built specifically for people who are new to the field or transitioning into security from adjacent IT roles.
- Career changers moving from help desk, networking, or systems administration into security
- College students and recent graduates building a credential before their first security job
- IT professionals who want a formal, vendor-neutral baseline before pursuing advanced certifications
Unlike many advanced security certifications, CC does not assume years of hands-on experience. It focuses on the core language and mental models of the profession: what security principles govern decision-making, how organizations recover from disruptions, how access is controlled, how networks are defended, and how day-to-day security operations function.
Why It Matters
Earning the CC gives candidates a recognized, résumé-ready signal that they understand cybersecurity fundamentals, which can help unlock entry-level analyst, help desk security, or SOC technician roles. It also serves as a natural stepping stone toward ISC2's more advanced certifications, since it introduces the same domain structure and vocabulary candidates will encounter later in their careers. For employers, the credential offers a consistent way to screen candidates who are serious about the field but may not yet have extensive on-the-job experience.
Understanding the exam's mechanics ahead of time helps candidates plan their study schedule and testing-day logistics with confidence.
Format and Timing
- The exam uses multiple choice and advanced item types, administered as Computerized Adaptive Testing (CAT)
- Candidates are given 2 hours (120 minutes) to complete the exam
- The exam contains 100-125 questions
- A passing score of 700 out of 1000 points is required
Because the exam is computer-adaptive, question difficulty adjusts based on prior answers, and the total number of questions a candidate sees can vary within the stated range.
Cost and Delivery
- The registration price for the CC exam is $199
- The exam is administered at Pearson VUE testing centers worldwide
Candidates who need to change plans should budget for logistics fees: Pearson VUE charges a $50 reschedule fee and a $100 cancellation fee. After passing, certified members who hold only the CC credential pay a $50 Annual Maintenance Fee (AMF), and members are given a 90-day grace period from the due date to pay it.
Because Pearson VUE centers operate globally, candidates can typically test close to home, and the adaptive format means well-prepared candidates may finish before using the full time allotment.
The CC exam covers 5 domains of foundational cybersecurity knowledge, and each is weighted differently, meaning some topics deserve more study time than others.
Domain 1: Security Principles (26%)
The largest domain, covering core concepts like confidentiality, integrity, and availability (CIA triad), risk management terminology, governance, and ethical practices. This domain sets the vocabulary used throughout the rest of the exam.
Domain 2: Business Continuity, Disaster Recovery & Incident Response Concepts (10%)
The smallest domain, focused on how organizations prepare for and recover from disruptive events, including the basics of incident handling and continuity planning.
Domain 3: Access Controls Concepts (22%)
Covers how organizations control who can reach which resources, including authentication, authorization, and the physical and logical mechanisms used to enforce access decisions.
Domain 4: Network Security (24%)
The second-largest domain, covering network architecture, common attacks, and the tools and practices used to defend network infrastructure.
Domain 5: Security Operations (18%)
Focused on the day-to-day practices that keep an organization secure, including monitoring, logging, and operational best practices.
Together, Domain 1, Domain 3, and Domain 4 make up more than seventy percent of the scored content, so candidates who are short on time should prioritize those three areas first.
Most candidates new to cybersecurity can prepare for the CC exam in four to six weeks of consistent study, though timelines vary based on prior IT background. Structuring preparation around the domain weightings makes the most efficient use of limited study time.
Weeks 1-2: Build the Foundation
Start with Domain 1 (Security Principles) since it introduces terminology used throughout the rest of the material. Focus on understanding concepts rather than memorizing definitions word-for-word, since the adaptive exam format rewards genuine comprehension.
Weeks 3-4: Tackle the Heavyweights
Move into Domain 4 (Network Security) and Domain 3 (Access Controls Concepts), the two next-largest domains. These topics benefit from diagrams and hands-on visualization, such as sketching network segments or mapping out authentication flows, even for candidates without lab access.
Week 5: Round Out Operations and Continuity
Cover Domain 5 (Security Operations) and Domain 2 (Business Continuity, Disaster Recovery & Incident Response Concepts). Although these are lighter-weighted domains, skipping them entirely is risky since every domain is scored.
Week 6: Practice and Review
- Take full-length practice exams under timed conditions to build stamina for the two-hour session
- Review a glossary of key terms daily to reinforce vocabulary recall
- Use flashcards for quick daily repetition, especially for domains with the lowest scores
- Revisit any domain where practice scores fall below your target passing threshold
Spacing out review sessions rather than cramming tends to produce better retention, particularly for a broad, terminology-heavy exam like this one.
Before the Exam
- Confirm your Pearson VUE testing center location and arrive with required identification, since the exam is administered at Pearson VUE testing centers worldwide
- Get familiar with the computer-adaptive format in advance so the pacing does not feel unfamiliar on test day
- Plan your schedule carefully; last-minute changes carry a reschedule fee, so lock in a date only once you are confident in your readiness
During the Exam
- Read each question fully before answering; advanced item types can present information in less familiar formats than a simple multiple-choice question
- Manage your time across the full two-hour window rather than rushing early questions, since adaptive scoring means early answers can influence later question difficulty
- Flag uncertain questions mentally and move on rather than dwelling, since CAT exams generally do not allow returning to previous questions
- Eliminate obviously incorrect answers first to improve your odds on questions where you are unsure
Common Mistakes to Avoid
- Memorizing definitions without understanding how concepts apply in scenario-based questions
- Neglecting the lower-weighted domains entirely, since every domain contributes to the overall score
- Underestimating how much vocabulary the exam expects, especially for candidates without prior IT background
- Skipping practice exams, which are one of the best ways to build comfort with question phrasing and pacing
Treat the exam as a test of applied understanding rather than rote recall, and give yourself enough runway before test day to reinforce weaker domains.
Preparing for the CC exam does not require expensive bootcamps or paid courses. A combination of targeted, freely available study tools can cover most of what the exam expects, especially when used consistently over several weeks.
Practice Questions
Working through realistic practice questions helps candidates get comfortable with the phrasing and scenario-based style used on the actual exam, and highlights which domains need more attention before test day. Since the CC exam spans five distinct domains with different weightings, practicing across all of them, not just the largest ones, helps avoid gaps.
Flashcards
Flashcards are well suited to a terminology-heavy exam like this one. Short, frequent review sessions using flashcards reinforce recall of key terms and concepts from each domain, making them a useful daily habit during the final weeks of preparation.
Glossary
A comprehensive glossary of cybersecurity terms gives candidates a quick reference for unfamiliar vocabulary encountered while studying. Since Domain 1 introduces much of the terminology used throughout the rest of the exam, reviewing a glossary early in the study process pays dividends later.
Used together, these free resources let candidates simulate the exam experience, reinforce weak areas, and build the vocabulary fluency the CC exam is designed to test, all without additional cost beyond the registration fee itself.
ISC2 CC flashcards
30 cards on the highest-yield terms and rules. Grading uses spaced repetition and saves in this browser.
Browse all 30 cards
How many domains does the ISC2 CC exam cover, and what are they?
Five domains: Security Principles; Business Continuity (BC), Disaster Recovery (DR) & Incident Response Concepts; Access Controls Concepts; Network Security; and Security Operations.
Which CC domain carries the highest exam weight, and what is it?
Domain 1, Security Principles, at 26% of the exam — the largest single domain weighting.
What is the passing score on the CC exam?
700 out of 1000 points, using a scaled scoring model rather than a raw percentage of questions correct.
How long is the CC exam and how many questions does it contain?
Candidates get 2 hours (120 minutes) to answer 100-125 questions.
What testing format does the CC exam use?
Multiple choice and advanced item types delivered via Computerized Adaptive Testing (CAT), where question difficulty adjusts based on prior answers.
What work experience is required to sit for the CC exam?
None. The CC is designed as an entry-level credential, so no prior professional cybersecurity experience is required to take the exam.
Define the CIA Triad.
The core security model of Confidentiality (preventing unauthorized disclosure), Integrity (preventing unauthorized modification), and Availability (ensuring authorized access when needed).
What is the difference between authentication and authorization?
Authentication verifies who a subject is (identity proofing), while authorization determines what an authenticated subject is permitted to do (access rights).
What is non-repudiation?
Assurance that a party cannot later deny having performed an action, typically achieved through digital signatures, logging, and audit trails tied to a verified identity.
Differentiate risk, threat, and vulnerability.
A threat is a potential cause of harm; a vulnerability is a weakness that a threat can exploit; risk is the likelihood and impact of a threat successfully exploiting a vulnerability.
What is defense in depth?
A layered security strategy that uses multiple, overlapping controls (physical, technical, administrative) so that if one control fails, others still protect the asset.
What is the principle of least privilege?
Subjects should be granted only the minimum access rights needed to perform their job function, reducing the potential impact of compromised accounts or insider misuse.
What is separation of duties?
Dividing critical tasks among multiple people so no single individual can complete a sensitive process alone, reducing fraud and error risk.
Name the four common risk treatment strategies.
Avoid, transfer, mitigate, and accept — organizations choose one or a combination based on risk appetite and cost-benefit analysis.
What distinguishes RTO from RPO in business continuity planning?
Recovery Time Objective (RTO) is the maximum acceptable time to restore a system after disruption; Recovery Point Objective (RPO) is the maximum acceptable amount of data loss measured in time.
What is the difference between a Business Continuity Plan (BCP) and a Disaster Recovery Plan (DRP)?
A BCP addresses keeping essential business functions running during and after a disruption; a DRP focuses specifically on restoring IT systems and infrastructure after a disaster.
List the typical phases of the incident response lifecycle.
Preparation, Detection & Analysis, Containment, Eradication, Recovery, and Post-Incident (lessons learned).
What is the difference between discretionary access control (DAC) and mandatory access control (MAC)?
DAC lets the resource owner decide who gets access; MAC enforces access based on fixed system-wide security labels/classifications that users cannot override.
What is role-based access control (RBAC)?
An access control model that assigns permissions to roles rather than individual users, and users are granted access by being assigned to the appropriate role(s).
What are the three factors of authentication?
Something you know (password/PIN), something you have (token/smart card), and something you are (biometric) — multifactor authentication combines two or more.
What is a firewall's primary function?
To filter network traffic between security zones based on defined rules, permitting or denying traffic by criteria such as IP address, port, and protocol.
What is the difference between an IDS and an IPS?
An Intrusion Detection System (IDS) monitors and alerts on suspicious traffic without blocking it; an Intrusion Prevention System (IPS) actively blocks or stops detected malicious traffic in real time.
What is a VPN and what security property does it primarily provide?
A Virtual Private Network creates an encrypted tunnel across an untrusted network, primarily providing confidentiality (and often integrity) for data in transit.
What is network segmentation and why is it used?
Dividing a network into smaller isolated zones (e.g., via VLANs or subnets) to limit the blast radius of a breach and control traffic flow between zones.
What is a DMZ in network security?
A Demilitarized Zone is a buffer subnet placed between an untrusted external network and a trusted internal network, hosting public-facing services while shielding the internal network.
What is the purpose of a Security Operations Center (SOC)?
A centralized team and facility responsible for continuously monitoring, detecting, analyzing, and responding to cybersecurity events across an organization.
What is the difference between symmetric and asymmetric encryption?
Symmetric encryption uses one shared secret key for both encryption and decryption; asymmetric encryption uses a mathematically linked public/private key pair.
What is a security control's purpose when categorized as preventive, detective, or corrective?
Preventive controls stop an incident before it occurs; detective controls identify that an incident is happening or has happened; corrective controls restore systems and reduce impact after an incident.
What is Computerized Adaptive Testing (CAT) as used on the CC exam?
An exam delivery method where question difficulty is dynamically adjusted based on the candidate's prior answers, so each candidate receives a personalized set of items.
What annual maintenance is required to keep the CC certification active?
Certified members must pay an Annual Maintenance Fee to ISC2, along with earning and reporting Continuing Professional Education (CPE) credits to maintain their certification.
ISC2 CC glossary
24 terms the ISC2 CC tests, defined in plain English.
- Availability
- The security property ensuring authorized users can access information and systems when needed.
- Business Continuity Plan (BCP)
- A documented plan describing how an organization will continue critical business functions during and after a disruptive event.
- CIA Triad
- The foundational security model of Confidentiality, Integrity, and Availability used to evaluate and design protections for information and systems.
- Confidentiality
- The security property ensuring information is disclosed only to authorized individuals, entities, or processes.
- Defense in Depth
- A layered security strategy that combines multiple independent controls so a single point of failure does not compromise the whole system.
- Demilitarized Zone (DMZ)
- A network segment positioned between an untrusted external network and a trusted internal network, used to host public-facing services securely.
- Disaster Recovery Plan (DRP)
- A documented plan focused on restoring IT infrastructure, systems, and data following a disaster.
- Discretionary Access Control (DAC)
- An access control model in which the resource owner determines who is granted access to that resource.
- Firewall
- A network security device or software that filters incoming and outgoing traffic based on predefined rules.
- Incident Response
- The structured process an organization follows to prepare for, detect, contain, eradicate, and recover from security incidents.
- Integrity
- The security property ensuring data and systems are accurate, complete, and unaltered except by authorized action.
- Intrusion Detection System (IDS)
- A monitoring tool that analyzes network or host activity for signs of malicious behavior and generates alerts without blocking traffic.
- Intrusion Prevention System (IPS)
- A security tool that actively detects and blocks malicious network traffic in real time.
- Least Privilege
- An access control principle requiring users and processes be granted only the minimum permissions necessary to perform their function.
- Mandatory Access Control (MAC)
- An access control model where access decisions are enforced by the system based on fixed classification labels, not by resource owners.
- Non-repudiation
- A security assurance that a party cannot deny having performed an action, typically supported by digital signatures and audit logs.
- Recovery Point Objective (RPO)
- The maximum acceptable amount of data loss, measured as a period of time, following a disruptive event.
- Recovery Time Objective (RTO)
- The maximum tolerable length of time a system or process can be down before causing unacceptable business impact.
- Risk
- The potential for loss or harm resulting from a threat exploiting a vulnerability, generally assessed by likelihood and impact.
- Role-Based Access Control (RBAC)
- An access control model that assigns permissions to defined roles, and users inherit permissions through their assigned role(s).
- Separation of Duties
- A control that splits a sensitive task among multiple people to prevent any single individual from acting alone in a way that causes harm or fraud.
- Threat
- Any circumstance or event with the potential to cause harm to an asset, such as a hacker, malware, or natural disaster.
- Virtual Private Network (VPN)
- A technology that creates an encrypted communication tunnel over a public or untrusted network to protect data in transit.
- Vulnerability
- A weakness in a system, process, or control that could be exploited by a threat to cause harm.
Sources
- 1.CC Certification Exam Outline — ISC2 (accessed Jul 18, 2026)
- 2.How to Register, Schedule, Cancel, Pay For Your ISC2 Exam — ISC2 (accessed Jul 18, 2026)
- 3.Certified in Cybersecurity (CC) Certification Overview — ISC2 (accessed Jul 18, 2026)
- 4.ISC2 Annual Maintenance Fees (AMF) Overview — ISC2 (accessed Jul 18, 2026)
- 5.ISC2 Exam Pricing — ISC2 (accessed Jul 18, 2026)
Official sources
Primary documents used to verify the exam details shown on this page.
- CC Certification Exam OutlineISC2isc2.org
- How to Register, Schedule, Cancel, Pay For Your ISC2 ExamISC2isc2.org
- Certified in Cybersecurity (CC) Certification OverviewISC2isc2.org
- ISC2 Annual Maintenance Fees (AMF) OverviewISC2isc2.org
- ISC2 Exam PricingISC2isc2.org
Last verified against the ISC2 exam outline: