ISC2 Certified in Cybersecurity (CC) Study Guide
- Time limit
- 2h
- Passing score
- 700 out of 1000 points
- Exam fee
- $199
- Governing body
- ISC2
The ISC2 Certified in Cybersecurity (CC) is an entry-level credential designed to validate foundational knowledge of cybersecurity concepts, terminology, and best practices. It is issued by ISC2, the same organization behind the CISSP, and is built specifically for people who are new to the field or transitioning into security from adjacent IT roles.
- Career changers moving from help desk, networking, or systems administration into security
- College students and recent graduates building a credential before their first security job
- IT professionals who want a formal, vendor-neutral baseline before pursuing advanced certifications
Unlike many advanced security certifications, CC does not assume years of hands-on experience. It focuses on the core language and mental models of the profession: what security principles govern decision-making, how organizations recover from disruptions, how access is controlled, how networks are defended, and how day-to-day security operations function.
Why It Matters
Earning the CC gives candidates a recognized, résumé-ready signal that they understand cybersecurity fundamentals, which can help unlock entry-level analyst, help desk security, or SOC technician roles. It also serves as a natural stepping stone toward ISC2's more advanced certifications, since it introduces the same domain structure and vocabulary candidates will encounter later in their careers. For employers, the credential offers a consistent way to screen candidates who are serious about the field but may not yet have extensive on-the-job experience.
Understanding the exam's mechanics ahead of time helps candidates plan their study schedule and testing-day logistics with confidence.
Format and Timing
- The exam uses multiple choice and advanced item types, administered as Computerized Adaptive Testing (CAT)
- Candidates are given 2 hours (120 minutes) to complete the exam
- The exam contains 100-125 questions
- A passing score of 700 out of 1000 points is required
Because the exam is computer-adaptive, question difficulty adjusts based on prior answers, and the total number of questions a candidate sees can vary within the stated range.
Cost and Delivery
- The registration price for the CC exam is $199
- The exam is administered at Pearson VUE testing centers worldwide
Candidates who need to change plans should budget for logistics fees: Pearson VUE charges a $50 reschedule fee and a $100 cancellation fee. After passing, certified members who hold only the CC credential pay a $50 Annual Maintenance Fee (AMF), and members are given a 90-day grace period from the due date to pay it.
Because Pearson VUE centers operate globally, candidates can typically test close to home, and the adaptive format means well-prepared candidates may finish before using the full time allotment.
The CC exam covers 5 domains of foundational cybersecurity knowledge, and each is weighted differently, meaning some topics deserve more study time than others.
Domain 1: Security Principles (26%)
The largest domain, covering core concepts like confidentiality, integrity, and availability (CIA triad), risk management terminology, governance, and ethical practices. This domain sets the vocabulary used throughout the rest of the exam.
Domain 2: Business Continuity, Disaster Recovery & Incident Response Concepts (10%)
The smallest domain, focused on how organizations prepare for and recover from disruptive events, including the basics of incident handling and continuity planning.
Domain 3: Access Controls Concepts (22%)
Covers how organizations control who can reach which resources, including authentication, authorization, and the physical and logical mechanisms used to enforce access decisions.
Domain 4: Network Security (24%)
The second-largest domain, covering network architecture, common attacks, and the tools and practices used to defend network infrastructure.
Domain 5: Security Operations (18%)
Focused on the day-to-day practices that keep an organization secure, including monitoring, logging, and operational best practices.
Together, Domain 1, Domain 3, and Domain 4 make up more than seventy percent of the scored content, so candidates who are short on time should prioritize those three areas first.
Most candidates new to cybersecurity can prepare for the CC exam in four to six weeks of consistent study, though timelines vary based on prior IT background. Structuring preparation around the domain weightings makes the most efficient use of limited study time.
Weeks 1-2: Build the Foundation
Start with Domain 1 (Security Principles) since it introduces terminology used throughout the rest of the material. Focus on understanding concepts rather than memorizing definitions word-for-word, since the adaptive exam format rewards genuine comprehension.
Weeks 3-4: Tackle the Heavyweights
Move into Domain 4 (Network Security) and Domain 3 (Access Controls Concepts), the two next-largest domains. These topics benefit from diagrams and hands-on visualization, such as sketching network segments or mapping out authentication flows, even for candidates without lab access.
Week 5: Round Out Operations and Continuity
Cover Domain 5 (Security Operations) and Domain 2 (Business Continuity, Disaster Recovery & Incident Response Concepts). Although these are lighter-weighted domains, skipping them entirely is risky since every domain is scored.
Week 6: Practice and Review
- Take full-length practice exams under timed conditions to build stamina for the two-hour session
- Review a glossary of key terms daily to reinforce vocabulary recall
- Use flashcards for quick daily repetition, especially for domains with the lowest scores
- Revisit any domain where practice scores fall below your target passing threshold
Spacing out review sessions rather than cramming tends to produce better retention, particularly for a broad, terminology-heavy exam like this one.
Before the Exam
- Confirm your Pearson VUE testing center location and arrive with required identification, since the exam is administered at Pearson VUE testing centers worldwide
- Get familiar with the computer-adaptive format in advance so the pacing does not feel unfamiliar on test day
- Plan your schedule carefully; last-minute changes carry a reschedule fee, so lock in a date only once you are confident in your readiness
During the Exam
- Read each question fully before answering; advanced item types can present information in less familiar formats than a simple multiple-choice question
- Manage your time across the full two-hour window rather than rushing early questions, since adaptive scoring means early answers can influence later question difficulty
- Flag uncertain questions mentally and move on rather than dwelling, since CAT exams generally do not allow returning to previous questions
- Eliminate obviously incorrect answers first to improve your odds on questions where you are unsure
Common Mistakes to Avoid
- Memorizing definitions without understanding how concepts apply in scenario-based questions
- Neglecting the lower-weighted domains entirely, since every domain contributes to the overall score
- Underestimating how much vocabulary the exam expects, especially for candidates without prior IT background
- Skipping practice exams, which are one of the best ways to build comfort with question phrasing and pacing
Treat the exam as a test of applied understanding rather than rote recall, and give yourself enough runway before test day to reinforce weaker domains.
Preparing for the CC exam does not require expensive bootcamps or paid courses. A combination of targeted, freely available study tools can cover most of what the exam expects, especially when used consistently over several weeks.
Practice Questions
Working through realistic practice questions helps candidates get comfortable with the phrasing and scenario-based style used on the actual exam, and highlights which domains need more attention before test day. Since the CC exam spans five distinct domains with different weightings, practicing across all of them, not just the largest ones, helps avoid gaps.
Flashcards
Flashcards are well suited to a terminology-heavy exam like this one. Short, frequent review sessions using flashcards reinforce recall of key terms and concepts from each domain, making them a useful daily habit during the final weeks of preparation.
Glossary
A comprehensive glossary of cybersecurity terms gives candidates a quick reference for unfamiliar vocabulary encountered while studying. Since Domain 1 introduces much of the terminology used throughout the rest of the exam, reviewing a glossary early in the study process pays dividends later.
Used together, these free resources let candidates simulate the exam experience, reinforce weak areas, and build the vocabulary fluency the CC exam is designed to test, all without additional cost beyond the registration fee itself.
Sources
- 1.CC Certification Exam Outline — ISC2 (accessed Jul 18, 2026)
- 2.How to Register, Schedule, Cancel, Pay For Your ISC2 Exam — ISC2 (accessed Jul 18, 2026)
- 3.Certified in Cybersecurity (CC) Certification Overview — ISC2 (accessed Jul 18, 2026)
- 4.ISC2 Annual Maintenance Fees (AMF) Overview — ISC2 (accessed Jul 18, 2026)
- 5.ISC2 Exam Pricing — ISC2 (accessed Jul 18, 2026)