Practice for the ISC2 Certified in Cybersecurity (CC) Full Exams '26 exam with 20 exam-style practice questions, instant answer reveals, and concise explanations of every correct answer. Topics include: Which type of attack will most effectively provide privileged access (root access in Unix/Linux platforms) to a computer. Follow @CertPunch and visit certpunch.com for more certification practice exams and study content.
Prefer hands-on? Take this round as an interactive practice test — answer every question, get instant feedback, and see your score: Start the ISC2 Certified in Cybersecurity (CC) Full Exams '26 practice test →
What you will practice
- Which type of attack will most effectively provide privileged access (root access in Unix/Linux platforms) to…
- Which of the following Cybersecurity concepts guarantees that information is accessible only to those authori…
- If there is no time constraint, which protocol should be employed to establish a reliable connection between…
- Which concept describes an information security strategy that integrates people, technology and operations in…
- When a company hires an insurance company to mitigate risk, which risk management technique is being applied?
- Which regulations address data protection and privacy in Europe?
Answers and explanations
Tap a question to expand the answer and the exam reasoning. Try to commit to your own pick first.
Q1. Which type of attack will most effectively provide privileged access (root access in Unix/Linux platforms) to a computer while hiding its presence?
Answer: C. Rootkits
A rootkit is designed to obtain and maintain highly privileged access while actively concealing its existence from system monitoring tools. Trojans provide backdoors but lack the robust stealth mechanisms inherent to rootkits, making them less effective for hidden root access.
Q2. Which of the following Cybersecurity concepts guarantees that information is accessible only to those authorized to access it?
Answer: A. Confidentiality
Confidentiality ensures that sensitive data is only accessible and readable by authorized individuals. Authentication verifies identity but does not itself enforce access rules, and accessibility focuses on system uptime rather than restricting unauthorized data disclosure.
Q3. If there is no time constraint, which protocol should be employed to establish a reliable connection between two devices?
Answer: B. TCP
TCP establishes a reliable connection by ensuring error-checked, ordered packet delivery, making it ideal when data integrity outweighs speed constraints. UDP skips handshake processes and error correction to favor low-latency transmission, rendering it unsuitable for reliable delivery.
Q4. Which concept describes an information security strategy that integrates people, technology and operations in order to establish security controls across multiple layers of the organization?
Answer: D. Defense in Depth
Defense in depth uses multiple, overlapping security controls across people, technology, and operations to protect an organization. Least privilege and separation of duties are access control principles, while privileged accounts are an administrative asset type.
Q5. When a company hires an insurance company to mitigate risk, which risk management technique is being applied?
Answer: D. Risk transfer
Risk transfer shifts the financial consequences of a threat to a third party, typically by purchasing an insurance policy. Risk mitigation reduces threat likelihood or impact, and risk avoidance requires eliminating the vulnerable process entirely.
Q6. Which regulations address data protection and privacy in Europe?
Answer: A. GDPR
The General Data Protection Regulation, or GDPR, is the European Union legislation governing data protection and privacy. The other options are United States regulations and do not apply to European data governance.
Q7. A web server that accepts requests from external clients should be placed in which network?
Answer: B. DMZ
Publicly accessible servers like web servers belong in a demilitarized zone, or DMZ, to isolate them from the trusted internal network. Placing them internally exposes the network, while a VPN is an access tunnel, not a hosting segment.
Q8. Which of the following is NOT an example of a physical security control?
Answer: D. Firewalls
Firewalls are technical controls regulating network traffic, not physical barriers protecting facilities. Security cameras, biometric readers, and electronic locks act as tangible, physical deterrents restricting direct access to buildings.
Q9. How many layers does the OSI model have?
Answer: D. 7
The Open Systems Interconnection model consists of exactly seven distinct layers. These range from the physical hardware layer up to the application layer, differing from the four-layer TCP/IP model.
Q10. Alice and Bob are exchanging sensitive financial data over an unsecured network. Alice prepares a document and wants to ensure that only Bob can decrypt and read the contents. To achieve this, she uses an asymmetric encryption algorithm. W…
Answer: A. Bob's public key
To ensure confidentiality in asymmetric encryption, the sender must encrypt the message using the recipient's public key. This guarantees that only the intended recipient, who holds the matching private key, can decrypt and read the contents. Using your own private key provides non-repudiation, not confidentiality.
Q11. Which of the following properties is NOT guaranteed by Digital Signatures?
Answer: C. Confidentiality
Digital signatures provide authentication, integrity, and non-repudiation, but they do not provide confidentiality. A signature verifies the sender and proves the message was not altered, but it does not encrypt the contents to hide them from unauthorized viewers.
Q12. Which access control model specifies access to an object based on the subject's role in the organization?
Answer: B. RBAC
Role-based access control grants permissions based on the user's assigned role or job function within the organization. Eliminate mandatory and discretionary models because they rely on security labels or direct owner discretion rather than organizational roles.
Q13. Which of these would be the best option if a network administrator needs to control access to a network?
Answer: C. NAC
Network Access Control enforces security policy by restricting device access to the network until appropriate credentials and compliance checks are met. Intrusion detection and SIEM systems are monitoring tools that lack the active enforcement capability needed to block initial access.
Q14. An entity that acts to exploit a target organization's system vulnerabilities is a:
Answer: B. Threat Actor
The correct answer proves a threat actor is an entity that intentionally exploits system vulnerabilities to compromise security. While an attacker is a plausible synonym, threat actor is the precise ISC2 exam terminology for this specific concept.
Q15. Which of the following is NOT an element of system security configuration management?
Answer: C. Audit logs
The correct answer proves audit logs are generated by verification and audit procedures rather than serving as core elements of system security configuration management. Baselines, inventories, and updates are foundational steps for securely configuring systems.
Q16. Which of the following documents contains elements that are NOT mandatory?
Answer: B. Guidelines
Guidelines are voluntary recommendations providing flexibility, whereas policies, procedures, and regulations mandate strict compliance. Recognizing this distinction in force is essential for categorizing governance documents accurately.
Q17. What is an effective way of hardening a system?
Answer: A. Patch the system
Applying patches and updates directly eliminates system vulnerabilities, hardening it against exploitation. The other options focus on detection or architectural isolation rather than actively reducing the system's inherent attack surface.
Q18. Which of the following is NOT a social engineering technique?
Answer: D. Segregation
Segregation, specifically segregation of duties, is an administrative control principle preventing fraud by splitting responsibilities. Baiting, pretexting, and quid pro quo are all recognized social engineering tactics used to manipulate human behavior.
Q19. After an earthquake disrupts business operations, which document contains the procedures required to return business to normal operation?
Answer: A. The Disaster Recovery Plan
The Disaster Recovery Plan guides restoring IT infrastructure and operations after a catastrophic event. A Business Impact Analysis identifies critical functions, while the Business Continuity Plan sustains operations during the disruption.
Q20. In which phase of an incident response plan are incidents prioritized based on their severity and potential impact?
Answer: D. Detection and Analysis
Incidents are prioritized during the detection and analysis phase. The team assesses alerts to determine severity and impact, ensuring the most critical threats are addressed first. Other phases handle preparation, containment, or post-incident review rather than initial prioritization.
More ISC2 Certified in Cybersecurity (CC) Full Exams '26 drills and other practice exams are on @CertPunch. New rounds drop every few days at certpunch.com.