ISC2 Certified in Cybersecurity (CC) Full Exams ’26 Practice Exam Questions and An – Part 10/10

Practice for the ISC2 Certified in Cybersecurity (CC) Full Exams '26 exam with 19 exam-style practice questions, instant answer reveals, and concise explanations of every correct answer. Topics include: Which of the following security concepts enables message recipients to prove the authenticity of the message sender to a. Follow @CertPunch and visit certpunch.com for more certification practice exams and study content.

Prefer hands-on? Take this round as an interactive practice test — answer every question, get instant feedback, and see your score: Start the ISC2 Certified in Cybersecurity (CC) Full Exams '26 practice test →

What you will practice

  • Which of the following security concepts enables message recipients to prove the authenticity of the message…
  • What is the PRIMARY goal of a visitor management policy as part of physical access controls?
  • What is the name of the network tool that changes and maps source addresses of client requests for client ano…
  • Which access control model is more flexible and scalable between Mandatory Access Control (MAC) and Discretio…
  • What is the recommended approach for assessing risks when designing a Business Continuity Plan (BCP) that con…
  • What is the best technology for enforcing uniform security settings on multiple mobile devices in an organiza…

Answers and explanations

Tap a question to expand the answer and the exam reasoning. Try to commit to your own pick first.

Q1. Which of the following security concepts enables message recipients to prove the authenticity of the message sender to a third party?

Answer: C. Non-repudiation

Non-repudiation provides undeniable proof that a sender transmitted a message, preventing them from denying the action. Authentication only validates identity for the recipient, while integrity proves the message was unaltered, but neither concept alone prevents the sender from later denying it.

Q2. What is the PRIMARY goal of a visitor management policy as part of physical access controls?

Answer: A. To control and monitor visitor access to the facility, ensuring only authorized individuals are granted entry

A visitor management policy tracks and restricts guest access to ensure only authorized individuals enter the facility. The remaining options describe weakening physical security, which directly contradicts the goal of safeguarding the facility and its physical assets.

Q3. What is the name of the network tool that changes and maps source addresses of client requests for client anonymity?

Answer: D. A proxy

A proxy server acts as an intermediary, forwarding client requests while masking the original IP address for anonymity. Standard gateways, routers, and firewalls focus on routing and filtering traffic rather than deliberately rewriting source addresses.

Q4. Which access control model is more flexible and scalable between Mandatory Access Control (MAC) and Discretionary Access Control (DAC)?

Answer: A. DAC, for enabling individual administrators to make decisions and achieve scalability and flexibility

Discretionary Access Control, or DAC, is more flexible because it allows individual resource owners to make access decisions. Eliminate Mandatory Access Control because adding security labels actually increases administrative rigidity, not scalability.

Q5. What is the recommended approach for assessing risks when designing a Business Continuity Plan (BCP) that considers tangible and intangible assets?

Answer: C. Combination of quantitative and qualitative risk assessment

Assessing both tangible and intangible assets requires a combination of quantitative and qualitative risk assessments. Quantitative methods calculate financial loss, while qualitative methods evaluate subjective impacts like reputation.

Q6. What is the best technology for enforcing uniform security settings on multiple mobile devices in an organization?

Answer: C. MDM

Mobile Device Management provides organizations with the tools to enforce security policies and manage mobile devices. Intrusion detection, intrusion prevention, and Security Information and Event Management systems focus on network threat detection rather than device configuration enforcement.

Q7. What is the other name given to security controls?

Answer: C. Security safeguards

Security controls are commonly referred to as safeguards to protect the confidentiality, integrity, and availability of data. The other terms are informal or describe specific software agents rather than the broad administrative, technical, or physical measures used.

Q8. Which of the following can be considered an example of a computer security incident?

Answer: B. Conducting an unauthorized vulnerability scan

An unauthorized vulnerability scan qualifies as an incident because it threatens system confidentiality and integrity through active probing. Routine administrative tasks, like updating signatures or completing backups, are standard operational events.

Q9. Which port is typically used to identify unencrypted FTP traffic by an IDS?

Answer: D. TCP port 21

File Transfer Protocol control traffic operates over TCP port 21. An intrusion detection system monitors this specific port to identify unencrypted FTP connections, distinguishing it from Telnet on port 23 or TFTP on UDP port 69.

Q10. Which of the following is a valid public IP address?

Answer: D. 12.123.23.23

A valid public IP address must fall outside private ranges and contain octets no higher than 255. Option D is public, while option A is private, and options B and C contain invalid octets or syntax, quickly eliminating them.

Q11. What is an 'on-path' attack?

Answer: D. An attack that attempts to intercept the communication between two devices in order to modify the information.

An on-path attack places a threat actor between two communicating devices to intercept or modify transmitted data. Eliminate the other options because passive observation does not include modification, and DDoS attacks use secondary victim systems.

Q12. Which cloud service model provides the highest level of flexibility and customization for the organization?

Answer: C. Infrastructure-as-a-Service (IaaS)

Infrastructure as a Service provides the highest level of flexibility and customization among cloud models by allowing organizations to manage operating systems, applications, and virtualized hardware. While on-premises offers maximum control, it is not categorized as a cloud service.

Q13. The PRIMARY objective of the Risk Management process is:

Answer: D. …To identify, assess, and prioritize risks, and implement appropriate controls to minimize their potential impact

Risk management is a proactive process of identifying, assessing, and prioritizing risks. Appropriate controls are then selected and implemented to reduce their potential impact. Eliminating all risks is impractical, while minimizing costs or relying on reactive measures leaves an organization exposed to unnecessary threats.

Q14. In disaster recovery planning, which of the following would typically be considered examples of natural disasters? (I) Hacking incident, (II) Tsunami, (III) Forest fire, (IV) Terrorism

Answer: B. II and III only

Natural disasters such as tsunamis and forest fires are naturally occurring events considered during disaster recovery planning. Hacking and terrorism are intentional, man-made security incidents, making them separate threat categories that require different preventive controls.

Q15. During a security incident, where will an incident responder member find the most recent modification to a system's security settings?

Answer: A. Change log

The change log records all modifications made to a system, including security settings. Security logs track events like logon attempts, while application and server logs capture software and operating system errors.

Q16. A Memorandum of Understanding (MOU) or Memorandum of Agreement (MOA) is:

Answer: B. … a formal agreement between two or more parties outlining the terms of their working relationship

A Memorandum of Understanding or Agreement is a formal document outlining the working relationship between parties. It differs from strict contracts by often lacking legal binding, focusing instead on mutual expectations.

Q17. What is the main purpose of a Service-Level Agreement (SLA)?

Answer: B. To outline the services provided by an MSP

A Service-Level Agreement defines the expected services and obligations between a service provider and a customer. It establishes measurable performance standards, unlike network segmentation, secure network access, or cloud access configuration.

Q18. What is the difference between Network Access Control (NAC) and a Virtual Private Network (VPN)?

Answer: C. NAC is used to control network access based on a determined policy, while VPN is used to create a secure connection

Network Access Control restricts network access based on endpoint compliance with defined policies. A Virtual Private Network creates an encrypted tunnel for secure remote connections, which distractors oversimplify by isolating the encryption feature.

Q19. What type of attack is an APT attack?

Answer: C. Advanced persistent threat attack

An Advanced Persistent Threat is a stealthy, continuous computer intrusion process targeting a specific entity. While the other options represent valid attack vectors, the acronym APT literally stands for Advanced Persistent Threat, making it the only correct choice.

More ISC2 Certified in Cybersecurity (CC) Full Exams '26 drills and other practice exams are on @CertPunch. New rounds drop every few days at certpunch.com.

Scroll to Top