Practice for the ISC2 Certified in Cybersecurity (CC) Full Exams '26 exam with 20 exam-style practice questions, instant answer reveals, and concise explanations of every correct answer. Topics include: What is the term for the random value added to a password to prevent rainbow table attacks?. Follow @CertPunch and visit certpunch.com for more certification practice exams and study content.
Prefer hands-on? Take this round as an interactive practice test — answer every question, get instant feedback, and see your score: Start the ISC2 Certified in Cybersecurity (CC) Full Exams '26 practice test →
What you will practice
- What is the term for the random value added to a password to prevent rainbow table attacks?
- What technology is used to ensure only authorized software is used within an organization?
- Which of the following tools would be the BEST to prevent unauthorized data exfiltration from a corporate net…
- How does a Business Impact Analysis contribute to the disaster recovery planning process?
- What is the PRIMARY purpose of using a mantrap in physical access control?
- Which principle of the ISC2 Code of Ethics Canons obliges you to prioritize public interest and protect criti…
Answers and explanations
Tap a question to expand the answer and the exam reasoning. Try to commit to your own pick first.
Q1. What is the term for the random value added to a password to prevent rainbow table attacks?
Answer: D. Salt
A salt is a random value added to a password before it is hashed to ensure unique outputs and prevent rainbow table attacks. MD5 is a weak hashing algorithm, while an extender is irrelevant, making Salt the only correct option.
Q2. What technology is used to ensure only authorized software is used within an organization?
Answer: D. Allow list
An allow list ensures only explicitly approved applications can run on a system, blocking everything else by default. A deny list only blocks known malicious software, which fails to prevent unknown threats.
Q3. Which of the following tools would be the BEST to prevent unauthorized data exfiltration from a corporate network?
Answer: B. Data Loss Prevention (DLP)
Data Loss Prevention tools are specifically designed to detect and block the unauthorized transmission of sensitive data. A network intrusion detection system only detects malicious activity, whereas a firewall simply controls traffic flow.
Q4. How does a Business Impact Analysis contribute to the disaster recovery planning process?
Answer: C. By identifying the critical systems and processes that must be prioritized
A Business Impact Analysis identifies critical systems and processes to prioritize recovery efforts during a disaster. It does not prevent disasters or ignore impacts, but rather forms the foundation of continuity planning.
Q5. What is the PRIMARY purpose of using a mantrap in physical access control?
Answer: D. To prevent tailgating or piggybacking
A mantrap prevents tailgating or piggybacking by using two interlocking doors that allow only one person to pass at a time. It mitigates unauthorized physical entry rather than serving as an authentication factor.
Q6. Which principle of the ISC2 Code of Ethics Canons obliges you to prioritize public interest and protect critical infrastructure over personal or organizational interests?
Answer: A. Protect society, the common good, necessary public trust and confidence, and the infrastructure
The first canon requires protecting society, the common good, public trust, and infrastructure. This canon sits above all others, meaning public safety always supersedes personal or organizational interests.
Q7. Which ISC2 Code of Ethics canon is being enacted when an employee refuses a bribe from a vendor to recommend their product and reports the incident?
Answer: D. Act honorably, honestly, justly, responsibly, and legally
Refusing a bribe demonstrates the requirement to act honorably, honestly, justly, responsibly, and legally. The other canons address public infrastructure, employer service quality, or advancing the profession, none of which directly cover personal integrity.
Q8. Which IPSec component is used to encrypt IP packets?
Answer: A. Encapsulating Security Payload
The Encapsulating Security Payload, or ESP, provides confidentiality by encrypting IP packet payloads. A common trap is Authentication Header, which provides integrity but does not encrypt data.
Q9. Which of the following is a logical access control method that verifies the identity of a user before granting access to a system?
Answer: C. Authentication
Authentication is the process of verifying user identity before granting access. The other options represent security controls like encryption or traffic monitoring that protect data rather than directly verifying identity.
Q10. What is the primary benefit of incorporating real-life examples and scenarios into security awareness training?
Answer: A. To make the training more engaging and help employees better understand the practical implications of security best practices
Real-life examples make security awareness training more engaging and help employees understand practical applications. The remaining options represent negative outcomes that actively harm an organization's security posture.
Q11. What is the PRIMARY purpose of implementing role-based access control (RBAC)?
Answer: B. To grant users access to resources based on their job responsibilities
Role-based access control grants users access to resources based on their job responsibilities. The other options describe physical security, encryption, and network monitoring, which are distinct concepts. The exam cue here is that RBAC maps permissions to job functions rather than individual identities.
Q12. Which technology is BEST for port-based authentication to ensure that network clients authenticate before use?
Answer: B. 802.1x
802.1x is the best technology for port-based authentication, ensuring network clients authenticate before gaining access. The trap is picking a standard like 802.3 or 802.11g, which simply define Ethernet and wireless transmission rather than enforcing network access control.
Q13. What term is used to describe phishing attacks that specifically target company administrators?
Answer: C. Whaling attacks
Whaling attacks are highly targeted phishing campaigns aimed at high-level executives and administrators. The other options are simply made up distractors designed to test your knowledge of social engineering terminology.
Q14. What type of malware is designed to replicate itself and spread to other devices without any user intervention?
Answer: A. Worm
Worms replicate independently across networks without user action. Viruses require host execution, distinguishing them from autonomous worms.
Q15. Which right allows a data subject in the UK to request the erasure of their personal data under certain conditions?
Answer: D. Right to be forgotten
The right to be forgotten allows individuals to request data erasure under privacy laws. Data portability involves moving data, not deleting it.
Q16. Which of the following is NOT a common system hardening practice?
Answer: B. Regularly performing backups
Performing regular backups is a disaster recovery practice, not a system hardening technique. Hardening reduces an attack surface by disabling unnecessary services, patching software, and implementing strong passwords.
Q17. Which term describes the acceptable range of potential losses that an organization is willing to accept in pursuit of its objectives?
Answer: D. Risk tolerance
Risk tolerance defines the acceptable range of variation within an organization's overall risk appetite. Risk appetite is a broad high-level statement, while risk capacity is the absolute maximum risk an organization can survive.
Q18. Which of the following security measures is most effective in protecting PII stored on a laptop in case of theft?
Answer: B. Full-disk encryption
Full-disk encryption protects data at rest by making it unreadable without the proper decryption key. Firewalls and antivirus software protect against network threats and malware, but they do not prevent a thief from directly reading the physical drive.
Q19. In the context of the CIA Triad, which of the following security controls would primarily enhance data availability?
Answer: A. Regularly backing up data and using redundant systems
Regularly backing up data and using redundant systems directly ensures timely access to information, fulfilling the availability principle of the CIA Triad. Encryption and authentication primarily protect confidentiality, while monitoring protects integrity and detects threats.
Q20. Which of the following system hardening techniques involves reducing the attack surface by removing unnecessary software and services?
Answer: A. Reducing the number of elements of a system
Reducing the number of system elements removes unnecessary software and services to minimize the attack surface. Patch management focuses on fixing vulnerabilities, while configuration management tracks system changes rather than eliminating unnecessary components.
More ISC2 Certified in Cybersecurity (CC) Full Exams '26 drills and other practice exams are on @CertPunch. New rounds drop every few days at certpunch.com.