Practice for the ISC2 Certified in Cybersecurity (CC) Full Exams '26 exam with 20 exam-style practice questions, instant answer reveals, and concise explanations of every correct answer. Topics include: What is the role of an Access Control List (ACL) in a Unix file system?. Follow @CertPunch and visit certpunch.com for more certification practice exams and study content.
Prefer hands-on? Take this round as an interactive practice test — answer every question, get instant feedback, and see your score: Start the ISC2 Certified in Cybersecurity (CC) Full Exams '26 practice test →
What you will practice
- What is the role of an Access Control List (ACL) in a Unix file system?
- What network security device allows remote users to securely connect to a private network over the public Int…
- What access control model allows the owner of a file to grant access to others via an access control list?
- What is the PRIMARY purpose of using an intrusion detection and prevention system?
- A company wants to replace its traditional firewall with a solution that can both filter network traffic and…
- Which of the following documents establishes context and sets out strategic direction and priorities?
Answers and explanations
Tap a question to expand the answer and the exam reasoning. Try to commit to your own pick first.
Q1. What is the role of an Access Control List (ACL) in a Unix file system?
Answer: A. Specify which users have access to resources
An access control list specifies exactly which users or groups have access to specific system resources. It does not actively monitor unauthorized access, nor does it dynamically adjust permissions or set default configurations without administrative input.
Q2. What network security device allows remote users to securely connect to a private network over the public Internet by encrypting their communications?
Answer: B. Virtual Private Network (VPN)
A virtual private network securely connects remote users to a private network over the public internet by encrypting their communications. Firewalls filter traffic, intrusion detection systems monitor for threats, and proxy servers act as intermediaries.
Q3. What access control model allows the owner of a file to grant access to others via an access control list?
Answer: C. Discretionary
Discretionary access control empowers the owner or creator of a resource to decide who gets access and what actions they can perform. Role-based and non-discretionary models rely on system administrators or central organizational policies.
Q4. What is the PRIMARY purpose of using an intrusion detection and prevention system?
Answer: A. To detect and block malicious attacks
An intrusion detection and prevention system actively monitors network traffic to detect and block malicious attacks in real time. Stopping malicious code or detecting connections are specific secondary functions rather than the primary overarching purpose.
Q5. A company wants to replace its traditional firewall with a solution that can both filter network traffic and perform advanced security functions such as application awareness and intrusion prevention in a single integrated system. Which te…
Answer: A. A next-generation firewall (NGFW)
A next-generation firewall integrates traditional traffic filtering with advanced features like application awareness and intrusion prevention. The other options handle isolated tasks like encryption or blocking exploits but cannot replace comprehensive firewall functionality.
Q6. Which of the following documents establishes context and sets out strategic direction and priorities?
Answer: D. Policies
Policies establish strategic direction and priorities by outlining high-level organizational rules and expectations. Standards mandate specific technical requirements, while procedures provide the granular steps needed to implement those policies.
Q7. Which of the following is a key component of a Business Continuity Plan (BCP)?
Answer: B. Developing strategies to maintain essential operations during and after a major incident
A business continuity plan develops strategies to maintain essential operations during and after a major disruption. The negative distractors are dangerous assumptions because ignoring alternate facilities or focusing solely on prevention guarantees operational failure.
Q8. Which of the following cloud models puts MOST responsibility on the cloud provider?
Answer: C. SaaS
Software as a Service places the most security responsibility on the provider because they manage everything from the underlying infrastructure to the application itself. Infrastructure and Platform models leave the customer managing applications or operating systems.
Q9. In the context of the risk management process, what does the term 'residual risk' refer to?
Answer: C. The risk that remains after all possible controls and countermeasures have been applied
Residual risk is the portion of risk that remains after all selected controls and countermeasures have been applied. Total elimination of risk is impossible, and the initial risk before controls is simply the inherent risk.
Q10. An organization wants to decrease the number of help desk cases related to password changes. What measure can the organization take?
Answer: D. Self-service password reset
Implementing self-service password reset directly decreases help desk tickets by empowering users to securely unlock their own accounts. Alternative authentication methods improve security but fail to address the volume of password reset requests.
Q11. Which principle is PRIMARILY concerned with preventing unauthorized data alteration or destruction?
Answer: D. Integrity
Integrity ensures data remains accurate and unaltered during its lifecycle. While authentication verifies access, it does not prevent modifications once access is granted.
Q12. Which policy will outline if personally owned equipment is permitted for business purposes?
Answer: D. Bring Your Own Device (BYOD) Policy
A bring your own device policy governs personal equipment use for business. Acceptable use dictates behavior, not hardware permissions.
Q13. Digital signatures PRIMARILY rely on which cryptographic technique?
Answer: A. Asymmetric-key cryptography
Digital signatures rely on asymmetric cryptography, using public and private key pairs. Symmetric cryptography uses shared keys, making non-repudiation impossible.
Q14. Which attacks involve an attacker using a list of pre-computed hashes to find a matching hash value for a user's password?
Answer: C. Rainbow Table Attack
Rainbow table attacks use pre-computed hashes to reverse passwords quickly. Dictionary attacks guess passwords using word lists rather than hash databases.
Q15. Which of the following is a PRIMARY objective of implementing physical access controls in an organization?
Answer: B. To prevent unauthorized access to facilities and protect sensitive information and resources
Physical access controls prevent unauthorized facility entry to protect assets. Public access and unrestricted entry defeat security goals, while technical controls remain necessary.
Q16. Defense in depth is a strategy that:
Answer: A. …that employs multiple layers of security measures for comprehensive protection
Defense in depth employs multiple layers of security controls to protect systems and data. Relying on a single layer leaves vulnerabilities, so this layered approach provides comprehensive protection against various threats.
Q17. A security analyst discovers a vulnerability in a client's system but decides to withhold the information, fearing negative publicity for the client. Which ISC2 Code of Ethics Canon has the analyst potentially violated?
Answer: A. Provide diligent and competent service to principals
Withholding crucial vulnerability information violates the canon to provide diligent and competent service to principals. Failing to inform the client prevents them from making informed decisions and securing their environment.
Q18. Which one of the following security tools would be the BEST to detect malicious behavior on a device (e.g., your personal computer)?
Answer: B. HIDS
A Host-based Intrusion Detection System monitors and detects malicious behavior on an individual device. A Network Intrusion Detection System monitors network traffic, while a firewall blocks unauthorized traffic.
Q19. What is the PRIMARY purpose of a forensic investigation during the analysis phase of an incident response?
Answer: B. To collect evidence and maintain its chain of custody for potential legal proceedings
Forensic investigations during incident response focus on collecting and preserving evidence to maintain a strict chain of custody for legal proceedings. Identifying attacker motivation or updating risk registries are secondary tasks that depend on properly preserved evidence.
Q20. Which of the following incident response team roles is responsible for coordinating communication between the incident response team and external stakeholders, such as law enforcement or media?
Answer: D. Public relations coordinator
The public relations coordinator manages consistent and accurate communication with external parties, including media and law enforcement. The technical and incident leads focus on operational containment, while legal advisors handle liability and compliance guidance.
More ISC2 Certified in Cybersecurity (CC) Full Exams '26 drills and other practice exams are on @CertPunch. New rounds drop every few days at certpunch.com.