ISC2 Certified in Cybersecurity (CC) Full Exams ’26 Practice Exam Questions and – Part 14/15

Practice for the ISC2 Certified in Cybersecurity (CC) Full Exams '26 exam with 20 exam-style practice questions, instant answer reveals, and concise explanations of every correct answer. Topics include: Which U.S. government agency within the Department of Commerce publishes and makes available for free download a wide va. Follow @CertPunch and visit certpunch.com for more certification practice exams and study content.

Prefer hands-on? Take this round as an interactive practice test — answer every question, get instant feedback, and see your score: Start the ISC2 Certified in Cybersecurity (CC) Full Exams '26 practice test →

What you will practice

  • Which U.S. government agency within the Department of Commerce publishes and makes available for free downloa…
  • What is the PRIMARY objective of baselines?
  • Which of the following is NOT considered an insider threat?
  • What type of factor is a callback to a mobile phone?
  • What is the main difference between symmetric and asymmetric encryption?
  • Which of the following options is NOT an access control layer?

Answers and explanations

Tap a question to expand the answer and the exam reasoning. Try to commit to your own pick first.

Q1. Which U.S. government agency within the Department of Commerce publishes and makes available for free download a wide variety of technical standards, including those for information technology and information security?

Answer: A. National Institute of Standards and Technology (NIST)

The National Institute of Standards and Technology is a U.S. government agency that publishes free cybersecurity frameworks and technical standards. ISO, IEEE, and IETF are international or professional organizations that typically charge for their published standards.

Q2. What is the PRIMARY objective of baselines?

Answer: A. To establish a minimum level of protection that can be used as a reference point

Baselines establish a minimum level of protection and standard operating conditions to serve as a reference point for future security comparisons. Identifying threats or monitoring events are functions of risk assessment and security tools, not the baselines themselves.

Q3. Which of the following is NOT considered an insider threat?

Answer: D. An external hacker breaching the company's firewall

An insider threat originates from someone with authorized access, such as an employee or vendor. External hackers do not have authorized internal access, which clearly eliminates employees, contractors, and vendors as examples of insiders.

Q4. What type of factor is a callback to a mobile phone?

Answer: D. Something you have

A mobile phone callback is a possession-based authentication factor. The system verifies that the user has the registered physical device. It does not rely on biometric traits, knowledge, or location.

Q5. What is the main difference between symmetric and asymmetric encryption?

Answer: A. Symmetric encryption uses the same key for encryption and decryption, while asymmetric encryption uses different keys for encryption and decryption

Symmetric encryption uses the same secret key for both encryption and decryption. Asymmetric encryption uses a public and private key pair, rendering the other options incorrect regarding speed and fundamental mechanics.

Q6. Which of the following options is NOT an access control layer?

Answer: B. Policy

Access control consists of three layers: technical, physical, and administrative. Policies govern administrative controls, but the policy itself is not categorized as a standalone fourth layer.

Q7. During which phase of the incident response process would it be most appropriate to implement long-term fixes to prevent similar incidents in the future?

Answer: D. Post-incident Activity

Post-incident activity focuses on long-term fixes and lessons learned after an event is resolved. Containment and eradication handle immediate threats, whereas preparation establishes baseline readiness.

Q8. Alice and Bob want to send secret messages to each other using asymmetric encryption. Alice receives a message from Bob. What key does Alice use to decrypt the encrypted message she received?

Answer: C. Alice's private key

In asymmetric encryption, a sender encrypts a confidential message using the recipient's public key. The recipient must then use their matching private key to decrypt it, ensuring only the intended party can read the message.

Q9. What is the PRIMARY identity and access management function you use when providing a user ID and password?

Answer: C. Authentication

Authentication proves a user's identity, typically by verifying credentials like a username and password. Authorization determines what resources an authenticated user can access, making the latter a distinct subsequent step.

Q10. What is the PRIMARY difference between a threat and a vulnerability?

Answer: A. A threat is a potential source of harm, while a vulnerability is a weakness in a system

A threat is any potential event or actor capable of causing harm, whereas a vulnerability is an actual flaw or weakness that a threat can exploit. Identifying this distinction is fundamental to assessing organizational risk.

Q11. When developing a banking website, what is the advised method to confirm user identities?

Answer: A. Requiring password and sms token

Requiring a password alongside an SMS token implements multi-factor authentication by combining something you know with something you have. Options like personal answers or PIN codes remain single-factor, lacking the necessary hardware verification.

Q12. What is the MOST formal document between a service provider and a customer that sets expectations FOR performance parameters?

Answer: C. Service-level agreement (SLA)

A Service-Level Agreement is a formal contract between a provider and a customer that defines specific performance metrics like uptime and response times. Internal departments use Operational Level Agreements, which differ from customer-facing commitments.

Q13. Which of the following is an example of a measure to protect confidentiality?

Answer: B. Access controls and encryption

Access controls and encryption are primary measures to protect the confidentiality of the CIA Triad by ensuring only authorized users can read sensitive data. Backups protect availability, while checksums and digital signatures protect data integrity.

Q14. Which of the options does not have attributes of a Privileged User Account?

Answer: A. It does not interact directly with servers and other infrastructure devices

Privileged accounts are specifically designed to interact directly with servers and infrastructure devices to perform critical administrative tasks. Requiring multi-factor authentication, assigning permissions, and enabling high-level logging are all required attributes of privileged accounts.

Q15. In the context of physical access controls, what is the purpose of implementing a mantrap?

Answer: A. To prevent tailgating

A mantrap is designed to prevent tailgating by creating a small space with two interlocking doors, ensuring only one person enters at a time. It does not replace security personnel or grant unrestricted access, but strictly controls physical entry.

Q16. Which of the following is a technical control?

Answer: D. Access control list (ACL)

An access control list is a technical control that enforces security policies by specifying system access permissions. Stop signs, acceptable use policies, and emergency procedures are administrative controls, as they govern human behavior and organizational processes.

Q17. What is the cloud computing model where customers share computing infrastructure without knowing each other's identity?

Answer: A. Public cloud

In a public cloud model, customers share computing infrastructure without knowing the identity of other tenants. Private clouds dedicate infrastructure to a single organization, while community clouds are shared among known organizations with common requirements.

Q18. Which of the following is a key component of a Disaster Recovery Plan (DRP)?

Answer: D. Establishing clear roles and responsibilities for personnel during disaster recovery efforts

A disaster recovery plan must establish clear roles and responsibilities for personnel to ensure effective response during a crisis. The other options describe ignoring backups and offsite facilities, which directly contradict disaster recovery best practices.

Q19. What security principle can help detect fraudulent behavior, such as employees transferring funds to their personal accounts?

Answer: B. Mandatory vacation

Mandatory vacation is a primary detective control used to uncover fraudulent behavior by requiring another employee to cover the perpetrator's duties. Separation of duties prevents fraud, but mandatory vacation detects ongoing malicious activity.

Q20. Which three OSI model layers correspond to the TCP/IP model's Application layer?

Answer: C. Application, Presentation, and Session

The Application layer of the TCP/IP model maps directly to the top three layers of the OSI model: Application, Presentation, and Session. A common trap is assuming a one-to-one mapping across all layers, but TCP/IP consolidates upper-layer functions.

More ISC2 Certified in Cybersecurity (CC) Full Exams '26 drills and other practice exams are on @CertPunch. New rounds drop every few days at certpunch.com.

Scroll to Top