ISC2 Certified in Cybersecurity (CC) Full Exams ’26 Practice Exam Questions and – Part 15/15

Practice for the ISC2 Certified in Cybersecurity (CC) Full Exams '26 exam with 19 exam-style practice questions, instant answer reveals, and concise explanations of every correct answer. Topics include: What technology prioritizes critical network traffic over browsing and social media?. Follow @CertPunch and visit certpunch.com for more certification practice exams and study content.

Prefer hands-on? Take this round as an interactive practice test — answer every question, get instant feedback, and see your score: Start the ISC2 Certified in Cybersecurity (CC) Full Exams '26 practice test →

What you will practice

  • What technology prioritizes critical network traffic over browsing and social media?
  • Which of the following types of information is considered PII?
  • What is the PRIMARY purpose of a password policy?
  • In an organization, which document provides step-by-step guidance in implementing a security measure?
  • Which of the following is a key component of the risk assessment process?
  • Which type of network attack involves an attacker intercepting and potentially altering the communication bet…

Answers and explanations

Tap a question to expand the answer and the exam reasoning. Try to commit to your own pick first.

Q1. What technology prioritizes critical network traffic over browsing and social media?

Answer: C. QoS

Quality of Service, or QoS, is the technology that prioritizes critical network traffic like voice and video over less important traffic. VLANs separate networks, TLS provides encryption, and VPNs create secure connections, but none of these directly manage traffic prioritization.

Q2. Which of the following types of information is considered PII?

Answer: C. A user's date of birth

Personally Identifiable Information includes data that can identify a specific individual, such as a user's date of birth. The elimination cue is that corporate policies, public posts, and topology diagrams do not directly identify a living person.

Q3. What is the PRIMARY purpose of a password policy?

Answer: B. To enforce the use of strong, complex passwords and periodic password changes

A password policy primarily enforces strong, complex passwords and periodic changes to reduce unauthorized access. Option C is a trap, as while unique passwords are a good practice, policy enforcement primarily targets complexity and lifecycle management rather than strict cross-system uniqueness.

Q4. In an organization, which document provides step-by-step guidance in implementing a security measure?

Answer: B. Procedures

Procedures provide the step-by-step, granular actions required to implement a specific security measure or technical process. Policies set the high-level organizational direction, while regulations are external legal requirements and standards provide mandatory baseline controls.

Q5. Which of the following is a key component of the risk assessment process?

Answer: B. Identifying and evaluating potential risks based on their likelihood and impact

Identifying and evaluating potential risks based on their likelihood and impact is the core goal of a risk assessment. The distractors describe bad security practices, such as ignoring threats or avoiding frameworks, which defeat the purpose of risk management.

Q6. Which type of network attack involves an attacker intercepting and potentially altering the communication between two parties without their knowledge?

Answer: A. On Path Attack

An on-path attack, formerly known as a man-in-the-middle attack, involves secretly intercepting and potentially altering communication between two parties. DDoS attacks overwhelm resources, and SQL injection targets web application databases.

Q7. What is the PRIMARY goal of a Disaster Recovery Plan (DRP)?

Answer: A. Restoring the business to full last-known reliable operations

A disaster recovery plan aims to restore systems and operations to their last known reliable state after a disruption. A business continuity plan keeps critical functions running during a crisis, while emergency response plans guide immediate physical safety actions.

Q8. What type of attack attempts to misdirect legitimate users to malicious websites by abusing URLs or hyperlinks in emails?

Answer: C. Phishing

Phishing attacks frequently abuse URLs and hyperlinks in emails to misdirect users to fraudulent websites. Spoofing only fakes an identity, while a denial-of-service attack disrupts availability rather than stealing credentials.

Q9. Which type of network attack involves an attacker sending specially crafted malicious data to an application or system, causing it to crash or become unresponsive?

Answer: D. Buffer Overflow Attack

A buffer overflow occurs when malicious data exceeds allocated memory, causing crashes. Denial of service uses request flooding, while on-path attacks intercept traffic.

Q10. Which of the following physical access control methods is designed to authenticate the identity of individuals entering a facility?

Answer: C. Key cards

Key cards authenticate users by matching embedded data against an authorized database. Surveillance and sign-in sheets monitor activity but lack identity verification.

Q11. What access control problems arise if during an audit it is found that an IT manager retains permission access to shared folders from his previous company roles?

Answer: C. Privilege creep

Privilege creep occurs when users accumulate outdated permissions after changing roles. Excessive provisioning happens initially, whereas creep develops over time.

Q12. What is the situation that occurs when a user accumulates system privileges that exceed the requirements of the user's job?

Answer: A. Privilege creep

Privilege creep occurs when a user accumulates system privileges that exceed their job requirements over time. However, the term excessive privileges also accurately describes this state, making the options potentially ambiguous. Excessive privileges can result from privilege creep.

Q13. Which of the following is NOT a recommended practice for password protection?

Answer: D. Reusing passwords for multiple systems

Reusing passwords across multiple systems increases the risk of credential stuffing attacks. Using a password manager and maintaining unique credentials are fundamental security practices that prevent a single breach from compromising multiple accounts.

Q14. What is the term for the GDPR requirement allowing individuals to request the termination of their data dissemination?

Answer: D. The right to be forgotten

The right to be forgotten allows individuals to request the erasure of their personal data. Data portability and access rights grant visibility or movement of data, but they do not mandate its deletion.

Q15. What is the primary objective of a Business Continuity Plan (BCP) in the context of incident response, business continuity, and disaster recovery concepts?

Answer: D. To ensure the organization can continue to operate during and after a disaster or major incident

A Business Continuity Plan ensures critical business operations continue during and after a disruption. Distractors suggesting the avoidance of recovery strategies or ignoring coordinated responses represent the exact opposite of continuity planning goals.

Q16. What attribute is NOT associated with a hashing algorithm?

Answer: C. A cryptographic key is required

Hashing provides integrity by creating a fixed-length digital fingerprint from variable-length data without using a cryptographic key. Options mentioning irreversibility and collision resistance describe essential hash properties, making the key requirement the false attribute.

Q17. Which of the following is not a physical security control?

Answer: A. Stop Sign in a Parking Lot

A stop sign is an administrative control because it directs human behavior through a rule rather than physically blocking access. Physical controls are tangible barriers like bollards, turnstiles, and door locks that physically restrict entry.

Q18. Which type of token-based authentication generates codes at fixed intervals without a server challenge?

Answer: D. Synchronous

Synchronous tokens generate one-time passwords at fixed time intervals, relying on internal clocks rather than a server challenge. Asynchronous tokens require a challenge-response mechanism, while smart cards and RFID use different hardware methods.

Q19. Which of the following is the MOST effective method to destroy data on a tape or disk?

Answer: A. Degaussing

Degaussing is the most effective method to destroy data on magnetic tapes or disks, using a strong magnetic field to permanently erase data. Disk zeroing, formatting, and encryption do not physically destroy the magnetic media, leaving potential for data recovery.

More ISC2 Certified in Cybersecurity (CC) Full Exams '26 drills and other practice exams are on @CertPunch. New rounds drop every few days at certpunch.com.

Scroll to Top