ISC2 Certified in Cybersecurity (CC) Full Exams ’26 Practice Exam Questions and An – Part 16/19

Practice for the ISC2 Certified in Cybersecurity (CC) Full Exams '26 exam with 24 exam-style practice questions, instant answer reveals, and concise explanations of every correct answer. Topics include: Which of the following is an example of biometric authentication?. Follow @CertPunch and visit certpunch.com for more certification practice exams and study content.

Prefer hands-on? Take this round as an interactive practice test — answer every question, get instant feedback, and see your score: Start the ISC2 Certified in Cybersecurity (CC) Full Exams '26 practice test →

What you will practice

  • Which of the following is an example of biometric authentication?
  • What is the first step in the risk management process?
  • Which of these is not one of the components of change management according to ISC2?
  • What does the acronym APT stand for?
  • Which of the following is an example of collusion?
  • Which of the following is NOT an ethical canon of the ISC2?

Answers and explanations

Tap a question to expand the answer and the exam reasoning. Try to commit to your own pick first.

Q1. Which of the following is an example of biometric authentication?

Answer: D. Voiceprint

Biometric authentication relies on unique biological characteristics, proving a voiceprint is the correct answer. The other options represent something you know, like a password or PIN, or something you have, like a physical key or token.

Q2. What is the first step in the risk management process?

Answer: C. Identify risks

The risk management process begins with identifying risks, as you cannot analyze or mitigate a threat without first discovering it. Analyzing, assessing, and mitigating risks are subsequent phases that rely entirely on accurate initial identification.

Q3. Which of these is not one of the components of change management according to ISC2?

Answer: D. Regression

Change management relies on a structured process to minimize disruptions. The core components include requesting a change, obtaining approval, and having a rollback plan, making regression the correct choice. The distractors represent actual phases or required actions in the standard workflow.

Q4. What does the acronym APT stand for?

Answer: C. Advanced Persistent Threat

An Advanced Persistent Threat refers to a long-term, highly resourced attack. Threat actors use continuous and stealthy techniques to gain unauthorized access to a target network. The other options are fabricated terms designed to test your knowledge of security acronyms.

Q5. Which of the following is an example of collusion?

Answer: B. When two or more individuals collaborate to circumvent segregation of duties for fraudulent purposes

Collusion defeats segregation of duties controls. It happens when multiple people coordinate their efforts to bypass security measures and commit fraud. The remaining options merely describe normal workplace collaboration or shift coverage without any malicious circumvention of controls.

Q6. Which of the following is NOT an ethical canon of the ISC2?

Answer: B. Provide active and diligent service to principals

The ISC2 Code of Ethics canon is to provide diligent and competent service to principals. This option incorrectly states active and qualified service, making it the false choice. The remaining options accurately reflect the mandatory ethical canons.

Q7. What are the six components in the data lifecycle?

Answer: C. Create, Store, Use, Share, Archive, Destroy

The standard data lifecycle components are create, store, use, share, archive, and destroy. The distractors swap in synonyms like delete or save, but ISC2 expects these exact terms.

Q8. In the context of business continuity planning (BCP), which of the following is an effective strategy for mitigating the risk of data loss?

Answer: C. Regular backup of data and systems in multiple dispersed geographical locations

Regular backups stored across multiple dispersed geographic locations directly mitigate data loss from localized disasters or system failures. The distractors represent physical security, awareness, or financial transfers rather than actual data preservation.

Q9. What term describes the activities that must be performed to ensure an incident is properly handled?

Answer: C. Incident Response

Incident response is the structured sequence of activities required to properly handle a security incident from detection through recovery. Incident management is a broader IT service desk concept, and investigation is just one specific phase.

Q10. What does a Privacy Policy typically stipulate?

Answer: B. Which information is considered personally identifiable information (PII)

A privacy policy stipulates how an organization collects, uses, and protects personally identifiable information. Breach notification steps belong in an incident response plan, weakening the other options.

Q11. What is the difference between SFA and MFA?

Answer: B. SFA uses one authentication method, while MFA uses two or more authentication methods

Single factor authentication relies on one method, while multi factor authentication requires two or more distinct factors. The distractors simply reverse the definitions or incorrectly limit the maximum number of allowed factors.

Q12. What is the time frame in which an organization must notify the relevant supervisory authority if it finds a personal data breach that is likely to result in a risk to individuals' rights and freedoms?

Answer: B. Within 72 hours

Under GDPR, organizations must notify the relevant supervisory authority of a qualifying personal data breach within seventy two hours. The other timeframes are incorrect regulatory variations and serve as pure memorization traps.

Q13. What is the difference between a Business Continuity Plan (BCP) and a Disaster Recovery Plan (DRP)?

Answer: B. Business Continuity Plan is about maintaining critical business functions, while Disaster Recovery Plan is about restoring IT and communications back to full operations

A Business Continuity Plan maintains overall critical business functions during a disruption, while a Disaster Recovery Plan specifically focuses on restoring IT and communications to full operation. Remember that BCP keeps the business running, whereas DRP brings the technical systems back online.

Q14. In the event of a disaster, which of the following designates a location to where an organization can relocate and that is fully equipped to resume operations immediately?

Answer: C. Hot site

A hot site is a fully equipped facility that allows an organization to immediately resume operations after a disaster. Warm and cold sites require additional time, equipment, or configuration before operations can safely resume.

Q15. Why is it a best practice to have a documented incident response plan?

Answer: D. To provide a clear and consistent process for handling security incidents and minimizing their impact

A documented incident response plan provides a clear, consistent process for handling security incidents and minimizing their overall impact. The alternative options suggest ignoring incidents or reducing security training, which directly violate foundational security principles.

Q16. In change management, what is the purpose of a rollback plan?

Answer: D. Recovery of the system to the state it was in before the change was made

A rollback plan provides a predefined procedure to restore a system to its previous state if a change causes unexpected failures. This ensures business continuity, unlike options related to testing patches or introducing updates.

Q17. What is the PRIMARY consideration when choosing physical access controls?

Answer: B. Security of the personnel

The primary consideration when selecting physical access controls is always the safety and security of personnel. While protecting equipment, buildings, and networks is important, human life and safety are paramount in security design.

Q18. What is the most critical factor when implementing access controls for a physical site?

Answer: C. The cost of implementing the controls to the value of what is being protected

When implementing physical access controls, the cost of the controls must be proportional to the value of the assets being protected. Security measures should be cost-effective, avoiding excessive spending on low-value items.

Q19. What is a common method for an access control system to authenticate an individual?

Answer: A. Compares the individual's badge against a verified database

Access control systems commonly authenticate individuals by comparing their presented credentials, such as a badge, against a verified database. The remaining options are invalid because access times, clothing, and unrelated biometric comparisons do not provide reliable identity verification.

Q20. In terms of social engineering tactics, what does 'vishing' refer to?

Answer: A. Using a rogue interactive voice response system

Vishing is a social engineering attack that uses voice communication, often through a rogue interactive voice response system, to steal information. The other options describe different concepts like tailgating or general authority impersonation rather than voice-based fraud.

Q21. Which of the following is NOT an example of a cyber attack?

Answer: C. Data breach

A data breach is the resulting compromise of a successful cyber attack, not an attack technique itself. The other options are active methods or actions used by threat actors to compromise systems and facilitate those breaches.

Q22. Mandatory Access Control (MAC) can be defined as:

Answer: A. A policy uniformly enforced across all subjects and objects within the system boundary

Mandatory Access Control enforces a strict security policy uniformly across all subjects and objects within a system boundary using classification labels. The other options describe discretionary control, physical security, or unrestricted access, which contradict the MAC framework.

Q23. How does ransomware typically enter a system?

Answer: A. Automatically installed through phishing emails or by visiting an infected website

Ransomware primarily relies on social engineering to compromise systems. Attackers often deliver malicious payloads through phishing emails or compromised websites. The remaining options fail to represent the most common and realistic infection vectors used by threat actors.

More ISC2 Certified in Cybersecurity (CC) Full Exams '26 drills and other practice exams are on @CertPunch. New rounds drop every few days at certpunch.com.

Scroll to Top