ISC2 Certified in Cybersecurity (CC) Full Exams ’26 Practice Exam Questions and An – Part 17/19

Practice for the ISC2 Certified in Cybersecurity (CC) Full Exams '26 exam with 23 exam-style practice questions, instant answer reveals, and concise explanations of every correct answer. Topics include: Which of the following is a law with multinational implications?. Follow @CertPunch and visit certpunch.com for more certification practice exams and study content.

Prefer hands-on? Take this round as an interactive practice test — answer every question, get instant feedback, and see your score: Start the ISC2 Certified in Cybersecurity (CC) Full Exams '26 practice test →

What you will practice

  • Which of the following is a law with multinational implications?
  • Which of the following is NOT a common indicator for side-channel attack?
  • Which of the following is NOT a common component of a comprehensive Business Continuity Plan (BCP)?
  • Which of the following is NOT commonly included in an Acceptable Use Policy (AUP)?
  • How many classifications are typically considered difficult to manage for an organization?
  • An organization plans to deploy new surveillance technology that systematically monitors individuals in publi…

Answers and explanations

Tap a question to expand the answer and the exam reasoning. Try to commit to your own pick first.

Q1. Which of the following is a law with multinational implications?

Answer: D. GDPR

The General Data Protection Regulation is a law with significant multinational implications. It affects any organization handling the personal data of individuals within the European Union. The other options are globally recognized standards or frameworks rather than enforceable laws.

Q2. Which of the following is NOT a common indicator for side-channel attack?

Answer: D. Packet analysis

Side-channel attacks gather information from the physical implementation of a system. Attackers exploit timing, power consumption, or fault analysis rather than standard network data. Packet analysis is a network diagnostic tool and not a characteristic indicator of physical system compromise.

Q3. Which of the following is NOT a common component of a comprehensive Business Continuity Plan (BCP)?

Answer: B. Employee well-being programs

Business continuity plans prioritize operational resilience and emergency response procedures, making employee well-being programs out of scope. The distractors are core elements because they address communication and operational recovery during a crisis.

Q4. Which of the following is NOT commonly included in an Acceptable Use Policy (AUP)?

Answer: D. Access to physical premisses

Acceptable use policies govern digital resources like networks, systems, and data, rather than physical building access. Facilities access is managed by physical security controls and policies, making it the clear outlier here.

Q5. How many classifications are typically considered difficult to manage for an organization?

Answer: D. More than four

Maintaining more than four data classification tiers becomes administratively difficult and resource intensive. Lower tier counts offer adequate protection without overwhelming administrative overhead, making this the threshold.

Q6. An organization plans to deploy new surveillance technology that systematically monitors individuals in public areas. Is a Data Protection Impact Assessment (DPIA) required?

Answer: A. Yes, because it poses a risk to individuals' rights and freedoms

A Data Protection Impact Assessment is required when processing poses a high risk to individuals rights and freedoms, such as public surveillance. Public collection and privacy policies do not waive this requirement, and the assessment must happen before deployment to be effective.

Q7. What is the purpose of awareness training?

Answer: B. Ensure everyone knows what is expected of them

Awareness training ensures everyone understands security expectations and their role in protecting the organization. Testing technologies or providing breaks are not the educational goals of a security awareness program.

Q8. In the cybersecurity landscape, what is the definition of a 'bug'?

Answer: A. A flaw causing an application to produce an unintended or unexpected result that may be exploitable

A bug is a flaw causing an application to produce an incorrect or unexpected result that may be exploitable. A bug creates a vulnerability, but the terms are not interchangeable, and a risk is a potential negative event.

Q9. What is the recommended temperature range for optimized data center uptime and hardware life?

Answer: D. 64°F to 81°F (18°C to 27°C)

The recommended temperature range for a data center is 64 to 81 degrees Fahrenheit, or 18 to 27 degrees Celsius. Maintaining this specific range optimizes hardware lifespan while preventing failures caused by overheating or excessive cooling.

Q10. What is the term used to describe the combination of the likelihood of a threat and the potential impact of the threat?

Answer: C. Risk

Risk is the combination of likelihood and impact when a threat exploits a vulnerability. A breach is an event, a zero-day is a specific unknown vulnerability, and a vulnerability is merely a weakness.

Q11. What does SaaS offer consumers?

Answer: B. Access to software applications

Software as a Service provides consumers with access to software applications over the internet. Hardware, network, and security components belong to infrastructure, network, and security as a service models.

Q12. Which device determines the most efficient route for traffic flow on a network?

Answer: C. Router

A router determines the most efficient path for traffic based on network topology and IP addresses. Switches use MAC addresses, firewalls filter traffic, and hubs simply broadcast to all ports.

Q13. What is the PRIMARY objective of access control?

Answer: C. Grant the appropriate level of access to authorized personnel and processes

Access control primarily ensures that authorized personnel and processes receive the appropriate access levels. Options A, B, and D act as distractors by describing secondary effects or focusing only on insiders or outsiders.

Q14. Non-repudiation is …:

Answer: D. … the protection against an individual falsely denying having performed a particular action

Non-repudiation proves that a specific individual performed an action, preventing them from falsely denying it. Privacy rights and general security measures act as distractors, while non-repudiation is a principle, not a law.

Q15. What is the definition of a 'risk'?

Answer: D. A possible event that can negatively impact the organization

Risk is defined as a possible event that negatively impacts an organization. The other options define core risk components like threat actors, vulnerabilities, and exploits, but do not represent the overall concept of risk.

Q16. What type of malware disguises itself as benign software but carries a malicious payload?

Answer: B. Trojan

A Trojan disguises itself as legitimate software to trick users into executing its malicious payload. Worms self-replicate, viruses attach to files, and spyware collects data covertly without relying on deceptive disguises.

Q17. What should be the PRIMARY consideration when deciding whether to install biometric scanners on all of the organization's doors or only some of them?

Answer: D. The results of a site assessment

A site assessment provides the primary data needed to determine where security controls are required. Evaluating the work area is important, but a comprehensive assessment considers all physical and operational risks.

Q18. Who controls access in a Mandatory Access Control (MAC) system?

Answer: A. Only properly designated security administrators

In Mandatory Access Control, designated security administrators strictly control access using classification labels. Standard users and executives cannot alter these permissions, distinguishing MAC from discretionary models.

Q19. What does a well-designed security policy aim to achieve?

Answer: D. Reduce the potential of security breaches to an acceptable level

The primary goal of a well-designed security policy is to reduce the potential of security breaches to an acceptable level. Security is never about absolute guarantees, so any option implying zero risk is a trap on the exam.

Q20. Which of the following options BEST describes the concept of a network?

Answer: D. A group of computers sharing data, information or resources

A network is fundamentally a group of computers that share data, information, or resources. Any option describing a single machine or a group of disconnected computers acts as a distractor because connectivity and resource sharing are the defining characteristics.

Q21. Which of the following is TRUE about Denial of Service (DoS)?

Answer: A. It is a type of attack used to disrupt normal operations

A Denial of Service or DoS attack is specifically designed to disrupt normal operations by making a system unavailable. Options mentioning bypassing authentication or gaining system access describe entirely different attack vectors, such as spoofing or unauthorized access.

More ISC2 Certified in Cybersecurity (CC) Full Exams '26 drills and other practice exams are on @CertPunch. New rounds drop every few days at certpunch.com.

Scroll to Top