ISC2 Certified in Cybersecurity (CC) Full Exams ’26 Practice Exam Questions and An – Part 18/19

Practice for the ISC2 Certified in Cybersecurity (CC) Full Exams '26 exam with 23 exam-style practice questions, instant answer reveals, and concise explanations of every correct answer. Topics include: Who dictates the access control rules in Discretionary Access Control (DAC)?. Follow @CertPunch and visit certpunch.com for more certification practice exams and study content.

Prefer hands-on? Take this round as an interactive practice test — answer every question, get instant feedback, and see your score: Start the ISC2 Certified in Cybersecurity (CC) Full Exams '26 practice test →

What you will practice

  • Who dictates the access control rules in Discretionary Access Control (DAC)?
  • What is the concept of redundancy in system design?
  • A company accuses a certified employee of intellectual property theft and demands ISC2 revoke their certifica…
  • In the context of change management, what is a security baseline?
  • In a network environment, which of the following is an example of a security control?
  • Which of the following options describes a possible enrollment process in a high-security environment?

Answers and explanations

Tap a question to expand the answer and the exam reasoning. Try to commit to your own pick first.

Q1. Who dictates the access control rules in Discretionary Access Control (DAC)?

Answer: D. The subject who created the object

Discretionary Access Control allows the subject who created the object, or the owner, to dictate access control rules. The owner has the discretion to decide who gets access. This differs from mandatory access control, where a central authority enforces strict rules.

Q2. What is the concept of redundancy in system design?

Answer: C. Duplicate components as a backup in case of failure

Redundancy in system design involves including duplicate components as a backup to ensure continued operation if a primary component fails. The goal is maintaining availability and preventing downtime, rather than using diverse suppliers or saving costs by reducing parts.

Q3. A company accuses a certified employee of intellectual property theft and demands ISC2 revoke their certification immediately. The company provides internal logs as evidence but has not yet pursued criminal charges or a civil lawsuit again…

Answer: D. They proceed only after a competent court or authority has made a factual determination

ISC2 relies on the findings of a competent legal or regulatory authority before taking disciplinary action for alleged illegal acts. This ensures due process, because ISC2 is not a law enforcement agency and lacks the mandate to conduct forensic investigations or act on unproven accusations.

Q4. In the context of change management, what is a security baseline?

Answer: A. A minimum level of protection that can be used as a reference point

A security baseline is a minimum level of protection used as a reference point. Any system changes should not reduce security below this baseline, making maximum protection and validation processes distractors.

Q5. In a network environment, which of the following is an example of a security control?

Answer: B. A firewall

A firewall is a preventative network security control that actively monitors and filters traffic. Access logs and user credentials are not controls themselves, but rather configuration elements or records used for identification and monitoring.

Q6. Which of the following options describes a possible enrollment process in a high-security environment?

Answer: A. Issuing a badge with the employee's credentials, possibly including biometrics

High-security enrollment often involves issuing a badge embedded with credentials and biometric data. This ensures accurate authentication, whereas letting users choose identifiers or collecting irrelevant religious history weakens security and violates privacy.

Q7. Physical access controls are employed to:

Answer: A. Protect the assets of a company, including its personnel

Physical access controls are primarily designed to protect company assets and personnel by preventing unauthorized entry. While they may track movement, features like easy entry or open facility access defeat their core security purpose.

Q8. What is the typical response when someone is detected trying to access a database without permission?

Answer: A. The attempt is logged, and the user is blocked

Standard security practice dictates that unauthorized access attempts should be logged and blocked immediately to prevent potential data breaches. Issuing warnings or deleting accounts are not typical automated responses, and promoting access violates the principle of least privilege.

Q9. What is an endpoint in a network?

Answer: B. The ends of a network communications link

An endpoint refers to the ends of a network communication link, typically representing devices like clients and servers. The other choices referencing beginnings or centers do not accurately reflect networking terminology.

Q10. Which of the following is NOT a type of attack used to gain access to an organization's network?

Answer: A. Denial of Service

A Denial of Service attack is designed to disrupt network availability by overwhelming it with traffic, not to gain unauthorized access. Brute force, password spraying, and rainbow tables are all credential-based attacks meant to bypass authentication.

Q11. Which of the following is NOT a category of the incident response process?

Answer: C. Retention

The standard phases of incident response include preparation, detection, containment, and recovery. Retention is a data management concept and does not belong to the active incident response lifecycle.

Q12. What is one of the challenges presented by a Bring Your Own Device (BYOD) policy?

Answer: D. Ensuring that the device is configured securely

A major challenge of BYOD policies is ensuring that employee-owned personal devices are securely configured to protect corporate data. The organization lacks direct control over these endpoints, unlike company-issued hardware.

Q13. Which of the following is an example of an invasion of privacy?

Answer: D. A doctor discussing patient information without consent

Invasion of privacy involves the unauthorized access or disclosure of personal information, making a doctor sharing patient data without consent the correct choice. The other options involve public information or general corporate access that lack the specific targeting of personal privacy.

Q14. What is the European Union's General Data Protection Regulation (GDPR)?

Answer: D. A regulation that applies to all organizations, foreign or domestic, doing business in the EU or any persons in the EU

The General Data Protection Regulation establishes strict rules for handling personal data. It famously applies to any organization processing the data of European Union residents, regardless of where the business operates. The remaining options are either too narrow or incorrectly describe legal relationships.

Q15. Which of the following is an example of a standard?

Answer: A. ISO 27001

Standards provide mandatory rules and frameworks to ensure consistent security implementation. ISO 27001 is a recognized international standard for information security management systems. The other choices represent internal documents or broader legal regulations rather than formal standards.

Q16. What is the PRIMARY purpose of the ISC2 Code of Ethics?

Answer: D. To ensure members adhere to the highest standards of ethical conduct

The ISC2 Code of Ethics mandates that certified professionals uphold the highest standards of ethical conduct. While protecting the public and advancing the profession are mandatory ethical canons, the primary purpose is enforcing a strict code of professional behavior.

Q17. The Bell-LaPadula model has a PRIMARY goal to:

Answer: A. Prevent the unauthorized sharing of classified information

The Bell-LaPadula model primarily prevents unauthorized disclosure of classified information using strict read and write rules. It is a confidentiality model, so malware protection or encryption are distractors.

Q18. What is the PRIMARY purpose of a Business Continuity Plan (BCP)?

Answer: A. Preserve business operations while recovering from a significant disruption

A Business Continuity Plan aims to maintain critical business operations during and after a significant disruption. Providing alternate workspaces or ensuring data security are supporting tasks, not the primary objective of the overall plan.

Q19. To protect sensitive information, when is sanitization or destruction required?

Answer: D. When elements of the system are to be removed and replaced

Sanitization or destruction of sensitive information is required when system elements like hard drives are removed and replaced. This prevents data recovery during hardware disposal. Upgrades or adding data require proper handling, not destruction.

Q20. What is the purpose of non-repudiation?

Answer: C. Ensure people are held responsible for transactions they conducted

Non-repudiation ensures individuals cannot deny their actions, holding them accountable for transactions they conducted. Options involving privacy data or regulations address compliance and confidentiality rather than proving an action originated from a specific user.

Q21. Which is NOT an example of biometric data?

Answer: A. Credit history identifiers

Biometrics measure unique physical or behavioral traits like fingerprints, retinal patterns, and keystroke dynamics. Credit history is a financial record, not a measurable biological characteristic, making it the correct non-biometric choice.

Q22. A vulnerability is:

Answer: C. …an exploitable weakness or flaw in a system or component

A vulnerability is an exploitable weakness or flaw in a system or component. A threat actor uses an exploit to take advantage of this weakness, whereas a risk is the potential for negative impact.

More ISC2 Certified in Cybersecurity (CC) Full Exams '26 drills and other practice exams are on @CertPunch. New rounds drop every few days at certpunch.com.

Scroll to Top