ISC2 Certified in Cybersecurity (CC) Full Exams ’26 Practice Exam Questions and An – Part 19/19

Practice for the ISC2 Certified in Cybersecurity (CC) Full Exams '26 exam with 23 exam-style practice questions, instant answer reveals, and concise explanations of every correct answer. Topics include: For a rack in a data center, how many temperature sensors are recommended?. Follow @CertPunch and visit certpunch.com for more certification practice exams and study content.

Prefer hands-on? Take this round as an interactive practice test — answer every question, get instant feedback, and see your score: Start the ISC2 Certified in Cybersecurity (CC) Full Exams '26 practice test →

What you will practice

  • For a rack in a data center, how many temperature sensors are recommended?
  • When implementing authentication, which of the following is considered a best practice?
  • What is the first activity in the change management process?
  • What is the main difference between risk avoidance and risk transference?
  • What is a definition for cloud computing?
  • What role does a hub play in a network?

Answers and explanations

Tap a question to expand the answer and the exam reasoning. Try to commit to your own pick first.

Q1. For a rack in a data center, how many temperature sensors are recommended?

Answer: B. Three

Data center racks should have three temperature sensors placed at the top, middle, and bottom. This arrangement accurately monitors airflow and identifies hot spots. Fewer sensors miss temperature variations, and more add unnecessary cost.

Q2. When implementing authentication, which of the following is considered a best practice?

Answer: D. Use two or more authentication methods, such as password, biometrics, and a pin code

The best practice for implementing authentication is to use multi-factor authentication by combining two or more independent factors. A username represents identification, not authentication, so options relying solely on a username and password fail to meet the multi-factor requirement.

Q3. What is the first activity in the change management process?

Answer: C. Request for change

The change management process begins with a formal request for change to identify the desired modification. Activities like approval, implementation, and rollback happen later in the lifecycle after the request is submitted and reviewed.

Q4. What is the main difference between risk avoidance and risk transference?

Answer: C. Risk avoidance is the process of withdrawing from a risk scenario, while risk transference is the process of transferring risk to another party

Risk avoidance means withdrawing from a risk scenario entirely, while risk transference shifts the risk burden to another party. Options that mix definitions or introduce mitigation are incorrect.

Q5. What is a definition for cloud computing?

Answer: A. A set of computing resources sold as a service

Cloud computing delivers computing resources like storage and processing as a service over the internet. Defining it as a physical product or limiting it to data storage or analysis are incorrect constraints.

Q6. What role does a hub play in a network?

Answer: B. Connect multiple devices on a network

A network hub connects multiple devices by acting as a central connection point. Hubs operate at the physical layer and lack intelligence, so they cannot filter traffic or control network flow like switches or routers.

Q7. The term "defense in depth" refers to:

Answer: B. A strategy that uses multiple security measures to protect an organization's systems

Defense in depth is a strategy that uses multiple security measures to protect an organization's information. The trap here is picking options that suggest using only one barrier or only technical measures, which completely miss the core concept of layering administrative, technical, and physical controls.

Q8. Which method involves writing multiple patterns across all storage media?

Answer: C. Overwriting

Overwriting involves writing multiple patterns across all storage media to ensure the original data cannot be recovered. The trap here is confusing this with deleting, which only removes the reference to the data, or purging and destroying, which use different methods.

Q9. What is the PRIMARY goal of enforcing defense in depth?

Answer: D. Prevent or deter a cyberattack using multiple layers of security measures

The primary goal of defense in depth is to prevent or deter cyberattacks using multiple layers of security measures. Beware of any option claiming a network can be made impenetrable or guaranteeing zero attacks, as absolute security is impossible.

Q10. What is the PRIMARY difference between DAC and MAC?

Answer: C. The person who controls access (object owner in DAC, security administrators in MAC)

The primary difference is who controls access. In Discretionary Access Control, the object owner decides, whereas in Mandatory Access Control, a security administrator enforces strict policies based on clearance levels.

Q11. What does configuration management guarantee?

Answer: A. That all changes made to a system are authorized and validated

Configuration management guarantees that all changes made to a system are formally authorized and validated before implementation. This ensures system stability, tracks modifications, and prevents unauthorized or untested updates from introducing new vulnerabilities into the environment.

Q12. Data remanence is known as:

Answer: A. Data that is left on media after deleting

Data remanence refers to the residual data left on storage media after standard deletion methods are used. Because deletion typically just marks space as available, the original data remains and can often be recovered until it is properly overwritten or the media is physically destroyed.

Q13. Members of a data protection team in an organization are typically NOT required to:

Answer: A. … Interpret global privacy laws

Data protection teams are not typically required to interpret global privacy laws unless the organization operates internationally. They must, however, ensure protective measures are in place and meet local legislative requirements for data collection.

Q14. Access controls are…

Answer: A. …mechanisms that grant appropriate access levels to authorized personnel and deny access to unauthorized ones

Access control mechanisms are designed to grant appropriate access to authorized users while explicitly denying access to unauthorized individuals. Providing the highest access level to everyone violates least privilege, and securing data integrity is only one aspect of their function.

Q15. In the incident response process, who is NOT typically involved in forensic investigations?

Answer: D. Sales Personnel

Sales personnel lack the technical expertise required for forensic investigations and are not typically involved in incident response. Cybersecurity analysts, network architects, and even receptionists providing physical logs can offer relevant investigative support.

Q16. Why do organizations classify their information?

Answer: C. To restrict the access to the information

Organizations classify information primarily to restrict access based on sensitivity and need-to-know principles. While searching and access speed are useful, they are not security drivers, and classification cannot stop ransomware directly.

Q17. In the context of incident response, the term that refers to the collection and preservation of an incident is:

Answer: A. Evidence Collection

Evidence collection is the process of properly gathering and preserving data from a cybersecurity incident. Forensics analysis involves examining that evidence, while the other terms are fabricated distractors.

Q18. What is the common mistake in records retention?

Answer: A. Applying the longest retention period to all types of information

A common records retention mistake is applying the longest retention period to all types of information. This increases storage costs and creates unnecessary legal risks if the data is subpoenaed. The other options describe practices that are either generally acceptable or not realistic business scenarios.

Q19. What does a 'low sensitivity' label on data mean?

Answer: A. Data compromise could cause minor disruption

A low sensitivity label means that compromising the data could cause a minor disruption. Data causing significant loss of life or loss of competitive advantage would be classified much higher, while data causing no harm might not need classification at all.

Q20. In a data center, what is NOT a typical issue related to airflow?

Answer: D. Noise

In data centers, noise is an environmental issue but is not directly tied to airflow management. Issues like cooling, dust, and noxious fumes are all direct results of how air is circulated, filtered, and managed in the facility.

Q21. What is Role-Based Access Control (RBAC)?

Answer: A. An access control based on user permissions set according to roles

Role-Based Access Control assigns permissions to specific roles rather than individual users. Users then inherit permissions by being assigned to those roles. While roles often align with job descriptions, the access control is strictly based on the defined role permissions, not the descriptions themselves.

Q22. What does the label 'unrestricted public data' mean?

Answer: B. Data compromise result in no harm

Unrestricted public data implies that compromising the data would result in no harm because it is already freely available. Data causing loss of life, competitive advantage, or disruption carries higher classification levels.

Q23. What are cloud-based resources?

Answer: B. Any resources that an organization accesses using cloud computing

Cloud-based resources are any computing resources that an organization accesses over the internet using cloud computing models. This includes storage, applications, and virtual machines. Accessing local physical servers or personal computers does not inherently mean using cloud resources.

More ISC2 Certified in Cybersecurity (CC) Full Exams '26 drills and other practice exams are on @CertPunch. New rounds drop every few days at certpunch.com.

Scroll to Top