ISC2 Certified in Cybersecurity (CC) Full Exams ’26 Practice Exam Questions and Answ – Part 2/5

Practice for the ISC2 Certified in Cybersecurity (CC) Full Exams '26 exam with 20 exam-style practice questions, instant answer reveals, and concise explanations of every correct answer. Topics include: Which type of key can be used to both encrypt and decrypt the same message?. Follow @CertPunch and visit certpunch.com for more certification practice exams and study content.

Prefer hands-on? Take this round as an interactive practice test — answer every question, get instant feedback, and see your score: Start the ISC2 Certified in Cybersecurity (CC) Full Exams '26 practice test →

What you will practice

  • Which type of key can be used to both encrypt and decrypt the same message?
  • A security safeguard is the same as a:
  • What is the consequence of a Denial of Service attack?
  • Which devices have the PRIMARY objective of collecting and analyzing security events?
  • The implementation of Security Controls is a form of:
  • Which cloud model gives the customer the least responsibility over the infrastructure?

Answers and explanations

Tap a question to expand the answer and the exam reasoning. Try to commit to your own pick first.

Q1. Which type of key can be used to both encrypt and decrypt the same message?

Answer: A. A symmetric key

Symmetric encryption uses a single shared secret key for both encrypting and decrypting data. This method is fast and efficient for bulk data. Asymmetric cryptography, by contrast, uses a matched public and private key pair where one key encrypts and the other decrypts.

Q2. A security safeguard is the same as a:

Answer: B. Security control

A security safeguard is synonymous with a security control, acting as a measure to manage risk by protecting system resources. Controls can be administrative, technical, or physical. The other terms describe different concepts and do not accurately define a safeguard.

Q3. What is the consequence of a Denial of Service attack?

Answer: B. Exhaustion of device resources

A denial of service attack overwhelms a target system with malicious traffic, causing exhaustion of its computational resources. This renders the service unavailable to legitimate users. The primary goal is operational disruption, not unauthorized remote control or malware deployment.

Q4. Which devices have the PRIMARY objective of collecting and analyzing security events?

Answer: B. SIEM

A Security Information and Event Management system is designed specifically to collect, aggregate, and analyze security events from across the network. Firewalls and routers handle traffic filtering and routing, while hubs act as basic signal repeaters without analytical capabilities.

Q5. The implementation of Security Controls is a form of:

Answer: C. Risk reduction

Implementing security controls is a form of risk reduction, also known as risk mitigation. The other options represent different risk responses, such as avoiding the activity, accepting the potential loss, or transferring the risk to a third party through insurance.

Q6. Which cloud model gives the customer the least responsibility over the infrastructure?

Answer: C. SaaS

Software as a Service gives the customer the least responsibility over the infrastructure because the provider manages everything from servers to the application. Infrastructure as a Service requires the customer to manage the operating systems and applications, leaving more infrastructure responsibility.

Q7. Which type of attack embeds malicious payload inside a reputable or trusted software?

Answer: A. Trojans

A Trojan horse embeds malicious payload inside a reputable or trusted software to evade security mechanisms. A rootkit maintains privileged access while concealing malicious activity, whereas phishing and cross-site scripting target users and web applications rather than hiding inside trusted software.

Q8. Which of the following is NOT a protocol of the OSI Level 3?

Answer: D. SNMP

Simple Network Management Protocol is an application layer protocol, which corresponds to level seven of the OSI model, not level three. IP, ICMP, and IGMP all operate at the network layer, making them incorrect answers when looking for a non-level three protocol.

Q9. Which of the following is a public IP?

Answer: B. 13.16.123.1

A public IP address must be routable on the open internet, and the thirteen dot sixteen dot one hundred twenty-three dot one address fits this requirement. The remaining options fall under private address ranges reserved for internal local area networks, such as ten dot zero dot zero dot zero.

Q10. In which of the following access control models can the creator of an object delegate permission?

Answer: D. DAC

Discretionary Access Control allows the creator or owner of an object to delegate permissions to other users. Mandatory access control enforces strict rules set by a central authority, while role-based and attribute-based models rely on assigned roles or policies.

Q11. An exploitable weakness or flaw in a system or component is a:

Answer: A. Vulnerability

A vulnerability is an exploitable weakness or flaw in a system or component that a threat source could leverage. A threat is the potential danger, risk is the potential for loss, and a bug is simply a software flaw that does not always create a security issue.

Q12. The process of verifying or proving the user's identification is known as:

Answer: B. Authentication

Authentication is the process of verifying or proving a user's identification before granting access to a system. Authorization determines what specific resources the verified user can access, while confidentiality and integrity are core security principles.

Q13. Which device is used to connect a LAN to the Internet?

Answer: C. Router

A router is the network device specifically used to connect a local area network to the Internet by directing data packets between networks. Firewalls filter traffic for security, intrusion detection systems monitor for threats, and SIEM analyzes security alerts.

Q14. Malicious emails that aim to attack company executives are an example of:

Answer: D. Whaling

Whaling is a specific type of phishing attack that explicitly targets high-ranking executives. Phishing targets general users, while Trojans and rootkits refer to malicious software rather than social engineering techniques.

Q15. Which of the following principles aims primarily at fraud detection?

Answer: B. Separation of Duties

Separation of Duties ensures that critical tasks require multiple individuals, preventing one person from committing and concealing fraud. This shared responsibility serves as a direct fraud detection mechanism, unlike least privilege or defense in depth.

Q16. Which port is used to secure communication over the web (HTTPS)?

Answer: D. 443

Port 443 is used for HTTPS to ensure encrypted web traffic. Port 80 is unencrypted HTTP, while ports 69 and 25 are reserved for TFTP and SMTP respectively.

Q17. According to ISC2, which are the six phases of data handling?

Answer: B. Create → Store → Use → Share → Archive → Destroy

According to ISC2, the six phases of the data lifecycle are create, store, use, share, archive, and destroy. Memorizing this exact order is crucial for the exam.

Q18. Which of the following cloud models allows access to fundamental computer resources?

Answer: A. Impact

Impact is defined as the magnitude of harm expected from unauthorized disclosure or loss of information. Likelihood measures probability, while vulnerabilities are weaknesses and threats are potential adverse events.

Q19. Which are the three packets used on the TCP connection handshake? (★)

Answer: D. SYN → SYN/ACK → ACK

TCP uses a three-way handshake to establish a reliable connection by exchanging three packets with the SYN, SYN/ACK and ACK flags. Although SYN, ACK and FIN are valid TCP packet flags, the sequence SYN → ACK → FIN is not the TCP handshake. Both the sequences Discover → Offer → Request and Offer → Request → ACK are used in DHCP.

Q20. The cloud deployment model where a company has resources on-premises and in the cloud is known as:

Answer: A. Hybrid cloud

A hybrid cloud combines on-premises infrastructure, private cloud services, and a public cloud to handle storage and services. Community clouds involve shared resources among organizations with common goals, while multi-tenancy refers to customers sharing computing resources.

More ISC2 Certified in Cybersecurity (CC) Full Exams '26 drills and other practice exams are on @CertPunch. New rounds drop every few days at certpunch.com.

Scroll to Top