ISC2 Certified in Cybersecurity (CC) Full Exams ’26 Practice Exam Questions and An – Part 22/23

Practice for the ISC2 Certified in Cybersecurity (CC) Full Exams '26 exam with 23 exam-style practice questions, instant answer reveals, and concise explanations of every correct answer. Topics include: What are some examples of physical access controls?. Follow @CertPunch and visit certpunch.com for more certification practice exams and study content.

Prefer hands-on? Take this round as an interactive practice test — answer every question, get instant feedback, and see your score: Start the ISC2 Certified in Cybersecurity (CC) Full Exams '26 practice test →

What you will practice

  • What are some examples of physical access controls?
  • Which of the following statements is TRUE about ransomware?
  • What concept is at the center in the concentric circles model of defense in depth?
  • Which of the following options best describes the concept of Ethernet?
  • At which layer of the OSI model does a firewall NOT control traffic?
  • A junior cybersecurity analyst has detected a ransomware attack on the company's servers and has activated th…

Answers and explanations

Tap a question to expand the answer and the exam reasoning. Try to commit to your own pick first.

Q1. What are some examples of physical access controls?

Answer: D. Fences, locks, security guards, badges, and alarms

Physical access controls include tangible barriers like fences, locks, security guards, badges, and alarms. Firewalls are logical controls, while background checks are administrative controls used to manage personnel security.

Q2. Which of the following statements is TRUE about ransomware?

Answer: C. It encrypts the victim's data and demands payment to decrypt it

Ransomware encrypts a victim's data and demands payment, typically via cryptocurrency, in exchange for a decryption key. The distractors fail because modern ransomware targets any operating system and deploys without explicit user permission.

Q3. What concept is at the center in the concentric circles model of defense in depth?

Answer: D. Assets

The concentric circle model of defense in depth places valuable assets at the very center. Physical, administrative, and technical controls function as the surrounding protective layers, making assets the only correct choice.

Q4. Which of the following options best describes the concept of Ethernet?

Answer: B. A standard that defines wired connections between networked devices

Ethernet is a network standard that defines wired connections between devices on a local area network. Wireless connections fall under different protocols like Wi-Fi, making the wired option the only accurate description.

Q5. At which layer of the OSI model does a firewall NOT control traffic?

Answer: A. Layer 1

Firewalls operate at higher OSI layers to inspect traffic based on logical rules, addresses, or application data. They do not control raw bit streams at the physical layer, making layer one the correct answer.

Q6. A junior cybersecurity analyst has detected a ransomware attack on the company's servers and has activated the incident response team. Which is the next BEST course of action?

Answer: A. Attempt to isolate any compromised servers to prevent further damage

During a ransomware incident, the immediate priority is containment to prevent the threat from spreading. Isolating compromised servers stops further damage, whereas investigating the entry point or restoring systems happens later in the response process.

Q7. Which of the following options best describes the concept of a server?

Answer: A. A computer that provides information to other computers on a network

A server is a computer that manages network resources and provides information to other computers, known as clients. The remaining options describe networking standards or filtering devices like firewalls rather than data-serving hardware.

Q8. What type of access control model is based on user clearance and object classification?

Answer: D. Mandatory access control (MAC)

Mandatory access control grants access based on user security clearance and object classification labels. Rule-based and role-based models rely on system rules or job functions, while discretionary access allows users to set permissions themselves.

Q9. In which of these activities are security posters PRIMARILY used?

Answer: C. Security Awareness

Security posters are administrative controls used primarily in security awareness programs to educate employees and promote a security-conscious culture. They are not typically used for incident response, physical security, or business continuity planning.

Q10. What is a Local Area Network (LAN)?

Answer: A. A network that typically connects a single floor or building

A local area network connects devices within a limited geographic area, such as a single floor or building. A wide area network covers distinct geographic locations, while a point-to-point connection links only two computers directly.

Q11. Which canon of the ISC2 Code of Ethics is specifically designed to prioritize the welfare and trust of the broader public?

Answer: C. Protect society, the common good, necessary public trust and confidence, and the infrastructure

The canon to protect society, the common good, and necessary public trust is the highest priority in the ISC2 Code of Ethics. The other options are lower-priority canons focused on principals, the profession, or individual behavior.

Q12. What best describes the primary objective of a data retention policy?

Answer: D. To specify how long information and assets should be retained

A data retention policy specifies the required lifespan for information and assets. Distractors fail by giving arbitrary timeframes, suggesting indefinite storage, or describing unrelated scope boundaries.

Q13. Which of the following statements is related to Discretionary Access Control (DAC)?

Answer: B. Allows the creator of the object to dictate access

Discretionary Access Control empowers the creator or owner of an object to dictate access permissions. Options describing predefined rules or total administrator control instead define Rule-Based or Mandatory Access Control.

Q14. Why might users be uncomfortable when using biometrics as an authentication method?

Answer: D. They could be considered an invasion of privacy

Biometric authentication can be considered an invasion of privacy because it requires collecting sensitive personal biological data. Claims that biometrics are less secure or easy to bypass are factually incorrect distractors.

Q15. What is the primary category of information specifically regulated by HIPAA?

Answer: A. PHI

The Health Insurance Portability and Accountability Act specifically regulates Protected Health Information, or PHI. PCI and PII represent payment card data and personally identifiable information, which fall under different regulatory frameworks.

Q16. Which of the following is a technique used to protect the confidentiality of data?

Answer: A. Encryption

Encryption protects data confidentiality by converting information into a format readable only by authorized parties. However, tokenization is also a valid confidentiality technique, making this question technically ambiguous. Hashing provides integrity, while digital signatures provide non-repudiation.

Q17. What are the three main concepts of access control?

Answer: A. Objects, Rules, Subjects

Core access control concepts are subjects, which request access; objects, which are the protected resources; and rules, which define permissions. Confidentiality, integrity, and availability represent the broader security triad, serving as a trap for test-takers looking for familiar acronyms.

Q18. What is ensured by an information security policy? (★)

Answer: D. The commitment of senior management to ensure that access to data is secure

An information security policy formally establishes senior management's commitment to protecting organizational data and outlines security expectations. While it communicates overall security posture, specific issues like social media usage or financial backups belong in separate, more targeted policies.

Q19. What is the difference between risk mitigation and risk acceptance?

Answer: D. Risk mitigation is the process of diminishing a risk, while risk acceptance is the process of accepting a risk

Risk mitigation is the process of diminishing or reducing a risk, while risk acceptance is a conscious decision to accept it without taking immediate action. Eliminate options that confuse these concepts with risk transfer, such as buying insurance, or risk elimination.

Q20. What are the 'known' ports?

Answer: B. Ports 0 – 1023

Known ports, also called well-known ports, range from 0 to 1023 and are assigned to system-level processes like web traffic. Remember that ports 1024 to 49151 are registered ports, while 49152 to 65535 are dynamic ports.

Q21. What is the consequence of failing to adhere to the ISC2 Code of Ethics?

Answer: A. Revocation of certification

Failure to adhere to the ISC2 Code of Ethics can result in severe consequences, including the revocation of your certification. While suspension or loss of membership might occur depending on the specific ethical breach, the most definitive and severe consequence is total revocation.

Q22. A company wants to process customer email addresses for direct marketing based on legitimate interest. What is assessed in the first step of a Legitimate Interest Assessment (LIA)?

Answer: D. Whether the processing activity supports a clearly defined business purpose

The first step in a Legitimate Interest Assessment is the purpose test, which ensures the processing supports a clearly defined business goal. The other choices are incorrect because explicit permission relates to consent, while internal policies and premium services do not establish this lawful basis.

Q23. Which of the following BEST describes a security solution that enforces policies on devices attempting to access network resources?

Answer: A. Network access control

Network Access Control enforces security policies on devices before granting them access to network resources. The remaining options are incorrect because they manage user passwords, access times, or locations rather than verifying the actual health or compliance of the connecting device.

More ISC2 Certified in Cybersecurity (CC) Full Exams '26 drills and other practice exams are on @CertPunch. New rounds drop every few days at certpunch.com.

Scroll to Top