Practice for the ISC2 Certified in Cybersecurity (CC) Full Exams '26 exam with 23 exam-style practice questions, instant answer reveals, and concise explanations of every correct answer. Topics include: Which of the following cloud models requires the LEAST administration and support from the organization?. Follow @CertPunch and visit certpunch.com for more certification practice exams and study content.
Prefer hands-on? Take this round as an interactive practice test — answer every question, get instant feedback, and see your score: Start the ISC2 Certified in Cybersecurity (CC) Full Exams '26 practice test →
What you will practice
- Which of the following cloud models requires the LEAST administration and support from the organization?
- What is the difference between 'implicit deny' and 'explicit deny' in access control?
- Which of the following can be considered Personally Identifiable Information (PII)?
- What is the definition of availability in the CIA triad?
- What information can be obtained by using the 'ping' command?
- In a data center, what do backup generators need to be sized for?
Answers and explanations
Tap a question to expand the answer and the exam reasoning. Try to commit to your own pick first.
Q1. Which of the following cloud models requires the LEAST administration and support from the organization?
Answer: C. Software as a Service (SaaS)
Software as a Service requires the least administration because the cloud provider manages the underlying infrastructure, operating systems, and applications. The other models leave the customer responsible for managing operating systems, applications, or network configurations.
Q2. What is the difference between 'implicit deny' and 'explicit deny' in access control?
Answer: B. 'Implicit deny' means that access is denied unless specifically granted, while 'explicit deny' means that access is specifically denied
Implicit deny means access is denied by default unless specifically granted, while explicit deny directly blocks a user regardless of other permissions. The remaining options are incorrect because they incorrectly attribute these controls to administrators or system events.
Q3. Which of the following can be considered Personally Identifiable Information (PII)?
Answer: B. Any data about an individual that could be used to direct or indirect identify them
Personally Identifiable Information is any data that can be used directly or indirectly to identify an individual. The distractors fail because they describe intellectual property, anonymized statistics, or general sensitive data rather than specific identifying information.
Q4. What is the definition of availability in the CIA triad?
Answer: B. Timely and reliable access to information and the ability to use it
Availability ensures timely and reliable access to information and the ability to use it when needed. The other choices are incorrect because they focus on unrelated aspects like information services, making data available to others, or location independence.
Q5. What information can be obtained by using the 'ping' command?
Answer: D. The online status of the remote system
The ping command tests the availability of a remote host by sending ICMP echo requests. Avoid options like file transfer speed or network routing, as those require tools like FTP or traceroute.
Q6. In a data center, what do backup generators need to be sized for?
Answer: B. The critical load and supporting infrastructure
Backup generators must be sized to handle the critical load and supporting infrastructure during a power outage. The critical load includes essential servers, while infrastructure includes cooling and power distribution.
Q7. The latest anti-malware solutions have expanded their detection capabilities to include more than just viruses. Which of the following is NOT typically detected by modern anti-malware?
Answer: C. APT
Modern anti-malware solutions are designed to detect common malicious software like ransomware, spyware, and rootkits. Advanced Persistent Threats involve stealthy, long-term operations by skilled adversaries, making them difficult for standard anti-malware to detect.
Q8. Which method prevents information from being recovered even in a laboratory environment?
Answer: B. Purging
Purging removes information from storage media so that it cannot be reconstructed by any known technique, including advanced laboratory methods. Clearing only prevents casual recovery, while overwriting might leave remnants that sophisticated tools could retrieve.
Q9. In change management, what is the meaning of baseline identification?
Answer: D. Identifying the system and all its components, interfaces, and documentation
Baseline identification in change management refers to comprehensively identifying and documenting the current state of a system, including its components and interfaces. This baseline serves as a reference point to evaluate the impact of proposed changes.
Q10. Why do many organizations find it challenging to maintain a separate test environment?
Answer: A. Because it presents logistical challenges
Maintaining a separate testing environment presents logistical challenges because it requires additional hardware, software, and personnel. It also demands careful coordination to ensure the test environment accurately mirrors the production environment.
Q11. What is one requirement of PCI DSS regarding credit card data?
Answer: C. Credit card data should be classified as confidential and encrypted
The Payment Card Industry Data Security Standard requires credit card data to be classified as confidential and encrypted during storage and transmission. Other options are beneficial security practices but are not explicit baseline requirements of the standard.
Q12. In unified cloud storage, which solution can be used to separate access to patient records from administrative data without moving servers into different networks?
Answer: B. VLAN segmentation
Virtual Local Area Network segmentation separates network traffic without changing the physical layout of the network. A screened subnet provides an additional layer of security with firewalls but does not specifically separate data types within the same network.
Q13. Which type of fire suppression system is better for electronics but can be toxic to humans?
Answer: D. Gas-based
Gas-based fire suppression systems are designed to suppress fires without damaging electronic equipment, making them ideal for data centers. However, the gases used can be harmful to humans, requiring immediate evacuation upon system activation.
Q14. Which of the following can be considered an administrative control in a data center?
Answer: B. A policy, defining the rules that assign access to authorized individuals
Administrative controls consist of the policies and procedures that govern human behavior. The other options are incorrect because they represent physical controls or technical controls.
Q15. Which of the following would help an organization secure its network-critical server that is about to experience a power outage?
Answer: B. Install redundant power supplies
Installing redundant power supplies directly maintains server functionality during a power outage. The other options are incorrect because they do not provide an immediate physical solution to keep the server running.
Q16. What are three common methods of authentication?
Answer: C. Passwords, Tokens, and Biometrics
The three common factors of authentication are something you know, something you have, and something you are. These are best represented by passwords, tokens, and biometrics. The other options list specific sub-types like memory cards rather than the broad categories.
Q17. What is the purpose of risk assessment?
Answer: B. Identify and prioritize risks
Risk assessment primarily identifies and prioritizes risks to an organization. Eradicating all risk is impossible, making options that claim complete elimination incorrect.
Q18. What should be done if one person is unavailable during an emergency?
Answer: D. Diligently assign a new decision maker to overcome the situation
During an emergency, organizations must diligently assign a new decision maker to maintain operational continuity. While phone trees provide communication, they do not solve the immediate need for authoritative leadership.
Q19. What is the main goal of a Disaster Recovery Plan (DRP)?
Answer: C. Restore IT and communications back to full operations
A disaster recovery plan specifically focuses on restoring information technology and communications systems after a disruptive event. Maintaining critical business functions overall is the goal of a business continuity plan, which represents the primary distractor in this scenario.
Q20. Which of the following best illustrates a shortened version of the IPv6 address 2003:0ab8:0000:0000:0000:eeee:0000:0001?
Answer: B. 2003:ab8::eeee:0:1
IPv6 compression rules allow leading zeros to be removed from groups and consecutive zero groups to be replaced with a single double colon. The other options fail because they either misuse the double colon, use it twice, or fail to drop leading zeros properly.
Q21. Why is it essential for organizations to periodically review their retained records?
Answer: A. To stay compliant with changing regulations
Organizations must periodically review retained records to stay compliant with changing data privacy regulations and avoid legal penalties. While freeing up storage or evaluating security risks are valid operational tasks, regulatory compliance is the primary driver.
Q22. What types of cards can be used as a tool to grant access?
Answer: C. Smart cards
Smart cards act as authentication tokens to grant logical or physical access. The other options are incorrect because standard credit, business, or birthday cards lack the necessary integrated circuit technology.
Q23. Which of the following is typically NOT a member of an incident response team?
Answer: A. HR representatives
An incident response team typically includes IT, engineering, legal, and public relations representatives to cover technical, legal, and communication needs. While HR may be consulted for internal investigations, they are not traditionally considered primary members of the core incident response team.
More ISC2 Certified in Cybersecurity (CC) Full Exams '26 drills and other practice exams are on @CertPunch. New rounds drop every few days at certpunch.com.