ISC2 Certified in Cybersecurity (CC) Full Exams ’26 Practice Exam Questions and Answ – Part 3/5

Practice for the ISC2 Certified in Cybersecurity (CC) Full Exams '26 exam with 19 exam-style practice questions, instant answer reveals, and concise explanations of every correct answer. Topics include: The process that ensures that system changes do not adversely impact business operations is known as:. Follow @CertPunch and visit certpunch.com for more certification practice exams and study content.

Prefer hands-on? Take this round as an interactive practice test — answer every question, get instant feedback, and see your score: Start the ISC2 Certified in Cybersecurity (CC) Full Exams '26 practice test →

What you will practice

  • The process that ensures that system changes do not adversely impact business operations is known as:
  • Which of the following is an example of a technical security control?
  • Which of these tools is commonly used to crack passwords?
  • Which of the following is NOT a type of learning activity used in security awareness?
  • Which security principle states that a user should only have the necessary permission to execute a task?
  • The Bell and LaPadula access control model is a form of:

Answers and explanations

Tap a question to expand the answer and the exam reasoning. Try to commit to your own pick first.

Q1. The process that ensures that system changes do not adversely impact business operations is known as:

Answer: A. Change Management

Change management is the process of implementing necessary changes so that they do not adversely affect business operations. Vulnerability management tracks system flaws, configuration management maintains system integrity, and incident management addresses unplanned events.

Q2. Which of the following is an example of a technical security control?

Answer: D. Access control lists

Access control lists are technical security controls implemented in software or hardware to limit access to digital resources based on rules. Fences, bollards, and turnstiles are physical security controls designed to prevent unauthorized physical access to facilities.

Q3. Which of these tools is commonly used to crack passwords?

Answer: B. John the Ripper

John the Ripper is a standard password cracking and auditing tool used to test password strength. The other options serve different security functions: Burp Suite tests web applications, while Wireshark and Nslookup are used for network analysis and DNS queries.

Q4. Which of the following is NOT a type of learning activity used in security awareness?

Answer: C. Tutorial

Awareness, training, and education are the three foundational learning activities defined in security programs. Tutorials simply teach specific step-by-step tasks and are not categorized as a primary security learning activity.

Q5. Which security principle states that a user should only have the necessary permission to execute a task?

Answer: B. Least Privilege

The principle of least privilege ensures users are granted only the minimum access required to perform their specific job duties. Separation of duties divides tasks to prevent fraud, while defense in depth uses multiple security layers.

Q6. The Bell and LaPadula access control model is a form of:

Answer: A. MAC

The Bell and LaPadula model is a classic implementation of mandatory access control, focusing on data confidentiality across strict security levels. Unlike discretionary access control, users cannot change the security labels governing access.

Q7. Which of the following is NOT a possible model for an incident response team (IRT)?

Answer: B. Pre-existing

Valid incident response team structures include dedicated, leveraged, and hybrid models. A pre-existing team is not a recognized model because incident response groups are intentionally formed to address specific organizational security mandates.

Q8. Which of the following is an example of two-factor authentication (2FA)?

Answer: A. One-Time passwords (OTP)

One-time passwords act as a secondary authentication factor, typically fulfilling the 'something you have' criteria. Badges, keys, and standard passwords only represent a single authentication factor unless paired with another mechanism.

Q9. Which of the following is a detection control?

Answer: A. Smoke sensors

Smoke sensors are detection controls because they identify hazards and trigger alerts. The distractors represent physical or technical preventive controls—bollards, turnstiles, and firewalls—which are designed to block unauthorized access entirely.

Q10. Which access control model can grant access to a given object based on complex rules?

Answer: D. ABAC

Attribute-based access control, or ABAC, evaluates complex rules using subject, object, and environmental attributes. The alternative models rely on fixed labels, ownership, or roles, lacking ABAC's dynamic policy flexibility.

Q11. Which are the components of an incident response plan?

Answer: B. Preparation → Detection and Analysis → Containment, Eradication and Recovery → Post-Incident Activity

The standard incident response lifecycle includes preparation, detection and analysis, containment, eradication and recovery, and post-incident activity. Eliminate any options that place containment after recovery, as you must isolate the threat before safely removing it and restoring systems.

Q12. The predetermined set of instructions or procedures to sustain business operations after a disaster is commonly known as:

Answer: D. Business Continuity Plan

A Business Continuity Plan outlines how an organization will sustain critical business operations during and after a major disruption. Disaster recovery focuses specifically on restoring IT infrastructure, whereas business continuity addresses the overall mission and business processes.

Q13. A company needs to securely connect two branch offices over the public internet. They implement a solution that encrypts the entire original IP packet and wraps it in a new packet header for safe transit. This ensures that internal IP addr…

Answer: A. IPSec Tunnel Mode

IPSec tunnel mode encapsulates and encrypts the entire original IP packet within a new packet header, which hides internal network addresses during transit. Transport mode only encrypts the payload and leaves the original IP header visible, making it unsuitable for site-to-site gateway connections.

Q14. Which of the following types of devices inspect packet header information to either allow or deny network traffic?

Answer: A. Firewalls

Firewalls inspect packet header information against a defined rule set to either allow or deny network traffic. Switches and routers forward traffic based on destination addresses, while hubs simply broadcast all packets without any inspection or filtering capabilities.

Q15. Governments can impose financial penalties as a consequence of breaking a:

Answer: B. Regulation

Regulations are legal requirements established by governments, meaning non-compliance can result in official financial penalties. Standards are voluntary technical guidelines, while policies and procedures are internal organizational rules that do not carry government fines.

Q16. A device found not to comply with the security baseline should be:

Answer: C. Disabled or isolated into a quarantine area until it can be checked and updated

A device that fails to meet security baselines should be disabled or isolated in a quarantine area until it is remediated. Placing it in a demilitarized zone exposes it to the internet, and a virus scan alone does not guarantee baseline compliance.

Q17. Which protocol uses a three-way handshake to establish a reliable connection?

Answer: D. TCP

The Transmission Control Protocol uses a three-way handshake to establish a reliable connection between two devices. UDP is a connectionless protocol that does not use handshakes, while SMTP and SNMP are application-layer protocols.

Q18. Which of the following attacks take advantage of poor input validation in websites?

Answer: B. Cross-Site Scripting

Cross-site scripting is a web application vulnerability that exploits poor input validation to inject malicious client-side scripts. Phishing relies on social engineering, while rootkits and trojans are types of malicious software.

Q19. Which cloud deployment model is suited to companies with similar needs and concerns?

Answer: C. Community cloud

A community cloud is shared by several organizations with similar needs, such as specific regulatory or security requirements. Private clouds serve a single organization, while hybrid clouds mix different environments.

More ISC2 Certified in Cybersecurity (CC) Full Exams '26 drills and other practice exams are on @CertPunch. New rounds drop every few days at certpunch.com.

Scroll to Top