ISC2 Certified in Cybersecurity (CC) Full Exams ’26 Practice Exam Questions and Answ – Part 4/5

Practice for the ISC2 Certified in Cybersecurity (CC) Full Exams '26 exam with 19 exam-style practice questions, instant answer reveals, and concise explanations of every correct answer. Topics include: What is the PRIMARY characteristic of a Smurfing attack?. Follow @CertPunch and visit certpunch.com for more certification practice exams and study content.

Prefer hands-on? Take this round as an interactive practice test — answer every question, get instant feedback, and see your score: Start the ISC2 Certified in Cybersecurity (CC) Full Exams '26 practice test →

What you will practice

  • What is the PRIMARY characteristic of a Smurfing attack?
  • What type of security control is the biometric reader that grants access to the data center building?
  • The detailed steps to complete tasks supporting departmental or organizational policies are typically documen…
  • Which of these has the PRIMARY objective of identifying and prioritizing critical business processes?
  • Two ISC2 certified professionals are involved in a heated legal dispute regarding the terms of a consulting c…
  • Which of the following is an example of an administrative security control?

Answers and explanations

Tap a question to expand the answer and the exam reasoning. Try to commit to your own pick first.

Q1. What is the PRIMARY characteristic of a Smurfing attack?

Answer: A. It floods a victim with traffic by abusing broadcast addresses

A smurfing attack is a distributed denial-of-service technique that abuses IP broadcast addresses to flood a victim with traffic. The other options describe malware, social engineering, or ransomware.

Q2. What type of security control is the biometric reader that grants access to the data center building?

Answer: B. Physical Control

A biometric reader that grants access to a building is considered a physical security control because it restricts facility entry. Technical controls protect computer systems, while administrative controls guide human behavior.

Q3. The detailed steps to complete tasks supporting departmental or organizational policies are typically documented in:

Answer: C. Procedures

Procedures provide the mandatory, step-by-step actions required to implement organizational policies. Policies establish high-level rules, whereas procedures detail the exact operational execution. Standards offer specific benchmarks, leaving procedures as the clear choice for detailed task completion.

Q4. Which of these has the PRIMARY objective of identifying and prioritizing critical business processes?

Answer: B. Business Impact Analysis

A Business Impact Analysis focuses entirely on identifying and prioritizing critical business processes following a disruption. Disaster recovery and business continuity plans dictate the actual technical and operational recovery steps, making them incorrect options here.

Q5. Two ISC2 certified professionals are involved in a heated legal dispute regarding the terms of a consulting contract. One member files a complaint with the ISC2 ethics committee, claiming the other party breached the contract and acted unp…

Answer: B. They will not intervene or investigate private disputes or conflicts of interest

ISC2 does not act as an arbitrator or legal authority for private, contractual disputes between certified professionals. The organization only reviews ethics violations based on established legal or factual findings, eliminating the distractors about suspensions and legal counsel.

Q6. Which of the following is an example of an administrative security control?

Answer: D. Acceptable Use Policies

Acceptable use policies represent administrative security controls because they dictate human behavior and governance rules. Badge readers and signs are physical controls, while access lists are technical, meaning only the policy correctly identifies an administrative function.

Q7. Which type of attack attempts to trick the user into revealing personal information by sending a fraudulent message?

Answer: D. Phishing

Phishing relies on social engineering, using fraudulent messages to manipulate users into surrendering private data. Trojans and cross-site scripting rely on technical exploits or malware execution rather than direct human deception to harvest information.

Q8. Which type of attack PRIMARILY aims to make a resource inaccessible to its intended users?

Answer: C. Denial of Service

Denial of Service attacks target system availability by overwhelming resources with illegitimate traffic until legitimate users are locked out. Phishing and cross-site scripting primarily compromise confidentiality or integrity, completely missing the availability target.

Q9. Which of these is NOT an attack against an IP network?

Answer: D. Side-channel Attack

A side-channel attack extracts cryptographic secrets by monitoring physical device emissions or timing rather than targeting network traffic. Man-in-the-middle, oversized, and fragmented packet attacks explicitly disrupt or intercept standard IP network communications.

Q10. Which device would be more effective in detecting an intrusion into a network?

Answer: D. NIDS

A network intrusion detection system is purpose-built to monitor traffic and alert administrators about malicious activity across the entire network. Firewalls and routers focus on traffic filtering, and host-based systems only monitor individual endpoints.

Q11. Which type of attack has the PRIMARY objective of controlling a system from outside?

Answer: A. Backdoors

A backdoor bypasses standard authentication to provide remote attackers with ongoing unauthorized control over a compromised system. While rootkits or trojans might install backdoors, the backdoor itself is the mechanism enabling external command execution.

Q12. Which access control is more effective at protecting a door against unauthorized access?

Answer: D. Locks

Locks directly secure doors by requiring authorized keys or credentials for entry. While turnstiles and fences manage perimeter traffic, locks provide the most targeted defense against unauthorized physical access at the entry point itself.

Q13. The SMTP protocol operates at which level of the OSI model?

Answer: B. 7

The Simple Mail Transfer Protocol operates at layer seven, the application layer of the OSI model, which interfaces directly with end-user software. The numerical options like twenty-five and twenty-three are port numbers, not network layers.

Q14. Which of these is the most thorough and effective way to test a business continuity plan?

Answer: B. Simulations

Simulations are the most effective method because they involve full-scale re-enactments of emergency procedures, testing the plan under realistic conditions. Walkthroughs and reviews are valuable but remain static preparation steps that do not actively stress-test operational readiness.

Q15. How many data classification labels are generally considered manageable for an organization?

Answer: C. 2 – 3

Industry best practices state that two or three data classification labels are manageable for most organizations. Maintaining a simple system prevents confusion and reduces administrative overhead. Implementing more than four categories often becomes overly complex and challenging to enforce consistently.

Q16. Which of the following is a data handling policy procedure?

Answer: A. Destroy

Destroy is the final phase of the data handling lifecycle, requiring the secure elimination of data so it cannot be recovered. The other options relate to general data processing or transformation, but they are not official data handling phases used in security policies.

Q17. The address 8be2:4382:8d84:7ce2:ec0f:3908:d29a:903a is an:

Answer: C. IPv6 address

An IPv6 address is represented as eight groups of four hexadecimal digits separated by colons. The length and format clearly distinguish it from 32-bit IPv4 addresses, 48-bit MAC addresses, and standard web URLs.

Q18. What is the PRIMARY purpose of an information security awareness program?

Answer: B. To influence and change employee behavior regarding security risks

The primary purpose of an information security awareness program is to influence employee behavior and foster a security-conscious culture. Technical controls are handled by systems, and eliminating all incidents or phishing responses is impossible.

More ISC2 Certified in Cybersecurity (CC) Full Exams '26 drills and other practice exams are on @CertPunch. New rounds drop every few days at certpunch.com.

Scroll to Top