Practice for the ISC2 Certified in Cybersecurity (CC) Full Exams '26 exam with 19 exam-style practice questions, instant answer reveals, and concise explanations of every correct answer. Topics include: Which of these is the PRIMARY objective of a Disaster Recovery Plan?. Follow @CertPunch and visit certpunch.com for more certification practice exams and study content.
Prefer hands-on? Take this round as an interactive practice test — answer every question, get instant feedback, and see your score: Start the ISC2 Certified in Cybersecurity (CC) Full Exams '26 practice test →
What you will practice
- Which of these is the PRIMARY objective of a Disaster Recovery Plan?
- Sensitivity is a measure of the …:
- Which type of attack attempts to gain information by observing the device's power consumption?
- In incident terminology, the meaning of Zero Day is:
- Which action best describes the capability of an editing account?
- Which of these types of user is LESS likely to have a privileged account?
Answers and explanations
Tap a question to expand the answer and the exam reasoning. Try to commit to your own pick first.
Q1. Which of these is the PRIMARY objective of a Disaster Recovery Plan?
Answer: B. Restore company operation to the last-known reliable operation state
The primary objective of a Disaster Recovery Plan is to restore operations to the last-known reliable state after an incident. Maintaining crucial operations during a disaster is the goal of a Business Continuity Plan.
Q2. Sensitivity is a measure of the …:
Answer: D. … importance assigned to information by its owner, or the purpose of representing its need for protection
Sensitivity measures the importance assigned to information by its owner to represent its need for protection. This concept directly dictates how data is classified and safeguarded against unauthorized access.
Q3. Which type of attack attempts to gain information by observing the device's power consumption?
Answer: A. Side Channels
A side-channel attack extracts information from the physical implementation of a system, such as power consumption or electromagnetic leaks. The other options represent different threat categories that do not rely on passive hardware emissions to gather data.
Q4. In incident terminology, the meaning of Zero Day is:
Answer: A. A previously unknown system vulnerability
A zero-day vulnerability is an unknown system flaw that attackers can exploit because no patch or signature exists yet. These vulnerabilities do not fit recognized patterns, making them difficult to detect and prevent using standard security tools.
Q5. Which action best describes the capability of an editing account?
Answer: D. Change the contents of existing files
An editing account is designed specifically to modify file content while lacking administrative or ownership-level control. Assigning permissions requires administrative rights, and accessing or sharing files typically requires owner or contributor privileges.
Q6. Which of these types of user is LESS likely to have a privileged account?
Answer: C. External Worker
External workers are less likely to have privileged accounts due to the increased risk of misuse and lack of oversight. Help desk staff, security analysts, and system administrators require elevated privileges to manage endpoints, infrastructure, and data environments.
Q7. In Change Management, which component addresses the procedures needed to undo changes?
Answer: A. Rollback
A rollback component addresses the procedures and actions needed to undo changes if monitoring suggests a failure or inadequate performance. A request for change formalizes the initial proposal, but only the rollback phase plans the reversal procedure.
Q8. Which of the following elements is the minimum required information that must be included in an ethics complaint affidavit?
Answer: C. The respondent, alleged behavior, breached canon, complainant's standing, and corroborating evidence
An ethics complaint must include the respondent, alleged behavior, breached canon, complainant's standing, and corroborating evidence. This provides the necessary jurisdiction and context, whereas the distractors omit mandatory elements or suggest non-required steps.
Q9. With respect to risk management, which of the following options should be prioritized?
Answer: B. The frequency of occurrence is low, and the expected impact value is high
Risk management prioritizes scenarios with high impact, even if the probability or frequency is low. This focus ensures resources mitigate severe consequences to critical assets, rather than routine low-impact issues.
Q10. Logging and monitoring systems are essential to:
Answer: B. Identifying inefficient performing systems, detecting compromises, and providing a record of how systems are used
Logging and monitoring systems are essential for identifying inefficient performance, detecting security compromises, and providing an audit trail. Logging detects and records incidents rather than actively preventing them, which eliminates options that promise prevention.
Q11. Two individuals approach a restricted server room entrance that requires biometric authentication. The first individual successfully scans their fingerprint to unlock the door, and the second individual slips in through the open door witho…
Answer: C. Piggybacking
Piggybacking occurs when an unauthorized individual enters a secure area with the knowledge and consent of an authorized person. Tailgating is the trap to avoid here because it implies the authorized user is completely unaware of the person following them inside.
Q12. Which of the following areas is the most distinctive property of PHI?
Answer: A. Confidentiality
Confidentiality is the most distinctive property of Protected Health Information because preventing unauthorized disclosure is the primary concern. While integrity, authentication, and non-repudiation apply to general data, strict privacy rules uniquely govern health records.
Q13. A best practice of patch management is to:
Answer: D. Test patches before applying them
Testing patches before applying them to production systems is a core best practice to prevent unexpected downtime or stability issues. Rushing deployment based on arbitrary schedules or vendor reputation introduces operational risk.
Q14. In order to find out whether personal tablet devices are allowed in the office, which of the following policies would be helpful to read?
Answer: A. BYOD
A Bring Your Own Device policy establishes the rules for using personal tablets or phones in the workplace. The acceptable use policy governs how organizational systems are used, while change and privacy policies cover different areas.
Q15. Which of these is NOT a change management component?
Answer: B. Governance
Governance is a broad organizational concept rather than a specific change management component. Change management relies on requests for change, approvals, and rollbacks to manage system modifications safely.
Q16. Which of the following are NOT types of security controls?
Answer: D. Storage controls
Control frameworks categorize safeguards into common, system-specific, and hybrid controls. Storage controls represent a hardware location, not a distinct administrative or technical control category, making it the correct outlier.
Q17. Which of the following is NOT a feature of a cryptographic hash function?
Answer: A. Reversible
Cryptographic hashes are one-way mathematical operations, meaning the original plaintext cannot be derived from the hash output. Reversibility directly contradicts this core security principle, ensuring that stolen hashes remain computationally secure.
Q18. What is the proper procedure to submit a complaint to ISC2?
Answer: C. Submit a sworn affidavit in writing with a second copy in PDF format
Formal ethics complaints must be submitted in writing with supporting evidence attached. This requirement ensures due process, traceability, and fairness during the investigation. Anonymous reports or verbal updates lack the verifiable accountability required by the ethics committee.
Q19. After conducting a risk assessment, an organization implements multiple security controls to reduce the likelihood and impact of known threats. However, some level of risk remains because it cannot be completely eliminated without incurrin…
Answer: E. Residual Risk
Residual risk is the portion of threat exposure that remains after management implements and accepts the limitations of security controls. Risk appetite and tolerance define strategic willingness, but neither describes the concrete leftover risk itself.
More ISC2 Certified in Cybersecurity (CC) Full Exams '26 drills and other practice exams are on @CertPunch. New rounds drop every few days at certpunch.com.