Practice for the ISC2 Certified in Cybersecurity (CC) Full Exams '26 exam with 20 exam-style practice questions, instant answer reveals, and concise explanations of every correct answer. Topics include: What is the PRIMARY goal of security training?. Follow @CertPunch and visit certpunch.com for more certification practice exams and study content.
Prefer hands-on? Take this round as an interactive practice test — answer every question, get instant feedback, and see your score: Start the ISC2 Certified in Cybersecurity (CC) Full Exams '26 practice test →
What you will practice
- What is the PRIMARY goal of security training?
- What is the most effective physical security measure for a recently established unstaffed computing facility…
- Which of the following is a best practice for data backup policies?
- Which risk management strategy does an organization use when it recognizes the risk of a natural disaster but…
- What is a zero-day vulnerability?
- What type of disaster recovery test involves activating the alternate processing facility while keeping the p…
Answers and explanations
Tap a question to expand the answer and the exam reasoning. Try to commit to your own pick first.
Q1. What is the PRIMARY goal of security training?
Answer: A. To build proficiency in a set of skills or actions in security subjects
Security training is designed to build practical skills, enabling employees to recognize and respond to threats effectively. The distractors describe unrealistic outcomes, as eliminating policies or granting administrative access would severely weaken security.
Q2. What is the most effective physical security measure for a recently established unstaffed computing facility, featuring motion detectors and secondary authentication?
Answer: D. Mantrap
A mantrap provides physical access control by using two interlocking doors, ensuring only authenticated users enter. The distractors fail because cameras only record intrusion, an IPS is a network control, and Faraday cages block electromagnetic fields.
Q3. Which of the following is a best practice for data backup policies?
Answer: D. Encrypting backups to protect data confidentiality and integrity
Encrypting backups protects the confidentiality and integrity of the stored data if it is lost or stolen. The other options represent poor practices, as backups require regular testing, defined schedules, and off-site storage to ensure recovery.
Q4. Which risk management strategy does an organization use when it recognizes the risk of a natural disaster but decides not to implement controls because the costs outweigh the benefits?
Answer: A. Risk acceptance
Risk acceptance occurs when leadership acknowledges a risk but chooses not to implement controls because the cost outweighs the benefit. Avoidance removes the threat entirely, mitigation reduces it, and transference shifts the impact to a third party.
Q5. What is a zero-day vulnerability?
Answer: A. An attack previously unknown to the security community
A zero-day vulnerability is an unknown security flaw in software or hardware that developers have had zero days to patch. The term does not refer to novice attackers or literal date manipulation.
Q6. What type of disaster recovery test involves activating the alternate processing facility while keeping the primary site operational?
Answer: B. Parallel test
A parallel test activates the alternate processing facility while keeping the primary site operational. The trap options are checklist, tabletop, and full interruption tests because they do not involve running both sites concurrently.
Q7. What is the PRIMARY objective of a Virtual Private Network (VPN)?
Answer: C. To provide secure access to a network
The primary objective of a Virtual Private Network is to provide secure access to a network. While VPNs do provide device access, options like subnetting or cloud connectivity are secondary functions rather than the main security goal.
Q8. What term is used to describe a large collection of unrelated patches released together?
Answer: A. Service pack
A service pack is a large collection of unrelated patches released together to update software efficiently. Eliminate hotfix and security fix because those terms refer to individual, targeted vulnerability patches.
Q9. Which of the following access control types does NOT involve a lock?
Answer: A. Directive
Directive access control is an administrative control that issues policies or guidelines, which does not involve a physical lock. Physical, preventive, and deterrent controls often rely on physical barriers or devices to function.
Q10. What term refers to a facility that is equipped with HVAC, power, and communications circuits, but does not have hardware for a business to use during a disaster?
Answer: A. Cold site
A cold site is a facility equipped with basic infrastructure like HVAC, power, and communications, but lacks active hardware. Eliminate warm and hot sites because they include pre-installed equipment and data replication capabilities.
Q11. Which option below does NOT represent a type of biometric data?
Answer: B. Smart Card
Biometric data refers to physical characteristics used for identification, such as voice records, retina scans, and fingerprints. A smart card is a physical authentication token, not an inherent physical or behavioral trait.
Q12. Which of the following documents is developed by governments or industry regulators to enforce specific requirements for cybersecurity?
Answer: B. Regulations
Regulations are developed by governments or industry regulators to enforce legally binding cybersecurity requirements. Eliminate policies and procedures because they are internal documents created by the organization itself.
Q13. Which of the ISC2 Code of Ethics canons emphasizes the importance of continuous professional development?
Answer: C. Advance and protect the profession
The advance and protect the profession canon requires members to maintain their competence and keep skills current. The other canons focus on protecting society, acting legally, and providing diligent service.
Q14. What type of control is commonly exemplified by dogs, guards, and fences?
Answer: A. Physical
Dogs, guards, and fences are physical controls designed to prevent or deter unauthorized physical access. Detective controls identify incidents, recovery controls restore operations, and administrative controls manage policies.
Q15. The CIA Triad is a foundational security model that includes which three key principles?
Answer: B. Confidentiality, Integrity, Availability
The CIA Triad is the foundational security model encompassing confidentiality, integrity, and availability. Accessibility, identity, and concealment are distractors that sound similar but do not form the standard triad.
Q16. What access control principle prevents someone from both creating a new user account and assigning that account superuser privileges within the same system?
Answer: A. Separation of duties
Separation of duties requires multiple individuals to complete sensitive tasks, preventing one person from creating and elevating an account. Least privilege limits access, but separation specifically divides these conflicting duties.
Q17. Which aspect of the CIA Triad focuses on ensuring that the information is accessible when it is needed?
Answer: C. Availability
Availability ensures that information and systems remain accessible to authorized users when needed. Confidentiality protects against unauthorized access, while integrity prevents unauthorized data alteration.
Q18. Which ISC2 Code of Ethics Canon emphasizes a security analyst's duty to avoid harm and uphold public well-being?
Answer: C. Protect society, the common good, necessary public trust and confidence, and the infrastructure
The first canon of the ISC2 Code of Ethics prioritizes protecting society, the common good, and public infrastructure. This overarching duty ranks above responsibilities to principals, ethical behavior, or advancing the profession.
Q19. An organization plans to implement a new billing policy for the financial department. The policy will affect existing procedures, require approval, and must be communicated to relevant stakeholders before being enforced. Which concept BEST…
Answer: B. Change management
Change management is the formal process of controlling modifications to systems, policies, or procedures to minimize disruption. It requires logging, assessing, approving, and communicating changes, distinguishing it from incident response or business continuity.
Q20. A business application fails to open a file received from an external source because the file has an unusual extension (.XLL). The user wants to open the file so work can continue and is unsure of the best action to take. What is the MOST…
Answer: C. Treat the file as untrusted and analyze it in a secure environment
Files with unusual extensions from external sources must be treated as untrusted and analyzed in a secure environment like a sandbox. Forcing applications to open files, renaming extensions, or disabling validation prioritizes convenience over security and weakens your defense-in-depth posture.
More ISC2 Certified in Cybersecurity (CC) Full Exams '26 drills and other practice exams are on @CertPunch. New rounds drop every few days at certpunch.com.