ISC2 Certified in Cybersecurity (CC) Full Exams ’26 Practice Exam Questions and Ans – Part 7/10

Practice for the ISC2 Certified in Cybersecurity (CC) Full Exams '26 exam with 20 exam-style practice questions, instant answer reveals, and concise explanations of every correct answer. Topics include: Which of the following layers is NOT a layer in the TCP/IP architecture?. Follow @CertPunch and visit certpunch.com for more certification practice exams and study content.

Prefer hands-on? Take this round as an interactive practice test — answer every question, get instant feedback, and see your score: Start the ISC2 Certified in Cybersecurity (CC) Full Exams '26 practice test →

What you will practice

  • Which of the following layers is NOT a layer in the TCP/IP architecture?
  • HIPAA primarily oversees the use of:
  • What term describes the maximum level of data loss an organization is willing to accept in pursuit of its obj…
  • Which of the following is NOT considered a threat actor?
  • What is a side-channel attack?
  • What process should the company undertake to verify that an employee has the necessary privileges, considerin…

Answers and explanations

Tap a question to expand the answer and the exam reasoning. Try to commit to your own pick first.

Q1. Which of the following layers is NOT a layer in the TCP/IP architecture?

Answer: D. Data link Layer

The data link layer is part of the OSI model, not the four-layer TCP/IP architecture. The TCP/IP model consists of the Application, Transport, and Internet layers, plus a Network Access layer, which eliminates the other options.

Q2. HIPAA primarily oversees the use of:

Answer: D. Protected health information (PHI) in the United States

HIPAA is a United States law that regulates the use and disclosure of Protected Health Information. It applies to covered entities like healthcare providers, eliminating options that reference European data or social media.

Q3. What term describes the maximum level of data loss an organization is willing to accept in pursuit of its objectives?

Answer: C. Risk appetite

Risk appetite is the broad amount and type of risk an organization is willing to accept to achieve its objectives. Risk tolerance refers to operational thresholds, while residual risk remains after controls are applied, eliminating the distractors.

Q4. Which of the following is NOT considered a threat actor?

Answer: B. A software company developing a malware detection system

A software company developing a malware detection system is a cybersecurity defender, not a threat actor. Nation-states, corporate competitors, and cyberterrorists are all malicious entities that exploit vulnerabilities, which validates the other options.

Q5. What is a side-channel attack?

Answer: C. A passive, noninvasive attack to observe the operation of a device

A side-channel attack is a passive, noninvasive technique where attackers observe the physical operation of a device, such as power consumption or timing. Options describing spoofing, phishing, or botnets target software or users instead.

Q6. What process should the company undertake to verify that an employee has the necessary privileges, considering their roles in HR, payroll, and customer service?

Answer: B. Account review

Account review verifies that employees have only the necessary privileges for their current roles, directly preventing privilege creep. Revocation removes access entirely, while re-provisioning happens during role changes, eliminating the distractors.

Q7. Which of the following is a common topic covered in security awareness training?

Answer: B. Recognizing and reporting phishing attempts

Recognizing and reporting phishing attempts is a core focus of security awareness training because it directly reduces human risk. Disabling antivirus, sharing passwords, and granting admin access to everyone all introduce critical vulnerabilities.

Q8. Which of the following documents outlines the specific step-by-step instructions to achieve a task or process?

Answer: B. Procedures

Procedures provide the mandatory, step-by-step technical instructions required to complete specific tasks securely. Policies establish high-level rules, standards define technical requirements, and regulations are legal mandates, which eliminates those options.

Q9. Which type of disaster recovery test has the LEAST possible impact on regular information system operations?

Answer: A. Checklist review

A checklist review is a paper-based exercise that validates recovery documentation without touching production systems. The other options involve actual system disruption or resource usage, with a full interruption test being the most disruptive approach.

Q10. Which type of documentation is commonly created once an incident has been remediated?

Answer: C. A document outlining the lessons learned

Once an incident is resolved, organizations create a lessons learned document to identify process improvements. The distractors apply to different lifecycle phases, as risk assessments happen beforehand and remediation actions occur during active mitigation.

Q11. What is the PRIMARY goal of a spoofing attack?

Answer: C. Gaining access to a target system

The primary goal of spoofing is gaining system access by impersonating a legitimate user or device to bypass authentication. While spoofing can support malicious code delivery or redirection, those are secondary effects rather than the core objective.

Q12. What is the main purpose of an Acceptable Use Policy (AUP)?

Answer: A. Informs users of company expectations when they use computer systems and networks

An Acceptable Use Policy outlines the rules and expectations for how employees may use organizational systems and networks. Password guidelines and network monitoring are separate administrative controls, making them incorrect distractors here.

Q13. What type of attack is a Distributed Denial of Service (DDoS) attack?

Answer: D. An attack involving numerous unsuspecting secondary victim systems used to flood the target system

A Distributed Denial of Service attack uses multiple compromised systems to flood a target with traffic, disrupting service for legitimate users. The other options describe spoofing, phishing, or specific HTTP floods rather than the distributed nature of the attack.

Q14. Which principle limits access to personally identifiable information (PII) to essential information?

Answer: C. Need to know

The need to know principle limits access to sensitive data strictly to what is required for a specific job function. Separation of duties splits tasks to prevent fraud, while context-dependent controls rely on system state.

Q15. What is the best technology for detecting unauthorized storage of sensitive data on hard drives?

Answer: C. DLP

Data Loss Prevention identifies, monitors, and protects sensitive data at rest, such as on hard drives. Intrusion detection and prevention systems focus on network traffic analysis, while Transport Layer Security encrypts data in transit.

Q16. What is the term for retaining and maintaining information for as long as it is needed?

Answer: C. Record retention

Record retention refers to the practice of maintaining and storing information for its required lifespan. Data storage policies dictate security guidelines, whereas asset maintenance deals with physical or virtual inventory tracking.

Q17. A security analyst is required to transmit a confidential incident report to the organization's CISO using email. The primary security objective is to ensure confidentiality of the message if it is intercepted during transmission. The anal…

Answer: A. The CISO's public key

To ensure confidentiality in public key infrastructure, the sender encrypts the message using the recipient's public key. This guarantees that only the intended recipient, who holds the matching private key, can decrypt and read the message.

Q18. Which of the following is an administrative security control?

Answer: D. Security Awareness Training

Security awareness training is an administrative control because it focuses on educating personnel and managing human risk through policies. Physical controls deter physical access, while technical controls enforce rules digitally.

Q19. Which of the following is an example of a physical security control?

Answer: C. Using CCTV cameras to monitor unauthorized access

Closed-circuit television cameras are physical controls because they monitor and record physical access to deter unauthorized entry. Acceptable use and training are administrative controls that manage human behavior.

Q20. What is the main difference between PII and PHI?

Answer: A. PII is personal information, while PHI is health-related information

Personally identifiable information identifies an individual, while protected health information specifically relates to their medical care and health status. Protected health information is a specialized subset of personally identifiable information.

More ISC2 Certified in Cybersecurity (CC) Full Exams '26 drills and other practice exams are on @CertPunch. New rounds drop every few days at certpunch.com.

Scroll to Top