Practice for the ISC2 Certified in Cybersecurity (CC) Full Exams '26 exam with 20 exam-style practice questions, instant answer reveals, and concise explanations of every correct answer. Topics include: What statement regarding the ISC2 code of ethics is NOT true?. Follow @CertPunch and visit certpunch.com for more certification practice exams and study content.
Prefer hands-on? Take this round as an interactive practice test — answer every question, get instant feedback, and see your score: Start the ISC2 Certified in Cybersecurity (CC) Full Exams '26 practice test →
What you will practice
- What statement regarding the ISC2 code of ethics is NOT true?
- Digital signatures provide which of the following security benefits?
- Which OSI model layer is responsible for the end-to-end transmission of data between two hosts?
- Which of the following describes the number of authentication factors employed by an organization requiring a…
- A hash function is …:
- Which security solution can prevent unauthorized access to the internal network?
Answers and explanations
Tap a question to expand the answer and the exam reasoning. Try to commit to your own pick first.
Q1. What statement regarding the ISC2 code of ethics is NOT true?
Answer: B. The code applies to all members of the information security profession
The ISC2 Code of Ethics applies specifically to ISC2 members and certified professionals, not every member of the information security industry. Adherence is mandatory for certification, breaches must be reported, and violations can result in certification revocation.
Q2. Digital signatures provide which of the following security benefits?
Answer: D. Data integrity and non-repudiation
Digital signatures provide data integrity and non-repudiation by uniquely linking the sender to the message. Any changes made after signing invalidate the signature, and the sender cannot deny sending it, whereas confidentiality requires encryption.
Q3. Which OSI model layer is responsible for the end-to-end transmission of data between two hosts?
Answer: D. The Transport layer
The Transport layer manages reliable or unreliable end-to-end data transmission between hosts using protocols like TCP and UDP. The Network layer handles routing between networks, while the Session and Presentation layers manage dialog and data formatting.
Q4. Which of the following describes the number of authentication factors employed by an organization requiring a username, PIN, token, and retina scan during login?
Answer: D. Three
The scenario uses three authentication factors: something you know, something you have, and something you are. The trap is counting the username and PIN as two separate items, but a username is an identity identifier, not an authentication factor.
Q5. A hash function is …:
Answer: A. … a mathematical function that generates a fixed-size string of characters
A hash function is a mathematical function that generates a fixed-size string of characters from an input. Eliminate data compression and encryption because hashing specifically ensures data integrity rather than confidentiality.
Q6. Which security solution can prevent unauthorized access to the internal network?
Answer: A. NAC
Network Access Control enforces security policies by checking device compliance before granting network access. SIEM aggregates logs, NAT translates addresses, and VLANs segment traffic, but none actively block non-compliant devices.
Q7. What is the term for an instance in which a logged-in user can perform specific activities within an application or system?
Answer: B. Authorization
Authorization grants or denies specific rights to a logged-in user, dictating what actions they can perform. Logins verify identity, while roles and groups simply organize users to make assigning those permissions easier.
Q8. A flood of inbound connections from various global locations suggests what kind of attack?
Answer: D. A distributed denial-of-service attack
A distributed denial-of-service attack floods a target with traffic from multiple compromised systems across various locations. Viruses and worms are malware types, while a smurf attack is a specific ICMP-based local flood.
Q9. What responsibility do you have as a member of the data protection team?
Answer: D. To understand how the privacy laws apply to your organization
Data protection teams must understand how privacy laws apply to their specific organization. Interpreting, drafting, or enacting laws falls to legal professionals, judges, and legislators, not internal security staff.
Q10. Which of the following is a PRIMARY purpose of using digital signatures?
Answer: D. Protecting data from unauthorized modification
Digital signatures provide non-repudiation and protect data from unauthorized modification by ensuring integrity. Encryption protects confidentiality, authentication verifies identity, and hashing secures password storage.
Q11. What phase of the incident response process is aimed at minimizing the impact or extent of an incident?
Answer: D. Containment
The containment phase minimizes the impact and extent of a security incident by isolating affected systems. Detection identifies the incident, response stops it, and recovery restores normal operations, but containment specifically limits the damage.
Q12. After receiving a valid personal data access request, how long does an EU company typically have to respond?
Answer: A. Within 30 days
Under GDPR, organizations must respond to data subject access requests without undue delay and within one month. The other durations are incorrect because they either fall short of the standard or incorrectly apply complex case extensions.
Q13. Which cryptographic attribute is demonstrated when Alice proves that Bob's message undeniably came from him?
Answer: A. Non-repudiation
Non-repudiation proves the origin of a message so the sender cannot deny sending it. Authentication verifies identity, confidentiality protects data from unauthorized viewing, and integrity ensures the message remains unaltered during transmission.
Q14. Which term is used to denote the standard permissions assigned to a user account upon creation?
Answer: A. Baseline
A baseline defines the standard initial permissions assigned to a user account upon creation. Entitlement refers to rights granted later based on role, while aggregation and transitivity involve data collection and domain trust relationships, respectively.
Q15. Which of the following logical access control models uses a set of rules to determine whether a subject can access a specific object?
Answer: D. Rule-Based Access Control (RuBAC)
Rule-Based Access Control uses specific conditions, like access control lists, to determine access permissions. Discretionary control relies on owner discretion, Role-Based uses job functions, and Mandatory Access Control relies on classification labels.
Q16. What instrument assists system administrators by providing secure configuration templates for operating systems and applications?
Answer: B. Baseline configuration
A baseline configuration provides secure configuration templates for operating systems and applications. Security guidelines are general recommendations, while a running configuration is simply the current active state, making baseline the only proven template.
Q17. When developing a business impact analysis, what should be the next step after creating a list of assets?
Answer: C. Determine the value of each asset
After creating an asset list in a business impact analysis, the immediate next step is determining the value of each asset. Evaluating risks and identifying vulnerabilities belong to the risk assessment process, not the initial business impact valuation.
Q18. Why is it important to conduct security awareness training regularly?
Answer: B. To ensure employees stay up to date with the latest security threats and best practices
Regular security awareness training ensures employees stay up to date with the latest threats and best practices. The other options describe actively bypassing security or decreasing critical security measures, which are never valid training goals.
Q19. What type of malware is used to take hostage a user's data and require a ransom payment for release?
Answer: D. Ransomware
Ransomware is malware that holds a user's data hostage by encrypting it until a ransom is paid. Trojans create backdoors, and denial of service attacks disrupt availability through traffic floods, eliminating the other options.
Q20. What receives a label in a MAC model?
Answer: D. Labels are assigned to objects and subjects
In a mandatory access control model, labels are assigned to both objects and subjects based on classification levels. Options suggesting only one receives a label or that all share the same label misrepresent the required subject and object pairing.
More ISC2 Certified in Cybersecurity (CC) Full Exams '26 drills and other practice exams are on @CertPunch. New rounds drop every few days at certpunch.com.