ISC2 Certified in Cybersecurity (CC) Full Exams ’26 Practice Exam Questions and Ans – Part 9/10

Practice for the ISC2 Certified in Cybersecurity (CC) Full Exams '26 exam with 19 exam-style practice questions, instant answer reveals, and concise explanations of every correct answer. Topics include: Which one of the following is PRIMARILY used for identification purposes and is not suitable for use as an authenticator. Follow @CertPunch and visit certpunch.com for more certification practice exams and study content.

Prefer hands-on? Take this round as an interactive practice test — answer every question, get instant feedback, and see your score: Start the ISC2 Certified in Cybersecurity (CC) Full Exams '26 practice test →

What you will practice

  • Which one of the following is PRIMARILY used for identification purposes and is not suitable for use as an au…
  • What information security principle is applied by restricting access to administrative servers only to IT sys…
  • Which one of the following security principles is PRIMARILY at risk when a device is lost or stolen?
  • Which of the following is NOT a principle of the ISC2 code of ethics?
  • A senior cybersecurity engineer is working late at night in the office. Before leaving, he notices an individ…
  • What access control model is commonly used in firewalls?

Answers and explanations

Tap a question to expand the answer and the exam reasoning. Try to commit to your own pick first.

Q1. Which one of the following is PRIMARILY used for identification purposes and is not suitable for use as an authenticator?

Answer: C. Username

A username is used for identification, claiming an identity, but it is not an authenticator. Passwords, tokens, and biometrics like retinal scans prove that identity, making them true authentication factors.

Q2. What information security principle is applied by restricting access to administrative servers only to IT system administrators?

Answer: B. Least privilege

The principle of least privilege grants users only the minimum access required to perform their official duties. Need to know is a valid related concept, but least privilege specifically focuses on restricting administrative rights to appropriate roles.

Q3. Which one of the following security principles is PRIMARILY at risk when a device is lost or stolen?

Answer: A. Confidentiality

When a device is physically lost or stolen, the primary security concern is unauthorized access to sensitive data. This directly impacts confidentiality, as the theft exposes private information to unauthorized individuals.

Q4. Which of the following is NOT a principle of the ISC2 code of ethics?

Answer: B. Promptly report security vulnerabilities to relevant authorities

Promptly reporting vulnerabilities is a best practice but is not explicitly listed as one of the four ISC2 Code of Ethics Canons. The four actual canons focus on protecting society, acting legally, serving principals, and advancing the profession.

Q5. A senior cybersecurity engineer is working late at night in the office. Before leaving, he notices an individual searching through a trash bin in a restricted area. The engineer does not recognize this person as an employee. Which security…

Answer: A. Dumpster Diving

Dumpster diving involves physically searching through trash to find discarded sensitive information or documents. Tailgating involves following someone through a secure door, whereas whaling and eavesdropping target executives and communications.

Q6. What access control model is commonly used in firewalls?

Answer: C. Rule-based access controls (RuBAC)

Rule-based access control, or RuBAC, uses specific conditions like IP addresses and ports to allow or deny actions. Firewalls rely heavily on these configured rule sets to filter network traffic, unlike role-based or discretionary models.

Q7. What type of attack involves attackers intercepting a connection between a user and a genuine website?

Answer: A. On Path

An on-path attack, formerly known as a man-in-the-middle attack, occurs when an attacker secretly intercepts and possibly alters communication between two parties. The other options describe software, internal actors, or prolonged network invasions.

Q8. What security principle is being adhered to when a user's access request is declined, despite meeting the necessary security clearance, because there is no business justification for the access?

Answer: A. Need to know

The need to know principle restricts access even from cleared personnel if they lack a specific business requirement. Least privilege grants the minimum necessary permissions, but need to know directly enforces business justification for sensitive data.

Q9. Which of the following concepts is exemplified by a load balancer that spans across multiple regions and boosts website availability and performance?

Answer: B. Multiple processing sites

Multiple processing sites provide redundancy by distributing workloads across different geographic locations to ensure availability. Warm and cold sites are standby facilities for disasters, while a honeynet serves as a decoy network to trap attackers.

Q10. What cloud service is recommended for developers to create applications?

Answer: C. Platform as a Service (PaaS)

Platform as a Service provides developers with a framework to build, test, and deploy applications without managing the underlying infrastructure. Infrastructure as a Service requires managing virtual machines, while Software as a Service delivers finished applications.

Q11. Access is based on which three elements?

Answer: B. Subject, Object, and Rules

Access control fundamentally relies on the relationship between a subject, an object, and the rules that govern their interaction. Permissions are derived from rules, while layers refer to network architecture rather than core access components.

Q12. What is a PRIMARY objective of a Virtual Local Area Network (VLAN)?

Answer: A. To segment a network into multiple subnets

A Virtual Local Area Network segments a larger physical network into multiple distinct broadcast domains to improve traffic management. Secure access to external providers uses VPNs, not local VLAN segmentation.

Q13. What is the PRIMARY purpose of encryption?

Answer: B. To protect data from unauthorized access

Encryption primarily protects data confidentiality by transforming readable plaintext into unreadable ciphertext. While it supports secure storage, its defining technical purpose is preventing unauthorized access, not processing or analyzing data.

Q14. What is the PRIMARY objective of security baselines?

Answer: C. Establish a standard for security configurations

Security baselines establish a uniform standard for system and application configurations to ensure a minimum level of protection. While baselines indirectly support data protection and threat monitoring, their primary purpose is to provide a measurable configuration standard.

Q15. Which of the following is typically NOT used as an anti-fraud measure?

Answer: C. Human resources

Mandatory vacations, job rotation, and two-person control are administrative controls specifically designed to prevent and detect internal fraud. Human resources is a department, not a specific anti-fraud control mechanism.

Q16. Which of the following is NOT an example of a technical control?

Answer: D. Data classification

Data classification is an administrative control because it involves defining policies and procedures for handling data based on its sensitivity. Technical controls are technology-based safeguards like firewalls, access control lists, and encryption.

Q17. What is the final phase of the data handling life cycle?

Answer: A. Destruction phase

Destruction is the final phase of the data handling lifecycle, ensuring that data is securely disposed of when it is no longer needed. This prevents unauthorized recovery of sensitive information.

Q18. What is the likelihood of a major earthquake in the downtown area of Paris in any given year, if records show that a major earthquake happens there every 100 years?

Answer: B. 0.01

The annual likelihood of an event occurring is calculated by dividing one by the frequency of occurrence in years. A 100-year event yields a probability of 0.01 per year.

Q19. What model is utilized in Mandatory Access Control (MAC)?

Answer: B. Lattice based

Mandatory Access Control uses a lattice-based model to determine access based on subject clearance and object sensitivity labels. Discretionary access control allows owners to set permissions, while group-based and rule-based methods describe implementation rather than the underlying model.

More ISC2 Certified in Cybersecurity (CC) Full Exams '26 drills and other practice exams are on @CertPunch. New rounds drop every few days at certpunch.com.

Scroll to Top