dc dotCreds
Reference guide

ISC2 CC Course Notes

Study ISC2 CC section notes, then jump straight into the guided course or related practice questions without losing your place.

Continue CourseStart PracticePDF downloads available in Pro.
Checking access

Checking Pro access...

Looking for your active Pro access before showing Course Notes. This usually takes just a moment.

Course Notes preview

Unlock Pro for the full per-exam reference guide.

Preview one piece from each section. Pro includes every Course Notes section, summary, key point, common mistake, exam tip, related-question review, and PDF export.

Includes full Course Mode and Course Notes.

Section 1Security Principles (24%)Preview
More in this section
  • 10 more key points in Pro version
  • 5 more common mistakes in Pro version
  • 2 more exam tips in Pro version
  • 45 more related questions in Pro version

Summary

Master the fundamentals: CIA, AAA, non-repudiation, privacy, risk lifecycle, governance hierarchy, control categories, and professional ethics.

Key Points

  • CIA: confidentiality = no unauthorized disclosure; integrity = no unauthorized change; availability = reliable access.

Common Mistakes

  • Confusing authentication and authorization.

Exam Tips

  • Identify the security objective before selecting a control.
Section 2Security Governance (17.3%)Preview
More in this section
  • 10 more key points in Pro version
  • 5 more common mistakes in Pro version
  • 2 more exam tips in Pro version
  • 32 more related questions in Pro version

Summary

Security Governance is GRC, continuity/redundancy, security culture, and measuring whether the program actually works.

Key Points

  • GRC links requirements -> risks -> controls -> owners -> evidence.

Common Mistakes

  • Treating compliance paperwork as the purpose of GRC.

Exam Tips

  • GRC is traceability and accountability.
Section 3Identity and Access Management (IAM) Concepts (20%)Preview
More in this section
  • 8 more key points in Pro version
  • 4 more common mistakes in Pro version
  • 2 more exam tips in Pro version
  • 37 more related questions in Pro version

Summary

IAM is lifecycle plus authorization: define roles, provision, review, deprovision, apply least privilege, separate duties, and know access-control models.

Key Points

  • Identity lifecycle = define role -> provision -> review/modify -> deprovision.

Common Mistakes

  • Adding new-role access without removing old access.

Exam Tips

  • JML = Joiner/Mover/Leaver.
Section 4Networking and Cloud Security Concepts (21.3%)Preview
More in this section
  • 10 more key points in Pro version
  • 4 more common mistakes in Pro version
  • 2 more exam tips in Pro version
  • 40 more related questions in Pro version

Summary

Networking and cloud now includes network fundamentals, architecture/Zero Trust, wireless and IoT/ICS, plus cloud characteristics, models, and shared responsibility.

Key Points

  • OSI: Application, Presentation, Session, Transport, Network, Data Link, Physical.

Common Mistakes

  • Treating a VPN as endpoint security.

Exam Tips

  • Layer first, control second.
Section 5Security Operations and Incident Response (17.3%)Preview
More in this section
  • 10 more key points in Pro version
  • 6 more common mistakes in Pro version
  • 2 more exam tips in Pro version
  • 31 more related questions in Pro version

Summary

Security Operations and Incident Response now covers data security, logging/triage/threat intelligence, IR planning/exercises, asset/change lifecycle, and modern security testing.

Key Points

  • Classification = sensitivity; label = communicate; masking = obscure value; sanitization = make data unrecoverable.

Common Mistakes

  • Calling masking encryption.

Exam Tips

  • Correlate -> triage -> prioritize -> escalate.