dc dotCreds
ISC2 Certified in Cybersecurity Practice Test

ISC2 CC Practice Test

Start today’s free 10-question ISC2 CC set with source-backed explanations, local progress, and a fresh rotation every morning.

10 Free Daily Questions Source-backed Explanations 200 Verified Questions

Questions updated at Aug 23, 2026, 8:12 PM CDT

Go Pro - One Time Unlock

Unlock the full ISC2 CC bank

200 verified questions Exam Mode Practice Mode Detailed explanations Weak-area review No subscription - one-time unlock

Get the complete source-backed bank with Interview Questions, the full Study Guide, full Course Notes, detailed explanations, weak-area review, and exam-style practice.

Interview Questions Full Study Guide Full Course Notes Exam Mode Practice Mode Guided Course Detailed explanations Weak-area review No subscription
$2.99 One-time payment
See bundle and PDF options

We will confirm your site email in one quick checkout step.

Why DotCreds?

Practice with explanations that teach.

Source links for every answer Every wrong answer explained Guided Course included Practice and Exam Mode Weak-area tracking Same verified bank across web practice

What you get with free practice

10 Free Questions Daily Fresh set every day from the live bank
Detailed Explanations Learn with clear source-backed answers
Track Your Progress Daily history and performance insights
Upgrade Anytime Unlock the full bank when you are ready
Today's 10 ISC2 CC questions

Use this ISC2 CC practice test to review ISC2 Certified in Cybersecurity. Questions rotate daily and each answer links back to the source used to write it.

Today’s Set
10 questions
Rotates at 10:00 AM local time
Progress
0/10
Answered on this page
Accuracy
0%
Loading countdown…

200 verified questions are in the live bank. Free daily questions are selected from a rotating sample set. Unlock Pro to access the full question bank.

Preparing today’s free questions... Ordering the final locked-bank set before showing the practice cards.
Question 1 of 10
Objective 3.1 Understand identity life cycle management Identity and Access Management (IAM) Concepts (20%)

A hospital is onboarding a new class of pharmacy technicians. Existing users were historically copied from a senior pharmacist account, producing excessive access. What should IAM governance do FIRST for the new role?

Concept tested:
Question 2 of 10
Objective 4.1 Understand network security Networking and Cloud Security Concepts (21.3%)

A hospital tablet fleet uses Bluetooth only during initial keyboard pairing; Bluetooth remains discoverable afterward. Which hardening action BEST reduces unnecessary wireless exposure?

Concept tested:
Question 3 of 10
Objective 3.1 Understand identity life cycle management Identity and Access Management (IAM) Concepts (20%)

A company buys an IAM suite expecting it to solve access governance automatically. Role definitions, authoritative sources and approval owners remain undefined. What is the MOST likely result?

Concept tested:
Question 4 of 10
Objective 2.1 Plan Governance, Risk, and Compliance (GRC) Security Governance (17.3%)

A small healthcare provider adopts a broad cybersecurity framework. Many recommended outcomes apply, but its size, technology and regulatory obligations differ from those of a global enterprise. What is the BEST implementation approach?

Concept tested:
Question 5 of 10
Objective 1.4 Understand cybersecurity controls Security Principles (24%)

A facility posts clear surveillance notices and visible cameras at a restricted entrance, but the door itself has no access-control mechanism. Which statement BEST characterizes the control gap?

Concept tested:
Question 6 of 10
Objective 5.2 Understand security operations Security Operations and Incident Response (17.3%)

A monitoring platform flags a database server for sending 600 GB to an internal backup appliance at 02:00. The volume is unusual for the server, but the backup team recently changed schedules. What is the BEST first triage action?

Concept tested:
Question 7 of 10
Objective 4.2 Understand network security architecture Networking and Cloud Security Concepts (21.3%)

A cloud application has hundreds of short-lived workloads on the same virtual network. Static subnet rules cannot express which individual services should talk to each other. Which architecture is BEST suited to the requirement?

Concept tested:
Question 8 of 10
Objective 3.2 Understand logical access controls Identity and Access Management (IAM) Concepts (20%)

A research portal must allow access only when the user is a project member, the dataset classification is approved for that project, and the request comes from a managed device. Which design BEST expresses the decision?

Concept tested:
Question 9 of 10
Objective 2.4 Measure cybersecurity effectiveness Security Governance (17.3%)

A KRI tracks the percentage of critical third parties with expired security attestations. Leadership has defined 5% as the risk-tolerance threshold. The indicator reaches 11%. What is the BEST response?

Concept tested:
Question 10 of 10
Objective 1.1 Understand cybersecurity concepts Security Principles (24%)

A developer is correctly authenticated to a source-control platform and belongs to the engineering group. A new repository contains production signing keys and should be accessible only to release engineers. What is the BEST control decision?

Concept tested:
Locked preview

You are viewing today’s free 10. Unlock 190 more questions.

Unlock full bank
Daily sample Rotating practice Free daily questions are selected from a rotating sample set.
Pro bank Full access Unlock Pro to access the full question bank, Exam Mode, Practice Mode, and random tests.
ISC2 CC Pro $2.99 one-time

50 Exam Practice Test $1.99 one-time

A 50-question ISC2 CC PDF for short review sessions. Questions come first, then the answer review and explanations later in the file.

ISC2 Bundle $9.99 one-time

Unlock all 4 active ISC2 Bundle practice banks in one permanent purchase.

What’s includedISC2 CC, ISC2 SSCP, ISC2 CCSP, ISC2 CISSP
All Access $6.99/month

Unlock every active practice exam, bundle and path experience, Pro course and study content, and included downloads.

What’s includedEvery current and future active practice exam, All active bundle and career-path practice content, Pro course lessons, study content, and supported paid downloads

Choose an unlock option to continue. We will confirm your site email in one quick checkout step.

Secure checkout powered by Stripe. Source-backed questions. Not brain dumps. Checkout stays on this page and unlocks the same Pro builder on this practice page.

Purchase options

Unlock the full ISC2 CC bank.

Get the full bank, Exam Mode, Practice Mode, question sets, random tests, readiness tracking, saved box scores, and review tools for this exam.

The PDF versions keep questions first and move the answer review, explanations, and distractor notes to the back of the file.

200 verified exam-style questions Every choice explained Exam Mode and Practice Mode Question sets and random tests Readiness score and trends Previous test box scores

You've answered 0/10 questions in today's set.

Locked: 190 more questions in the full bank.

Locked: exam simulation mode, practice mode, readiness tracking, and saved review history.

Checkout stays on this page, so you can keep practicing, unlock the full bank, and start Exam Mode or Practice Mode when you are ready.

Cheat Sheets

7-day score keeper

Answer questions today and this will become a rolling 7-day scorecard.

Local history
Optional progress sync

Keep today’s practice moving

Guest progress saves automatically on this device. Add an email later when you want a magic link that keeps your daily ISC2 CC practice in sync across browsers.

Guest progress saves on this device automatically

Guest progress is available without an account.

Source-backed answer review

The free daily ISC2 CC set includes crawlable question text, answer choices, correct answer labels, objective mapping, and source links. Only the first SEO card includes answer explanations and any extra learning features. Pro-only bank questions stay locked; this section mirrors only the 10 free daily questions already shown on this page.

Question 1 A hospital is onboarding a new class of pharmacy technicians. Existing users were historically copied from a senior pharmacist account, producing excessive access. What should IAM governance do FIRST for the new role?

Answer choices

  1. A. Grant the same access as pharmacists but require MFA, for the described technical objective and its associated operational control requirements, as proposed.
  2. B. Define the pharmacy-technician role and its required entitlements from job responsibilities before provisioning accounts.
  3. C. Clone the least-active pharmacist account and remove permissions when complaints occur, under the documented operational and governance requirements.
  4. D. Provision no access and let each technician request individual permissions over time, within the described operational context.

Correct answer

Define the pharmacy-technician role and its required entitlements from job responsibilities before provisioning accounts.

Role definition should precede provisioning so access is based on assigned duties rather than inherited convenience. This creates a defensible baseline for least privilege and later reviews.

Wrong-answer review

  • A. Grant the same access as pharmacists but require MFA, for the described technical objective and its associated operational control requirements, as proposed.: Stronger authentication does not correct excessive authorization.
  • C. Clone the least-active pharmacist account and remove permissions when complaints occur, under the documented operational and governance requirements.: Cloning an unrelated senior role perpetuates unknown excess privilege.
  • D. Provision no access and let each technician request individual permissions over time, within the described operational context.: A default-deny start can be safe, but without role definition it creates inconsistent access and manual entitlement sprawl.

Extra learning features

Why candidates miss this

The choice of ‘Grant the same access as pharmacists but require MFA’ is tempting because MFA is a common security control. However, it doesn’t address the underlying issue of excessive access rights. The core problem is the inherited access, not a lack of authentication. Likely wrong answer: Grant the same access as pharmacists but require MFA. Review focus: NIST SP 800-53 Rev. 5: Security and Privacy Controls for Information Systems and Organizations

Interview question

Q: Given the hospital's need for pharmacy technician access, defining a role before provisioning is a foundational security practice. This approach minimizes the risk of inheriting excessive permissions and enables effective ongoing monitoring and adjustments. Strong answer: Role definition should precede provisioning so access is based on assigned duties rather than inherited convenience. This creates a defensible baseline for least privilege and later reviews.

  • role definition
  • least privilege
  • provisioning
  • account management

Caution: Do not restate the multiple-choice stem or ask the learner merely to name a product, rule, or term.

Objective/domain: Identity and Access Management (IAM) Concepts (20%)

Source: NIST SP 800-53 Rev. 5: Security and Privacy Controls for Information Systems and Organizations

Question 2 A hospital tablet fleet uses Bluetooth only during initial keyboard pairing; Bluetooth remains discoverable afterward. Which hardening action BEST reduces unnecessary wireless exposure?

Answer choices

  1. A. Change the tablet screen timeout, for the described technical objective and its associated operational control requirements, within this context.
  2. B. Increase Wi-Fi encryption strength, for the described technical objective and its associated operational control requirements, for the specified implementation requirement.
  3. C. Move the tablets to a different IP subnet, under the organization’s defined implementation and exception-management process.
  4. D. Disable or restrict Bluetooth discoverability and functionality after the approved pairing use is complete, for the stated scenario.

Correct answer

Disable or restrict Bluetooth discoverability and functionality after the approved pairing use is complete, for the stated scenario.

Objective/domain: Networking and Cloud Security Concepts (21.3%)

Source: NIST SP 800-121 Rev. 2: Guide to Bluetooth Security (Updated January 19, 2022)

Question 3 A company buys an IAM suite expecting it to solve access governance automatically. Role definitions, authoritative sources and approval owners remain undefined. What is the MOST likely result?

Answer choices

  1. A. The tool will infer perfect least-privilege roles from login history, for the described technical objective and its associated operational control requirements, as selected.
  2. B. The tool will automate inconsistent decisions because governance rules and lifecycle ownership must be defined before automation is reliable, for the described technical objective.
  3. C. All access risk transfers to the IAM vendor, for the described technical objective and its associated operational control requirements, as selected.
  4. D. MFA will compensate for undefined roles and approval ownership, for the stated identity and access management (iam) concepts (20%) requirement.

Correct answer

The tool will automate inconsistent decisions because governance rules and lifecycle ownership must be defined before automation is reliable, for the described technical objective.

Objective/domain: Identity and Access Management (IAM) Concepts (20%)

Source: NIST SP 800-53 Rev. 5: Security and Privacy Controls for Information Systems and Organizations

Question 4 A small healthcare provider adopts a broad cybersecurity framework. Many recommended outcomes apply, but its size, technology and regulatory obligations differ from those of a global enterprise. What is the BEST implementation approach?

Answer choices

  1. A. Use only the controls already supported by existing tools, for the stated security, delivery, and accountability requirements.
  2. B. Treat the framework as optional guidance and avoid documenting deviations, within the documented scope, ownership, and validation boundaries.
  3. C. Implement every possible control at the strongest setting regardless of operational impact, as the primary implementation for the described business requirement.
  4. D. Tailor the framework to the provider's risk, mission and obligations while preserving traceability to the framework outcomes, for this requirement.

Correct answer

Tailor the framework to the provider's risk, mission and obligations while preserving traceability to the framework outcomes, for this requirement.

Objective/domain: Security Governance (17.3%)

Source: The NIST Cybersecurity Framework (CSF) 2.0

Question 5 A facility posts clear surveillance notices and visible cameras at a restricted entrance, but the door itself has no access-control mechanism. Which statement BEST characterizes the control gap?

Answer choices

  1. A. The notices provide authorization because entrants were warned before entering, as the recommended implementation across the complete governed service lifecycle.
  2. B. The primary missing control is data encryption on systems inside the room, for the described technical objective and its associated operational control requirements, within this context.
  3. C. The cameras are sufficient because detective controls are equivalent to preventive controls, under the described security principles (24%) criteria.
  4. D. The visible monitoring may deter and detect, but an enforcing physical control is still needed to prevent unauthorized entry, within the security principles (24%) context.

Correct answer

The visible monitoring may deter and detect, but an enforcing physical control is still needed to prevent unauthorized entry, within the security principles (24%) context.

Question 6 A monitoring platform flags a database server for sending 600 GB to an internal backup appliance at 02:00. The volume is unusual for the server, but the backup team recently changed schedules. What is the BEST first triage action?

Answer choices

  1. A. Suppress the detection permanently because the destination is internal, under the documented operational and governance requirements.
  2. B. Immediately rebuild the database server from a clean image, under the organization’s defined implementation and exception-management process.
  3. C. Validate the event against asset context, approved changes, and related telemetry before declaring an incident, for the required operational result and control objective.
  4. D. Treat the data volume alone as proof of exfiltration and initiate public breach notification, under the documented operational and governance requirements.

Correct answer

Validate the event against asset context, approved changes, and related telemetry before declaring an incident, for the required operational result and control objective.

Objective/domain: Security Operations and Incident Response (17.3%)

Source: NIST SP 800-53 Rev. 5: Security and Privacy Controls for Information Systems and Organizations

Question 7 A cloud application has hundreds of short-lived workloads on the same virtual network. Static subnet rules cannot express which individual services should talk to each other. Which architecture is BEST suited to the requirement?

Answer choices

  1. A. Use a single VPN tunnel between all workloads, for the described technical objective and its associated operational control requirements, under this approach.
  2. B. Place every workload behind one internet-facing perimeter firewall and allow all internal traffic, for the described technical objective and its associated operational control requirements, for this scenario.
  3. C. Use workload-aware microsegmentation or policy enforcement that restricts east-west communication to defined service relationships, as the proposed networking and cloud security concepts (21.3%) approach.
  4. D. Assign each workload a public IP so flows are easier to identify, within the networking and cloud security concepts (21.3%) context.

Correct answer

Use workload-aware microsegmentation or policy enforcement that restricts east-west communication to defined service relationships, as the proposed networking and cloud security concepts (21.3%) approach.

Objective/domain: Networking and Cloud Security Concepts (21.3%)

Source: NIST SP 800-207: Zero Trust Architecture

Question 8 A research portal must allow access only when the user is a project member, the dataset classification is approved for that project, and the request comes from a managed device. Which design BEST expresses the decision?

Answer choices

  1. A. Authenticate the user with MFA and skip further authorization, within the defined security and accountability boundaries.
  2. B. Assign one static role to every researcher and allow all project datasets, under the documented operational and governance requirements.
  3. C. Use discretionary access controlled only by the dataset creator, under the proposed approach.
  4. D. Use policy that evaluates subject, resource and environmental attributes at access time, as configured.

Correct answer

Use policy that evaluates subject, resource and environmental attributes at access time, as configured.

Objective/domain: Identity and Access Management (IAM) Concepts (20%)

Source: NIST SP 800-53 Rev. 5: Security and Privacy Controls for Information Systems and Organizations

Question 9 A KRI tracks the percentage of critical third parties with expired security attestations. Leadership has defined 5% as the risk-tolerance threshold. The indicator reaches 11%. What is the BEST response?

Answer choices

  1. A. Escalate the threshold breach through the defined governance process and assess corrective actions or risk acceptance, for the required outcome.
  2. B. Delete suppliers with expired attestations from the metric, under the organization’s defined implementation and exception-management process.
  3. C. Wait until a supplier incident occurs before escalating, for the described technical objective and its associated operational control requirements, for the required outcome.
  4. D. Change the threshold to 12% so the dashboard returns to green, for the described technical objective and its associated operational control requirements.

Correct answer

Escalate the threshold breach through the defined governance process and assess corrective actions or risk acceptance, for the required outcome.

Question 10 A developer is correctly authenticated to a source-control platform and belongs to the engineering group. A new repository contains production signing keys and should be accessible only to release engineers. What is the BEST control decision?

Answer choices

  1. A. Permit read-only access because viewing a signing key cannot affect integrity, for the described technical objective and its associated operational control requirements.
  2. B. Rely on repository audit logs and investigate any misuse afterward, within the documented scope, ownership, and validation boundaries.
  3. C. Require the developer to reauthenticate before every repository read, for the required operational result and control objective.
  4. D. Authorize access based on the release-engineer role rather than treating engineering-group membership as sufficient, for the specified implementation requirement.

Correct answer

Authorize access based on the release-engineer role rather than treating engineering-group membership as sufficient, for the specified implementation requirement.

Where to go after the daily web set

How are ISC2 CC questions generated?

dotCreds builds ISC2 CC practice questions from public exam objectives and ISC2 exam and documentation references. The questions are written for realistic study practice, not copied from exam dumps.

How are explanations sourced?

Each question includes an explanation and, when available, a source link back to the provider documentation or reference used to validate the answer. That keeps the practice tied to study material you can actually review.

What score do I get?

The page tracks today's answered count and accuracy for the 10-question daily set, then saves a 7-day score history on this device so you can see your recent practice trend.

Why use this site?

The site is the fastest way to start ISC2 CC practice without installing anything. It is built for daily recall, quick weak-topic discovery, and source-backed explanations you can review immediately.