dc dotCreds
ISC2 Certified in Cybersecurity Practice Test

ISC2 CC Practice Test

Start today’s free 10-question ISC2 CC set with source-backed explanations, local progress, and a fresh rotation every morning.

10 Free Daily Questions Source-backed Explanations 200 Verified Questions

Questions updated at Aug 22, 2026, 8:53 PM CDT

Go Pro - One Time Unlock

Unlock the full ISC2 CC bank

200 verified questions Exam Mode Practice Mode Detailed explanations Weak-area review No subscription - one-time unlock

Get the complete source-backed bank with Interview Questions, the full Study Guide, full Course Notes, detailed explanations, weak-area review, and exam-style practice.

Interview Questions Full Study Guide Full Course Notes Exam Mode Practice Mode Guided Course Detailed explanations Weak-area review No subscription
$4.99 One-time payment
See bundle and PDF options

We will confirm your site email in one quick checkout step.

Why DotCreds?

Practice with explanations that teach.

Source links for every answer Every wrong answer explained Guided Course included Practice and Exam Mode Weak-area tracking Same verified bank across web practice

What you get with free practice

10 Free Questions Daily Fresh set every day from the live bank
Detailed Explanations Learn with clear source-backed answers
Track Your Progress Daily history and performance insights
Upgrade Anytime Unlock the full bank when you are ready
Today's 10 ISC2 CC questions

Use this ISC2 CC practice test to review ISC2 Certified in Cybersecurity. Questions rotate daily and each answer links back to the source used to write it.

Today’s Set
10 questions
Rotates at 10:00 AM local time
Progress
0/10
Answered on this page
Accuracy
0%
Loading countdown…

200 verified questions are in the live bank. Free daily questions are selected from a rotating sample set. Unlock Pro to access the full question bank.

Preparing today’s free questions... Ordering the final locked-bank set before showing the practice cards.
Question 1 of 10
Objective Understand security awareness Security Governance (17.3%)

Quarterly phishing simulations show employees correctly identify suspicious messages but still enter credentials when a message appears to come from a senior executive. Which training change is MOST likely to address the measured weakness?

Concept tested:
Question 2 of 10
Objective Understand risk management concepts Security Principles (24%)

An organization accepts a third-party service risk because the provider has a required certification and quarterly failover tests. Which ongoing activity BEST supports the risk-management lifecycle?

Concept tested:
Question 3 of 10
Objective Understand data security Security Operations and Incident Response (17.3%)

A storage array containing highly sensitive records is being repurposed. The vendor offers a built-in sanitize command. The asset team plans to run the command and immediately return the media to service with no verification. Which change is MOST important?

Concept tested:
Question 4 of 10
Objective Understand network security Networking and Cloud Security Concepts (21.3%)

Users cannot reach an application by hostname, but they can reach the same server by IP and port. Other applications are working. Which component is the BEST first focus?

Concept tested:
Question 5 of 10
Objective Understand logical access controls Identity and Access Management (IAM) Concepts (20%)

A company creates a 'Senior Analyst' role by inheriting every permission from 'Analyst' and adding ten more. One inherited permission is no longer needed by senior analysts and exposes payroll data. What is the BEST correction?

Concept tested:
Question 6 of 10
Objective Understand Incident Response (IR) Security Operations and Incident Response (17.3%)

After ransomware containment, a file server is restored from backup and starts normally. The operations team wants to return it to production immediately. Which additional step is MOST important before declaring recovery complete?

Concept tested:
Question 7 of 10
Objective Understand network security architecture Networking and Cloud Security Concepts (21.3%)

A company VPN authenticates a user once, then grants broad access to every internal subnet. Which redesign is MOST consistent with zero trust?

Concept tested:
Question 8 of 10
Objective Understand identity life cycle management Identity and Access Management (IAM) Concepts (20%)

A project requires a developer to administer a production service for three days. The manager approves the need. Which provisioning control BEST limits lifecycle risk?

Concept tested:
Question 9 of 10
Objective Measure cybersecurity effectiveness Security Governance (17.3%)

A KRI tracks the percentage of critical third parties with expired security attestations. Leadership has defined 5% as the risk-tolerance threshold. The indicator reaches 11%. What is the BEST response?

Concept tested:
Question 10 of 10
Objective Maintain professional and ethical conduct Security Principles (24%)

An organization has a policy requiring critical patches within seven days. The security manager publishes the policy, funds the patching service and assigns owners, then reviews weekly evidence that systems actually meet the requirement. Which activity BEST demonstrates due diligence rather than merely due care?

Concept tested:
Locked preview

You are viewing today’s free 10. Unlock 190 more questions.

Unlock full bank
Daily sample Rotating practice Free daily questions are selected from a rotating sample set.
Pro bank Full access Unlock Pro to access the full question bank, Exam Mode, Practice Mode, and random tests.
ISC2 CC Pro $4.99 one-time

Unlock all 200 ISC2 CC questions, explanations, review tools, and exam-style practice.

50 Exam Practice Test $1.99 one-time

A 50-question ISC2 CC PDF for short review sessions. Questions come first, then the answer review and explanations later in the file.

Choose an unlock option to continue. We will confirm your site email in one quick checkout step.

Secure checkout powered by Stripe. Source-backed questions. Not brain dumps. Checkout stays on this page and unlocks the same Pro builder on this practice page.

Purchase options

Unlock the full ISC2 CC bank.

Get the full bank, Exam Mode, Practice Mode, question sets, random tests, readiness tracking, saved box scores, and review tools for this exam.

The PDF versions keep questions first and move the answer review, explanations, and distractor notes to the back of the file.

200 verified exam-style questions Every choice explained Exam Mode and Practice Mode Question sets and random tests Readiness score and trends Previous test box scores

You've answered 0/10 questions in today's set.

Locked: 190 more questions in the full bank.

Locked: exam simulation mode, practice mode, readiness tracking, and saved review history.

Checkout stays on this page, so you can keep practicing, unlock the full bank, and start Exam Mode or Practice Mode when you are ready.

Cheat Sheets

7-day score keeper

Answer questions today and this will become a rolling 7-day scorecard.

Local history
Optional progress sync

Keep today’s practice moving

Guest progress saves automatically on this device. Add an email later when you want a magic link that keeps your daily ISC2 CC practice in sync across browsers.

Guest progress saves on this device automatically

Guest progress is available without an account.

Source-backed answer review

The free daily ISC2 CC set includes crawlable question text, answer choices, correct answer labels, objective mapping, and source links. Only the first SEO card includes answer explanations and any extra learning features. Pro-only bank questions stay locked; this section mirrors only the 10 free daily questions already shown on this page.

Question 1 Quarterly phishing simulations show employees correctly identify suspicious messages but still enter credentials when a message appears to come from a senior executive. Which training change is MOST likely to address the measured weakness?

Answer choices

  1. A. Increase the length of the annual password-policy presentation.
  2. B. Stop simulations because employees already know what phishing looks like.
  3. C. Add realistic authority-themed scenarios and practice the expected verification/reporting behavior for urgent executive requests.
  4. D. Require employees to memorize more examples of malware file extensions.

Correct answer

Add realistic authority-themed scenarios and practice the expected verification/reporting behavior for urgent executive requests.

The measurement shows a specific behavioral gap: authority and urgency override knowledge. Role-relevant practice should target that behavior rather than repeat generic definitions.

Wrong-answer review

  • A. Increase the length of the annual password-policy presentation.: Longer generic content does not directly address the authority-themed social-engineering weakness shown by the data.
  • B. Stop simulations because employees already know what phishing looks like.: Recognition without safe behavior means the program has not yet achieved its risk-reduction goal.
  • D. Require employees to memorize more examples of malware file extensions.: Malware trivia is not the behavior failing in the simulation.

Extra learning features

Why candidates miss this

The distractor ‘Stop simulations because employees already know what phishing looks like.’ is tempting because it suggests a simple solution. However, this ignores the critical need for active practice and reinforcement of learned behaviors. The decisive clue is the simulation’s focus on authority-themed scenarios, highlighting the behavioral gap that requires targeted training. Likely wrong answer: Stop simulations because employees already know what phishing looks like. Review focus: NIST SP 800-50 Rev. 1: Building a Cybersecurity and Privacy Learning Program

Objective/domain: Security Governance (17.3%)

Source: NIST SP 800-50 Rev. 1: Building a Cybersecurity and Privacy Learning Program

Question 2 An organization accepts a third-party service risk because the provider has a required certification and quarterly failover tests. Which ongoing activity BEST supports the risk-management lifecycle?

Answer choices

  1. A. Treat the certification as permanent proof that provider risk is unchanged.
  2. B. Replace internal monitoring with the provider's marketing status page.
  3. C. Repeat the original assessment only after an actual outage occurs.
  4. D. Monitor whether the certification, failover evidence and other acceptance assumptions remain valid, and reassess when they change.

Correct answer

Monitor whether the certification, failover evidence and other acceptance assumptions remain valid, and reassess when they change.

Objective/domain: Security Principles (24%)

Source: NIST SP 800-30 Rev. 1: Guide for Conducting Risk Assessments

Question 3 A storage array containing highly sensitive records is being repurposed. The vendor offers a built-in sanitize command. The asset team plans to run the command and immediately return the media to service with no verification. Which change is MOST important?

Answer choices

  1. A. Delete the filesystem metadata and rely on normal reuse to overwrite the blocks over time.
  2. B. Encrypt the remaining data after the sanitize command so any missed records become less visible.
  3. C. Select the sanitization technique based on data sensitivity and media characteristics, then validate that the sanitization outcome was effective.
  4. D. Perform three overwrite passes on every type of storage because a fixed pass count is universally sufficient.

Correct answer

Select the sanitization technique based on data sensitivity and media characteristics, then validate that the sanitization outcome was effective.

Objective/domain: Security Operations and Incident Response (17.3%)

Source: NIST SP 800-88 Rev. 2: Guidelines for Media Sanitization

Question 4 Users cannot reach an application by hostname, but they can reach the same server by IP and port. Other applications are working. Which component is the BEST first focus?

Answer choices

  1. A. The application's TCP listener.
  2. B. The user's disk-encryption configuration.
  3. C. Name-resolution configuration and DNS path for the affected hostname.
  4. D. The physical switch uplink to the server.

Correct answer

Name-resolution configuration and DNS path for the affected hostname.

Objective/domain: Networking and Cloud Security Concepts (21.3%)

Source: IETF RFC 1034: Domain Names — Concepts and Facilities

Question 5 A company creates a 'Senior Analyst' role by inheriting every permission from 'Analyst' and adding ten more. One inherited permission is no longer needed by senior analysts and exposes payroll data. What is the BEST correction?

Answer choices

  1. A. Require MFA only when senior analysts open payroll records.
  2. B. Remove or override the unnecessary inherited entitlement so the senior role reflects actual job need rather than assuming inheritance is always safe.
  3. C. Create a shared payroll account for the analysts who occasionally need the data.
  4. D. Keep the permission because senior roles should always be supersets of junior roles.

Correct answer

Remove or override the unnecessary inherited entitlement so the senior role reflects actual job need rather than assuming inheritance is always safe.

Objective/domain: Identity and Access Management (IAM) Concepts (20%)

Source: NIST SP 800-53 Rev. 5: Security and Privacy Controls for Information Systems and Organizations

Question 6 After ransomware containment, a file server is restored from backup and starts normally. The operations team wants to return it to production immediately. Which additional step is MOST important before declaring recovery complete?

Answer choices

  1. A. Verify the restored service is dependable and that the conditions that enabled the incident have been addressed or acceptably mitigated.
  2. B. Disable monitoring temporarily so recovery traffic does not generate alerts.
  3. C. Delete all incident records so users are not concerned about the prior outage.
  4. D. Restore every system from the same backup regardless of whether it was affected.

Correct answer

Verify the restored service is dependable and that the conditions that enabled the incident have been addressed or acceptably mitigated.

Objective/domain: Security Operations and Incident Response (17.3%)

Source: NIST SP 800-61 Rev. 3: Incident Response Recommendations and Considerations for Cybersecurity Risk Management

Question 7 A company VPN authenticates a user once, then grants broad access to every internal subnet. Which redesign is MOST consistent with zero trust?

Answer choices

  1. A. Use a longer VPN session timeout while preserving broad internal access.
  2. B. Issue every user a static internal IP and allow that IP everywhere.
  3. C. Grant access to specific resources according to explicit policy and continuously reevaluate relevant context instead of providing broad network trust after VPN login.
  4. D. Add a second VPN concentrator for redundancy.

Correct answer

Grant access to specific resources according to explicit policy and continuously reevaluate relevant context instead of providing broad network trust after VPN login.

Objective/domain: Networking and Cloud Security Concepts (21.3%)

Source: NIST SP 800-207: Zero Trust Architecture

Question 8 A project requires a developer to administer a production service for three days. The manager approves the need. Which provisioning control BEST limits lifecycle risk?

Answer choices

  1. A. Grant time-bound privileged access that expires automatically and is reviewed if extension is requested.
  2. B. Use the manager's administrator account for the three days.
  3. C. Create a permanent new role for the one-off project.
  4. D. Grant permanent privilege and add a calendar reminder to remove it.

Correct answer

Grant time-bound privileged access that expires automatically and is reviewed if extension is requested.

Objective/domain: Identity and Access Management (IAM) Concepts (20%)

Source: NIST SP 800-53 Rev. 5: Security and Privacy Controls for Information Systems and Organizations

Question 9 A KRI tracks the percentage of critical third parties with expired security attestations. Leadership has defined 5% as the risk-tolerance threshold. The indicator reaches 11%. What is the BEST response?

Answer choices

  1. A. Escalate the threshold breach through the defined governance process and assess corrective actions or risk acceptance.
  2. B. Delete suppliers with expired attestations from the metric.
  3. C. Wait until a supplier incident occurs before escalating.
  4. D. Change the threshold to 12% so the dashboard returns to green.

Correct answer

Escalate the threshold breach through the defined governance process and assess corrective actions or risk acceptance.

Question 10 An organization has a policy requiring critical patches within seven days. The security manager publishes the policy, funds the patching service and assigns owners, then reviews weekly evidence that systems actually meet the requirement. Which activity BEST demonstrates due diligence rather than merely due care?

Answer choices

  1. A. Reviewing evidence over time to verify that the patching process continues to operate as intended.
  2. B. Publishing the seven-day requirement.
  3. C. Assigning system owners to the process.
  4. D. Purchasing the patching platform.

Correct answer

Reviewing evidence over time to verify that the patching process continues to operate as intended.

Objective/domain: Security Principles (24%)

Source: ISC2 CISSP Glossary — Due Care and Due Diligence

Where to go after the daily web set

How are ISC2 CC questions generated?

dotCreds builds ISC2 CC practice questions from public exam objectives and ISC2 exam and documentation references. The questions are written for realistic study practice, not copied from exam dumps.

How are explanations sourced?

Each question includes an explanation and, when available, a source link back to the provider documentation or reference used to validate the answer. That keeps the practice tied to study material you can actually review.

What score do I get?

The page tracks today's answered count and accuracy for the 10-question daily set, then saves a 7-day score history on this device so you can see your recent practice trend.

Why use this site?

The site is the fastest way to start ISC2 CC practice without installing anything. It is built for daily recall, quick weak-topic discovery, and source-backed explanations you can review immediately.