ISC2 CC Practice Questions (Free Sample)

Free practice sample

Fifteen original CC practice questions, unlocked with no signup and instant scoring. The sample draws proportionally across all five domains of the ISC2 exam outline, weighted the way the exam is weighted — heaviest in Security Principles at 26% and Network Security at 24%, lightest in Business Continuity, Disaster Recovery and Incident Response Concepts at 10% — so the mix here reflects the shape of the real exam rather than a single topic slice.

CC is an entry-level exam, and that shapes what its hard questions look like. They are rarely deep; they are precise. The exam asks you to tell apart terms that live next to each other — identification versus authentication versus authorization, RTO versus RPO, IDS versus IPS, DAC versus MAC versus RBAC, containment versus eradication — and to pick the control that belongs to the category the question named rather than the one that merely sounds strongest. The October 2025 outline adds an AI thread that runs through all five domains, so expect model poisoning framed as an integrity problem and pasting confidential data into a public chatbot framed as a confidentiality one. Every explanation here names the winning answer and the near-miss it beats, so a review pass teaches the distinction rather than a letter to memorise.

Outline dates. This sample targets the exam outline that took effect October 1, 2025, in which ISC2 wove foundational AI security through all five domains — data poisoning, AI-generated phishing and voice cloning, the security of the AI workspace, and acceptable use policies that now cover generative AI tools. ISC2 has announced a refreshed outline effective September 1, 2026; if your test date falls after that, pull the updated outline from isc2.org before you finalize a study plan.

Vendor · ISC2 Exam · CC CAT format Items · 100–125 Duration · 2 hours Pass · 700 / 1000 scaled Pearson VUE 5 domains No experience required $199 + $50 AMF
Security Principles Domain 1 · 26%
Business Continuity, Disaster Recovery & Incident Response Concepts Domain 2 · 10%
Access Controls Concepts Domain 3 · 22%
Network Security Domain 4 · 24%
Security Operations Domain 5 · 18%

Frequently asked questions about CC

How many questions are on the actual CC exam?

There is no fixed number. CC is delivered as a computerized adaptive test at Pearson VUE, so the engine serves between 100 and 125 items over two hours and adjusts difficulty as you answer. Confirm current logistics at isc2.org when you book, since ISC2 sets the format and may change it.

What score do I need to pass CC?

700 out of 1000 on ISC2’s scaled scoring. That is not a raw 70%, because under adaptive delivery your score reflects the difficulty of the items you answered correctly rather than a simple count of right answers. The Certifym practice pass mark is set at 70% as an honest raw-score equivalent, and because every set is weighted to the official domain percentages, clearing it means genuine coverage across all five domains rather than luck in the heavy ones.

Which domains should I spend the most time on?

Security Principles is the single heaviest domain at 26%, and it is also the frame that decides the right answer in questions nominally about other domains — the CIA triad, the risk treatment options, and the technical/administrative/physical control categories are what most CC distractors are sorted by. Network Security follows at 24% and is the most technical domain on the exam, so career-changers without an IT background should budget the most time there. Access Controls Concepts is 22% and Security Operations 18%. Business Continuity, Disaster Recovery and Incident Response Concepts is lightest at 10%, but it is nearly pure definitions — RTO versus RPO, hot/warm/cold sites, the incident response lifecycle in order — which makes it the cheapest ten percent on the exam. Do not leave it on the table.

Do I need work experience to take the CC exam?

No. CC requires no work experience, which is the whole point of the credential — it is built for people stepping into a first security role, changing careers, or finishing a degree. That makes it unusual among ISC2 certifications, where the flagship credentials gate on years of documented experience. Exam and certification fees, eligibility terms, and the annual maintenance fee are set by ISC2, so confirm the current terms on isc2.org before you register.

What did the October 2025 outline change, and what happens in September 2026?

The defining change in the current outline is AI, woven through all five domains rather than confined to one: data poisoning as an integrity attack on machine-learning models, AI-generated phishing and voice cloning as network threats, the security of the AI workspace — the data-leakage risk when employees paste confidential information into public chatbots — and the governance expectation that acceptable use policies now cover generative AI tools. Material written before October 2025 still covers the classic fundamentals well but gives you nothing on that thread. ISC2 has announced a further refreshed outline effective September 1, 2026, so if you are testing after that date, download the new outline before you plan a schedule around any weighting.

Should I take CC or go straight to SSCP?

CC is the entry point and SSCP is the next rung. Passing CC starts an ISC2 record that compounds as you move up through SSCP, CGRC, CCSP, and eventually CISSP, and because CC requires no experience it is the one you can sit before you have a security job rather than after. SSCP is a practitioner credential aimed at people already doing the work. If you are still building the vocabulary — access control models, the OSI layers, the incident response lifecycle — CC is where that vocabulary is tested, and it is the cleaner first step.

How is this free sample different from the full Certifym bank?

The sample is a fixed 15-question set spread across the five domains at outline proportions, with no account needed. Members get ten full-length Certified in Cybersecurity practice exams with full explanations, study mode, and domain drills; each full-length attempt is a 100-question timed simulation stratified to the official weights — 26 on Security Principles, 24 on Network Security, 22 on Access Controls, 18 on Security Operations, and 10 on BC/DR/IR — against a 120-minute clock. New practice content is added every week and your progress is saved when you join. None of the member-bank items appear in this sample.

Is Certifym affiliated with ISC2?

No. Certifym.net is operated by Certifym Exam Services, LLC and is not affiliated with, endorsed by, or sponsored by ISC2, Inc. All questions and explanations on this site are original content produced by Certifym and are not sourced from actual ISC2 exam questions.

Trademark notice & independence. Certifym.net is operated by Certifym Exam Services, LLC and is not affiliated with, endorsed by, or sponsored by ISC2, Inc. ISC2®, CC®, SSCP®, and CISSP® are registered marks of ISC2, Inc., used here only to identify the certification these study materials are intended for. The CC exam outline and its domain structure are the property of ISC2, Inc.; download the current outline directly from isc2.org.

All practice questions, answers, and explanations on this page are original content produced by Certifym Exam Services, LLC. They are not actual ISC2 examination questions and are not represented as such. Exam format, domain weights, and eligibility criteria are set by ISC2 and may change — including the refreshed exam outline effective September 1, 2026; verify current details at isc2.org before scheduling.