Certified in Cybersecurity Essentials (CC-aligned) Practice Exams

Three 50-question entry-level security practice papers across security principles, business continuity and incident response, access controls, network security and security operations.

3 practice papers · 150 questions · 60 minutes each · pass mark 70% · ₹196 for all papers

What the CC practice exams cover

Written from the published ISC2 Certified in Cybersecurity (CC) exam outline domains.

Practice papers

Free CC sample questions

Sample question 1 (Security principles)

A healthcare clinic identifies that patients could be harmed if prescription records were altered by an unauthorized insider. The security team rates the likelihood of this event as low but the potential impact as very high. Which risk management step is the team performing when it combines likelihood and impact into an overall risk rating?

  1. Risk identification
  2. Risk assessment
  3. Risk treatment
  4. Risk tolerance

Answer: B. Risk assessment

Option B is correct because risk assessment is the step where identified risks are evaluated by combining likelihood and impact to produce an overall risk rating or priority. Option A is incorrect because risk identification focuses on discovering and cataloging risks, not on evaluating their severity. Option C is incorrect because risk treatment involves selecting responses such as mitigate, transfer, avoid, or accept after assessment is done. Option D is incorrect because risk tolerance describes the amount of risk an organization is willing to bear, not the act of rating a specific risk.

Sample question 2 (Continuity and incident response)

A regional bank configures its customer transaction database to perform a full backup at midnight and incremental backups every three hours throughout the day. The most recent incremental backup completed at 3:00 PM. A hardware failure corrupts the database at 4:45 PM. In this scenario, what is the recovery point objective that has been achieved, and what does it indicate?

  1. An RPO of three hours, meaning the bank can restore the database to full operation within three hours of the failure.
  2. An RPO of one hour and forty-five minutes, meaning the database can tolerate being offline for that duration.
  3. An RPO of three hours, meaning the bank could lose up to three hours of transaction data since the last successful backup.
  4. An RPO of twenty-four hours, meaning data loss is limited to one full backup cycle.

Answer: C. An RPO of three hours, meaning the bank could lose up to three hours of transaction data since the last successful backup.

Option C is correct because the recovery point objective (RPO) represents the maximum amount of data the organization is willing to lose, measured in time. With backups every three hours and the last backup at 3:00 PM, up to three hours of transactions could be lost. Option A is incorrect because RPO is not the time needed to restore systems; that is the RTO. Option B is incorrect because RPO does not describe how long a system can be down. Option D is incorrect because RPO is not related to the interval between full backups only; it reflects the maximum acceptable data loss gap, which here is three hours between incremental backups.

Sample question 3 (Access control concepts)

A new employee presents a photo ID at the IT help desk and receives a username and a temporary password. The employee enters the username and password at the login screen, and the system checks the credentials against a directory. The system then determines which network folders the employee may open and records each file access in an audit log. Which sequence correctly identifies the four access control processes in the order they occur in this scenario?

  1. Identification, authorization, authentication, accounting
  2. Identification, authentication, authorization, accounting
  3. Authentication, identification, accounting, authorization
  4. Authorization, authentication, identification, accounting
  5. Authentication, accounting, identification, authorization

Answer: B. Identification, authentication, authorization, accounting

Option B is correct because presenting the photo ID and receiving a username is identification, entering the password and having it checked is authentication, determining which folders may be opened is authorization, and writing each file access to an audit log is accounting. Option A is incorrect because it swaps authorization and accounting, placing audit logging before the access decision. Option C is incorrect because it treats receiving the username as authentication rather than identification. Option D is incorrect because it conflates authentication with authorization and omits the distinct accounting step. Option E is incorrect because it reverses identification and authentication and mislabels the audit activity as authorization.

Sample question 4 (Network security)

A security analyst notices that an external attacker is sending packets into the corporate network with a source IP address that belongs to an internal trusted server, causing downstream devices to accept and forward the traffic. Which type of network threat is being carried out?

  1. Spoofing
  2. Denial of service
  3. Sniffing
  4. Man-in-the-middle

Answer: A. Spoofing

Option A is correct because IP spoofing involves forging the source address in packets so they appear to originate from a trusted host. Option B is incorrect because a denial-of-service attack aims to overwhelm or disrupt service availability, not to impersonate a trusted host. Option C is incorrect because sniffing passively captures traffic rather than actively forging source addresses. Option D is incorrect because a man-in-the-middle attack intercepts and potentially alters communication between two parties, which is a different technique from source address impersonation.

Sample question 5 (Security operations)

A software vendor publishes a large service pack on its public website and wants customers to be able to verify that the file has not been altered since it was posted. Which cryptographic technique should the vendor use?

  1. Symmetric encryption with AES
  2. Asymmetric encryption with RSA
  3. Generating an MD5 or SHA-256 hash of the file
  4. Applying a digital certificate to the web server

Answer: C. Generating an MD5 or SHA-256 hash of the file

Hashing generates a fixed-size fingerprint of a file that changes if even a single bit is altered, allowing customers to verify file integrity. Option A and Option B provide confidentiality, not integrity verification. Option D authenticates the server to the client but does not verify the downloaded file.

About these papers

Unofficial practice material. Every question is original, written from the vendor's publicly published exam objectives, and no real exam item is reproduced or paraphrased. This paper is not affiliated with, endorsed by, sponsored by or certified by the certification owner, and passing it does not confer any certification.

More certification practice exams