Hello, you are using an old browser that's unsafe and no longer supported. Please consider updating your browser to a newer version, or downloading a modern browser.

Free Practice Test

Free Certified in Cybersecurity Practice Test 2026 (CC)

Check your readiness for the ISC2 Certified in Cybersecurity (CC) exam with 50 exam-style questions across all five domains of the outline effective September 1, 2026, each with an instant explanation. Free to take, with a 60-minute timer that matches the pace of the real exam, and retake it as often as you want.

25 or 50 Questions 60-Minute Timer 5 CC Domains Every Answer Explained New Sample Each Retake

New to Certified in Cybersecurity? Learn more about the certification →

Start Your Free Practice Test

Enter your details, then choose a 25-question Quick Test or the full 50-question, 60-minute practice test.

First Name
Last Name
Phone
About This Test

Free ISC2 Certified in Cybersecurity (CC) Practice Test

This free ISC2 Certified in Cybersecurity practice test checks your readiness for the CC exam with 50 exam-style questions across all five domains of the outline effective September 1, 2026, each with an explanation for every answer choice, on a 60-minute timer that mirrors the pace of the real two-hour exam. Built by Training Camp, an ISC2 Official Training Partner, and drawn from the same objectives we teach in our Certified in Cybersecurity Boot Camp. New to the certification? Learn more about the ISC2 CC.

What's on the ISC2 Certified in Cybersecurity (CC) exam?

ISC2 refreshed the CC outline on September 1, 2026, and this test follows the new version. It has five weighted domains: Security Principles (24%), Security Governance (17.3%), Identity and Access Management (IAM) Concepts (20%), Networking and Cloud Security Concepts (21.3%), and Security Operations and Incident Response (17.3%). The real exam uses computerized adaptive testing, so you answer between 100 and 125 questions in 2 hours, and you need 700 out of 1000 points to pass. Items are multiple choice plus advanced item types, and foundational AI security concepts are woven through every domain rather than sitting in a domain of their own.

There is no experience requirement. ISC2 designed the CC as an entry point for career changers, students and IT staff moving into security, and the exam tests whether you can apply foundational concepts to a short scenario rather than whether you can configure anything. If you studied under the previous outline, note that Security Governance is now its own domain (it absorbed business continuity and disaster recovery along with security awareness), Access Controls became Identity and Access Management, and Incident Response moved into Security Operations and Incident Response next to new material on threat actors, threat intelligence and security testing.

How to use this practice test

Take it once without notes to get an honest baseline, then read the explanation for every answer, including the ones you got right. The incorrect-choice explanations are where the distinctions the CC likes to test (authentication versus authorization, a policy versus a standard, containment versus eradication) get spelled out. Study your weakest domain and retake the test in a week. The 60-minute timer over 50 questions keeps you honest about pacing: the real exam gives you 2 hours for up to 125 adaptive questions, so practice deciding in about a minute and moving on rather than second-guessing.

Domains Covered · CC

Security Principles24%

CIA triad, AAA, privacy, risk terms, policies and standards, control types, and ethics.

Security Governance17.3%

GRC planning, business continuity and disaster recovery, security awareness, and metrics.

Identity and Access Management (IAM) Concepts20%

Identity life cycle, authentication factors, least privilege, separation of duties, and access models.

Networking and Cloud Security Concepts21.3%

OSI and TCP/IP, ports, network threats, segmentation, VPNs, and cloud service models.

Security Operations and Incident Response17.3%

Data handling and encryption, logging and triage, threat actors, incident response, hardening, and security testing.

Try Before You Start

Sample Certified in Cybersecurity Practice Questions

Four questions from the bank, one per domain, with the reasoning behind every answer. The full test has 50.

Question 1 Security Principles

A hospital discovers that patient records were altered by an unauthorized script overnight. Nobody outside the organization saw the records and the system stayed online the whole time. Which element of the CIA triad was violated?

  1. Confidentiality
  2. Integrity Correct
  3. Availability
  4. Authentication
Why this is the best answer

Correct. Integrity means data is accurate and has not been altered without authorization. Records being changed by an unauthorized script is a direct integrity violation, even though nothing was disclosed and nothing went offline.

Question 2 Networking and Cloud Security Concepts

Which security design principle layers multiple independent controls so that the failure of any one control does not expose the protected asset?

  1. Separation of duties
  2. Defense in depth Correct
  3. Least privilege
  4. Zero trust
Why this is the best answer

Correct. Defense in depth, also called layered defense, places several independent controls in an attacker's path, such as a firewall, MFA, encryption and monitoring, so a single failure does not compromise the asset.

Question 3 Security Governance

Which of the following terms describes a measurement with a defined threshold that warns leadership when the organization's risk exposure is rising?

  1. Key performance indicator (KPI)
  2. Recovery time objective (RTO)
  3. Risk register
  4. Key risk indicator (KRI) Correct
Why this is the best answer

Correct. A key risk indicator is a metric tied to a threshold, such as the percentage of critical patches overdue, that signals when risk exposure is approaching a level leadership will not accept. KRIs feed the dashboards and scorecards used in governance reporting.

Question 4 Security Operations and Incident Response

Which of the following roles is responsible for deciding how a data set is classified, who may access it and how long it is retained?

  1. Data custodian
  2. Data owner Correct
  3. Data user
  4. Data processor
Why this is the best answer

Correct. The data owner, sometimes called the data controller, is the business role accountable for a data set. The owner assigns its classification, approves who may access it and sets its retention period, and the custodian implements those decisions.

Every one of the 50 questions works this way: an explanation for the right answer and for the one you picked, so a wrong answer teaches you something. Questions last reviewed against the current ISC2 Certified in Cybersecurity (CC) objectives.

Certified in Cybersecurity Practice Test

Frequently Asked Questions

Quick answers about the test, the ISC2 Certified in Cybersecurity (CC) exam, and how to prepare.

Is this ISC2 CC practice test free?

Yes. Training Camp's Certified in Cybersecurity practice test is free to take. You get 50 exam-style questions across all five domains of the 2026 CC outline, with a written explanation for every answer choice.

How does this practice test work?

It is 50 multiple-choice scenario questions drawn from all five CC domains, with an instant explanation after each answer and a 60-minute timer that mirrors the pace of the real exam. You can retake it as often as you want. Treat it as a readiness check rather than a substitute for full preparation.

How many questions are on the real ISC2 CC exam?

The CC exam uses computerized adaptive testing, so you answer between 100 and 125 questions in 2 hours. The item count varies because the exam stops once it is confident about your ability level.

What score do I need to pass the ISC2 CC exam?

You need 700 out of 1000 points. Because the exam is adaptive and scaled, 700 does not mean answering 70 percent of the questions correctly.

What domains does the ISC2 CC exam cover?

Under the outline effective September 1, 2026, the five domains are Security Principles (24%), Security Governance (17.3%), Identity and Access Management (IAM) Concepts (20%), Networking and Cloud Security Concepts (21.3%), and Security Operations and Incident Response (17.3%). Foundational AI security concepts appear across all five.

How hard is the ISC2 CC exam?

The CC is an entry-level certification with no experience requirement, easier than the SSCP or CISSP, but it is scenario-based rather than pure memorization. Most candidates find the identity and access models and the network security terminology the hardest parts, and the adaptive format means it feels demanding the whole way through.

Do I need experience to take the ISC2 CC?

No. ISC2 designed the CC for people starting out, so there is no work experience requirement and no prerequisite certification. Basic IT familiarity helps, but the exam assumes you are learning security concepts for the first time.

How should you prepare for the ISC2 CC exam?

Start with the ISC2 exam outline and work through each domain, then use practice questions like these to find your weak areas. If you want a structured path with an instructor and your exam voucher included, our three-day Certified in Cybersecurity Boot Camp covers all five domains of the 2026 outline.