Start Your Free Practice Test
Enter your details, then choose a 25-question Quick Test or the full 50-question, 60-minute practice test.
Hello, you are using an old browser that's unsafe and no longer supported. Please consider updating your browser to a newer version, or downloading a modern browser.
Check your readiness for the ISC2 Certified in Cybersecurity (CC) exam with 50 exam-style questions across all five domains of the outline effective September 1, 2026, each with an instant explanation. Free to take, with a 60-minute timer that matches the pace of the real exam, and retake it as often as you want.
New to Certified in Cybersecurity? Learn more about the certification →
Enter your details, then choose a 25-question Quick Test or the full 50-question, 60-minute practice test.
This free ISC2 Certified in Cybersecurity practice test checks your readiness for the CC exam with 50 exam-style questions across all five domains of the outline effective September 1, 2026, each with an explanation for every answer choice, on a 60-minute timer that mirrors the pace of the real two-hour exam. Built by Training Camp, an ISC2 Official Training Partner, and drawn from the same objectives we teach in our Certified in Cybersecurity Boot Camp. New to the certification? Learn more about the ISC2 CC.
ISC2 refreshed the CC outline on September 1, 2026, and this test follows the new version. It has five weighted domains: Security Principles (24%), Security Governance (17.3%), Identity and Access Management (IAM) Concepts (20%), Networking and Cloud Security Concepts (21.3%), and Security Operations and Incident Response (17.3%). The real exam uses computerized adaptive testing, so you answer between 100 and 125 questions in 2 hours, and you need 700 out of 1000 points to pass. Items are multiple choice plus advanced item types, and foundational AI security concepts are woven through every domain rather than sitting in a domain of their own.
There is no experience requirement. ISC2 designed the CC as an entry point for career changers, students and IT staff moving into security, and the exam tests whether you can apply foundational concepts to a short scenario rather than whether you can configure anything. If you studied under the previous outline, note that Security Governance is now its own domain (it absorbed business continuity and disaster recovery along with security awareness), Access Controls became Identity and Access Management, and Incident Response moved into Security Operations and Incident Response next to new material on threat actors, threat intelligence and security testing.
Take it once without notes to get an honest baseline, then read the explanation for every answer, including the ones you got right. The incorrect-choice explanations are where the distinctions the CC likes to test (authentication versus authorization, a policy versus a standard, containment versus eradication) get spelled out. Study your weakest domain and retake the test in a week. The 60-minute timer over 50 questions keeps you honest about pacing: the real exam gives you 2 hours for up to 125 adaptive questions, so practice deciding in about a minute and moving on rather than second-guessing.
Domains Covered · CC
CIA triad, AAA, privacy, risk terms, policies and standards, control types, and ethics.
GRC planning, business continuity and disaster recovery, security awareness, and metrics.
Identity life cycle, authentication factors, least privilege, separation of duties, and access models.
OSI and TCP/IP, ports, network threats, segmentation, VPNs, and cloud service models.
Data handling and encryption, logging and triage, threat actors, incident response, hardening, and security testing.
Four questions from the bank, one per domain, with the reasoning behind every answer. The full test has 50.
A hospital discovers that patient records were altered by an unauthorized script overnight. Nobody outside the organization saw the records and the system stayed online the whole time. Which element of the CIA triad was violated?
Correct. Integrity means data is accurate and has not been altered without authorization. Records being changed by an unauthorized script is a direct integrity violation, even though nothing was disclosed and nothing went offline.
Which security design principle layers multiple independent controls so that the failure of any one control does not expose the protected asset?
Correct. Defense in depth, also called layered defense, places several independent controls in an attacker's path, such as a firewall, MFA, encryption and monitoring, so a single failure does not compromise the asset.
Which of the following terms describes a measurement with a defined threshold that warns leadership when the organization's risk exposure is rising?
Correct. A key risk indicator is a metric tied to a threshold, such as the percentage of critical patches overdue, that signals when risk exposure is approaching a level leadership will not accept. KRIs feed the dashboards and scorecards used in governance reporting.
Which of the following roles is responsible for deciding how a data set is classified, who may access it and how long it is retained?
Correct. The data owner, sometimes called the data controller, is the business role accountable for a data set. The owner assigns its classification, approves who may access it and sets its retention period, and the custodian implements those decisions.
Every one of the 50 questions works this way: an explanation for the right answer and for the one you picked, so a wrong answer teaches you something. Questions last reviewed against the current ISC2 Certified in Cybersecurity (CC) objectives.
Quick answers about the test, the ISC2 Certified in Cybersecurity (CC) exam, and how to prepare.
Yes. Training Camp's Certified in Cybersecurity practice test is free to take. You get 50 exam-style questions across all five domains of the 2026 CC outline, with a written explanation for every answer choice.
It is 50 multiple-choice scenario questions drawn from all five CC domains, with an instant explanation after each answer and a 60-minute timer that mirrors the pace of the real exam. You can retake it as often as you want. Treat it as a readiness check rather than a substitute for full preparation.
The CC exam uses computerized adaptive testing, so you answer between 100 and 125 questions in 2 hours. The item count varies because the exam stops once it is confident about your ability level.
You need 700 out of 1000 points. Because the exam is adaptive and scaled, 700 does not mean answering 70 percent of the questions correctly.
Under the outline effective September 1, 2026, the five domains are Security Principles (24%), Security Governance (17.3%), Identity and Access Management (IAM) Concepts (20%), Networking and Cloud Security Concepts (21.3%), and Security Operations and Incident Response (17.3%). Foundational AI security concepts appear across all five.
The CC is an entry-level certification with no experience requirement, easier than the SSCP or CISSP, but it is scenario-based rather than pure memorization. Most candidates find the identity and access models and the network security terminology the hardest parts, and the adaptive format means it feels demanding the whole way through.
No. ISC2 designed the CC for people starting out, so there is no work experience requirement and no prerequisite certification. Basic IT familiarity helps, but the exam assumes you are learning security concepts for the first time.
Start with the ISC2 exam outline and work through each domain, then use practice questions like these to find your weak areas. If you want a structured path with an instructor and your exam voucher included, our three-day Certified in Cybersecurity Boot Camp covers all five domains of the 2026 outline.