Certified in Cybersecurity Free Sample Questions

20 free sample questions220 in the full practice test

Try simulator

CC Sample Questions

  1. Question 1

    A global financial institution is implementing a new security framework. The Chief Information Security Officer (CISO) emphasizes that while technical defenses are crucial, the organization must ensure that all employees understand their responsibilities and the consequences of non-compliance. Which governance document should be primarily established to provide this high-level authority and direction?

    Answer and explanation

    Correct answer: C

    A security policy is a high-level document that outlines the organization's security goals, responsibilities, and enforcement. It provides the necessary authority and strategic direction. Standards are mandatory specific rules, and procedures are step-by-step instructions, both of which support the policy but do not provide the high-level authority themselves.

  2. Question 2

    During a risk assessment meeting, the security team identifies a legacy server that contains non-critical data. The cost to upgrade the server's security controls exceeds the value of the data it processes. The management team decides to continue operating the server without additional controls. Which risk treatment strategy has management adopted?

    Answer and explanation

    Correct answer: C

    Risk acceptance occurs when an organization decides that the cost of countermeasures outweighs the potential loss or impact of the risk, and therefore chooses to operate with the known risk. Mitigation would involve applying controls; avoidance would stop the activity; transfer would involve insurance.

  3. Question 3

    A security consultant is explaining the concept of defense-in-depth to a client. The client recently installed a biometric scanner (Physical Control) and a firewall (Technical Control). To complete the triad of security control categories, which of the following should be implemented?

    Answer and explanation

    Correct answer: B

    Security controls are categorized into Physical, Technical (Logical), and Administrative. The client has Physical and Technical controls. Employee background checks are an Administrative (or Managerial) control, completing the triad.

  4. Question 4

    An ISC2 member discovers that their employer is unknowingly releasing software that contains a critical safety flaw which could endanger human lives. The employer refuses to delay the release due to financial pressure. According to the ISC2 Code of Ethics, which canon must the member prioritize above all others?

    Answer and explanation

    Correct answer: C

    The first and highest canon of the ISC2 Code of Ethics is to 'Protect society, the common good, necessary public trust and confidence, and the infrastructure'. When safety of life is at risk, this canon takes precedence over providing diligent service to the employer (principals).

  5. Question 5

    Multiple answers

    A user logs into a banking application using a password and a one-time code sent to their mobile phone. Which two authentication factors are being utilized in this scenario? (Select TWO)

    Answer and explanation

    Correct answers: A, C

    The password represents 'Something you know'.

    The mobile phone receiving the code represents 'Something you have'.

  6. Question 6

    A healthcare provider sends a digitally signed email to a patient containing medical records. The patient uses the provider's public key to verify the signature. This process primarily ensures which security concept?

    Answer and explanation

    Correct answer: C

    Digital signatures provide non-repudiation, ensuring that the sender cannot deny having sent the message and that the integrity of the message has not been compromised. While it proves integrity, the specific concept of proving origin to a third party is non-repudiation.

  7. Question 7

    True or False: In the context of risk management, 'Risk Appetite' refers to the specific amount of loss an organization can objectively endure without failing, whereas 'Risk Tolerance' is the broader strategic level of risk they are willing to take.

    Answer and explanation

    Correct answer: B

    False. It is the reverse. 'Risk Appetite' is the broad, strategic level of risk an organization is willing to accept in pursuit of its goals. 'Risk Tolerance' is the specific variance from that appetite that is acceptable (e.g., specific metrics or limits).

  8. Question 8

    Which of the following scenarios best illustrates the 'Integrity' component of the CIA Triad?

    Answer and explanation

    Correct answer: B

    Integrity ensures data is accurate and has not been tampered with. Hashing is a primary method to verify integrity. Encryption addresses confidentiality, and load balancing addresses availability.

  9. Question 9

    A multinational corporation must comply with the General Data Protection Regulation (GDPR). They are appointing a specific role responsible for determining the purposes and means of processing personal data. What is this role called?

    Answer and explanation

    Correct answer: B

    Under GDPR, the Data Controller determines the 'purposes and means' of processing personal data. The Data Processor processes data on behalf of the controller. The DPO is an oversight role.

  10. Question 10

    An organization is conducting a quantitative risk assessment. They determine that a specific server fails once every 4 years. The replacement cost of the server is $10,000. What is the Annualized Loss Expectancy (ALE)?

    Answer and explanation

    Correct answer: A

    ALE = Single Loss Expectancy (SLE) x Annualized Rate of Occurrence (ARO). SLE is $10,000. ARO is 1/4 (0.25). ALE = $10,000 x 0.25 = $2,500.

Register free to unlock 10 more sample questions

Lifetime One

Own this practice test forever.

$79.99
$75.99
one-time
  • Full access to 220 questions
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • Brainy AI Assistant
  • Lifetime updates

Two

Any 2 exams per month.

$20.00/exam
$39.99
/month
  • 2 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 1,000 Brainy AI Credits
  • Cancel anytime

Premium Twelve

Any 12 exams over 3 months.

$15.00/exam
$179.99
/3 months
  • 4 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 15,000 Brainy AI Credits
  • Dedicated support
  • Friend seat included — full access

Trusted by professionals at

NvidiaSupabaseGitHubOpenAITursoClerkClaude AIAmazon