Sitonce
Country: US
Show exams for United States Hong Kong
Sign in

ISC2 CC Practice Questions with Explanations

Updated 10 min read
Key takeaway

These original practice questions illustrate the current CC domains and are not recalled from a live exam.

  • Each item includes the answer and reasoning.
  • Use the explanations to learn distinctions such as authentication versus authorization, customer versus provider responsibility, continuity versus recovery, and incident response sequence.
On this page13 sections
  1. How to use these original questions
  2. Question 1: authentication or authorization?
  3. Question 2: cloud responsibility
  4. Question 3: continuity or disaster recovery?
  5. Question 4: first step for a suspicious attachment
  6. Question 5: choose an administrative control
  7. Question 6: preserve evidence during response
  8. Review a miss so it transfers
  9. Practice ethically and realistically
  10. Question 7: identify the security objective
  11. Question 8: choose a network control
  12. Question 9: separate a security alert from a confirmed incident
  13. A final self-review after answering

How to use these original questions

Attempt each item before reading the answer. Identify the exact question: Is it asking for a first action, a security objective, a responsible party or a control? Select one option and explain why it directly meets the need. Then compare every distractor. If your answer was correct by guess, record it as a learning gap.

These are original illustrative items written for practice. They are not taken from or meant to reproduce protected ISC2 exam questions. The live CC exam uses CAT, presents 100 to 125 items in two hours, and does not allow candidates to skip an item and return later. These examples test reasoning, not the live interface or adaptive scoring.

Question 1: authentication or authorization?

An employee signs in successfully with a password and multifactor authentication. The employee can then open customer records outside the employee’s assigned region. Which control problem most directly explains the exposure?

  1. A. Authentication did not verify the employee’s identity
  2. B. Authorization granted access beyond the employee’s role
  3. C. Accounting failed to record the login
  4. D. Availability controls failed to keep records accessible

Correct answer: B. The employee authenticated successfully, so identity verification is not the issue described. The problem is that the account has permissions to access records outside its business need. Review and narrow authorization using least privilege. A is tempting because the prompt mentions sign-in, but successful sign-in is evidence that authentication worked. C may be relevant to auditing, but the scenario identifies excess access, not missing logs. D concerns access to a service, not who may view a particular record.

Domain connection: Identity and Access Management Concepts. The clue is not simply that the event occurred after login; it is that the user can perform an action outside the assigned role.

Question 2: cloud responsibility

A company runs a virtual machine in a public cloud. A security scan finds that the guest operating system is missing a critical patch. Who is primarily responsible for applying the patch?

  1. A. The cloud provider, because it owns the physical server
  2. B. The customer, because it manages the guest operating system
  3. C. The internet service provider, because the machine communicates over a network
  4. D. The software vendor, because it wrote the application

Correct answer: B. In a customer-managed virtual machine, the cloud provider protects the physical facility and underlying infrastructure, while the customer typically manages the guest operating system and its patches. A confuses security of the cloud with security in the cloud. C is unrelated to OS maintenance. D may supply software updates, but the scenario asks who applies the guest operating-system patch in the customer’s workload.

Domain connection: Networking and Cloud Security Concepts. State the service layer before assigning responsibility. A fully managed service shifts some operations, but customer identities, data and configurations remain important customer duties.

Question 3: continuity or disaster recovery?

A flood closes a company’s main office. The company must keep processing payroll while employees work from another location. Which planning objective is most directly involved?

  1. A. Business continuity
  2. B. Disaster recovery
  3. C. Non-repudiation
  4. D. Authentication

Correct answer: A. Business continuity plans how critical functions continue during disruption. Disaster recovery focuses on restoring technology and data after an event. Recovery may be part of the response to the flood, but the specific need is to keep payroll operating while the office is unavailable. C concerns proving an action cannot be denied; D concerns verifying identity. Neither matches continuity of a business process.

Domain connection: Security Governance. A useful distinction is function versus technology: keeping the work going is continuity, while rebuilding systems is disaster recovery.

Question 4: first step for a suspicious attachment

A worker notices a suspicious email attachment but has not opened it. The organization has a process for reporting suspected phishing. What is the best immediate action?

  1. A. Open the file in a personal email account to see what it contains
  2. B. Report the message through the organization’s process and do not open the attachment
  3. C. Rebuild the worker’s computer from a clean image
  4. D. Disable all organization accounts

Correct answer: B. The attachment has not been opened, so safe handling and reporting are the proportionate immediate actions. The organization can assess the message and warn others if needed. A increases risk. C and D are disruptive actions without evidence that a device or account was compromised. If the file had executed and malicious activity were confirmed, containment and incident-response actions would be appropriate.

Domain connection: Security Operations and Incident Response. The phrase “has not opened” is decisive. Determine what is known before selecting a response stage.

Question 5: choose an administrative control

A small organization has repeated cases of staff sharing passwords. Management wants to establish a consistent rule and explain how employees should report suspected misuse. Which action best addresses the need?

  1. A. Publish an approved security policy and a reporting procedure, then train employees
  2. B. Add more disk capacity to the file server
  3. C. Encrypt all network traffic without changing account practices
  4. D. Install a second firewall at the internet boundary

Correct answer: A. A policy sets management direction and a procedure defines the reporting steps; awareness helps employees understand and follow them. Encryption and firewalls can support security but do not define acceptable credential sharing or how to report misuse. Storage capacity has no connection to the behavior. The prompt asks for governance and awareness, not another technical perimeter control.

Domain connection: Security Principles and Security Governance. Administrative controls and technical controls complement one another; the correct choice should match the specific behavior and decision process.

Question 6: preserve evidence during response

A workstation is confirmed to be communicating with a suspicious external host. The response plan calls for containment and evidence preservation. Which action best follows that plan?

  1. A. Immediately wipe the device before notifying anyone
  2. B. Follow the authorized containment process, document actions and preserve relevant evidence
  3. C. Ignore the alert because the user can still log in
  4. D. Ask the user to delete suspicious files and continue work

Correct answer: B. The incident is confirmed enough to require action, and the stated plan explicitly calls for containment and evidence preservation. Documented containment limits harm while keeping an investigation possible. A can destroy evidence and bypass authority. C confuses system availability with safety. D risks further damage and alters evidence without an approved response.

Domain connection: Security Operations and Incident Response. Contrast this with Question 4: there, the attachment had not been opened; here, suspicious activity is confirmed and containment is warranted.

Review a miss so it transfers

For each error, write down the clue, the correct concept and the reason the strongest distractor was wrong. A useful note might be: “User signed in, but permissions exceeded role; authorization, not authentication.” Then solve a different scenario involving the same distinction. This tests transfer rather than memory of the wording.

If you miss several questions in one domain, consult the current September 2026 exam outline and target the named tasks. Do not infer an official domain score from this small set. These examples are not calibrated to the CAT or official scoring. The passing grade is 700 out of 1,000 scaled points, not a raw percentage of this article’s questions.

Practice ethically and realistically

Use official outline-aligned resources and original, authorized practice. Avoid dumps and claims that a site reproduces actual protected questions. The purpose of practice is to learn security judgment, not collect recalled answers. On the live exam, candidates cannot skip and return, so practice at least some questions with each choice treated as final.

A correct choice matters less than being able to explain why it fits. If you chose the right option for the wrong reason, the next variation may expose the gap. Review concepts, apply them to fresh workplace examples and use practice results only to choose what to study next.

Question 7: identify the security objective

A staff member notices that a transaction record was changed without authorization. Which information-security objective is most directly affected?

  1. A. Confidentiality
  2. B. Integrity
  3. C. Availability
  4. D. Non-repudiation

Correct answer: B. Integrity concerns accuracy and completeness and protects against unauthorized modification. Confidentiality concerns disclosure, so it would be central if someone viewed the record without permission. Availability concerns timely access, such as a system outage. Non-repudiation helps establish that an action occurred and cannot simply be denied, but the stated problem is the unauthorized change itself.

Domain connection: Security Principles. A practical way to distinguish the CIA objectives is to ask whether information was disclosed, altered or made unavailable.

Question 8: choose a network control

An organization wants to limit the traffic that can pass between an employee workstation network and a server containing sensitive records. Which concept most directly reduces unnecessary paths between these systems?

  1. A. Network segmentation with rules allowing only required communication
  2. B. A password-expiration reminder for employees
  3. C. A backup schedule for the server
  4. D. A business continuity call tree

Correct answer: A. Segmentation separates network areas and allows the organization to restrict communication between them. A password reminder addresses account practice, a backup supports recovery, and a call tree supports communications during disruption. All may be useful controls, but none directly limits network paths between the two systems.

Domain connection: Networking and Cloud Security Concepts. The key clue is traffic between network segments, not identity lifecycle or recovery.

Question 9: separate a security alert from a confirmed incident

A monitoring tool reports an unusual login time for an employee. No other suspicious activity is yet confirmed. What is the most appropriate next step?

  1. A. Ignore the alert because the employee’s account still works
  2. B. Investigate the alert using the organization’s monitoring and escalation process
  3. C. Publicly announce that the employee’s account was compromised
  4. D. Delete the account and all related logs immediately

Correct answer: B. An alert is a signal to investigate, not proof by itself that an incident occurred. Follow the organization’s process to verify the activity and escalate if warranted. A ignores a potentially important event. C makes an unsupported claim. D destroys evidence and takes drastic action without analysis or authorization.

Domain connection: Security Operations and Incident Response. If the investigation confirms compromise, containment and further response can follow. The scenario has not established that point yet.

A final self-review after answering

After each item, be able to state the clue in one sentence: “the user authenticated but had excess permissions,” “the guest operating system needs a patch,” or “the system is unavailable while a business function must continue.” If you can state the clue, you can usually explain why the answer fits. If you cannot, review the question’s objective before moving to another source.

These nine examples span the five current domains, but they are not a complete course or a prediction of item distribution. Use the exam outline for full coverage and seek additional authorized practice as needed. The live assessment can present different item formats, and no small sample reproduces CAT behavior or the official score scale.

Common questions

Are these ISC2 CC questions from the live exam?

No. They are original illustrative practice questions and do not reproduce protected live exam content.

Do these practice scores predict my CC scaled score?

No. This small set is not calibrated and does not map to the official scaled score.

What topics do these questions cover?

They cover IAM, cloud responsibility, governance, continuity and incident response from the current five-domain outline.

Can I return to CC exam questions?

No. ISC2 says candidates cannot skip an item and return later.