Sitonce
Country: US
Show exams for United States Hong Kong
Sign in

ISC2 CC Exam Domains and Weights

Updated 10 min read
Key takeaway

The current ISC2 CC outline, effective September 1, 2026, has five domains: Security Principles (24%), Security Governance (17.3%), Identity and Access Management Concepts (20%), Networking and Cloud Security Concepts (21.3%), and Security Operations and Incident Response (17.3%).

  • Together they cover foundational security judgment and operations.
On this page12 sections
  1. The five-domain outline
  2. Domain 1: Security Principles, 24%
  3. Domain 2: Security Governance, 17.3%
  4. Domain 3: Identity and Access Management Concepts, 20%
  5. Domain 4: Networking and Cloud Security Concepts, 21.3%
  6. Domain 5: Security Operations and Incident Response, 17.3%
  7. Cross-domain scenarios
  8. How to use domain weights while studying
  9. How the 2026 structure changes study emphasis
  10. Compare related concepts within domains
  11. Additional scenario practice
  12. Use the outline as a coverage checklist

The five-domain outline

The current CC outline took effect September 1, 2026. Its five domains retain an entry-level focus but reorganize and expand several topics. Security Governance is a dedicated domain, identity and access is explicit, cloud security appears alongside networking, and security operations incorporates incident response. Foundational AI security considerations appear across domains. Candidates using older course notes should map the content to this structure before relying on past domain weights.

DomainWeightMain decision questions
1. Security Principles24%Which security goal, risk concept, control or ethical duty applies?
2. Security Governance17.3%Who sets direction, accepts risk, plans continuity and builds awareness?
3. Identity and Access Management Concepts20%How is identity claimed, verified, authorized and reviewed?
4. Networking and Cloud Security Concepts21.3%What protects communication and how are cloud responsibilities divided?
5. Security Operations and Incident Response17.3%How are threats monitored, incidents handled and services recovered?

Weights describe the average exam blueprint. They do not guarantee a fixed question count in an individual CAT session. Use them to plan coverage, not to calculate how many items will appear. A learner should account for both weight and personal weakness: a smaller domain that is poorly understood can still be a meaningful risk.

Domain 1: Security Principles, 24%

Security Principles includes confidentiality, integrity, availability, authentication, authorization, accounting, privacy and non-repudiation. Confidentiality limits disclosure to authorized parties. Integrity protects accuracy and completeness. Availability means information and systems can be used when needed. Authentication verifies a claimed identity; authorization sets what that identity may do. Accounting records activity so actions can be traced.

Risk management considers threats, vulnerabilities, likelihood, impact and the controls selected to manage risk. Controls may be technical, administrative or physical. A firewall is technical; an approved policy and training are administrative; a locked server room is physical. More than one type may be needed. Professional conduct includes following the ISC2 Code of Ethics, exercising due care and reporting concerns through appropriate channels.

Worked example: a shared folder contains payroll details, and every employee can open it. The main weakness is excessive access, so authorization and least privilege are central. Encryption at rest may protect a lost storage device, but it does not stop an authorized account with unnecessary permission from opening the folder. Choose the control that addresses the actual exposure.

Domain 2: Security Governance, 17.3%

Governance, risk and compliance connect security to organizational objectives, accountability and applicable obligations. Policies express management direction; standards define required controls; procedures state repeatable steps; guidelines recommend practices. Risk decisions should be made by the role with authority, documented and reviewed. Technical staff provide information, but they should not silently accept business risk beyond their authority.

The domain also covers redundancy, business continuity, disaster recovery and awareness. Business continuity aims to keep critical functions operating during disruption. Disaster recovery restores technology, applications and data. Redundancy can support availability, but a backup that has never been restored is not evidence that recovery will meet the business need. Awareness helps workers recognize threats and follow reporting paths.

Worked example: a company’s payroll service is offline after a building outage. The continuity plan identifies how payroll will still be processed; the disaster recovery plan addresses restoring the supporting systems. A server replica may help recovery, but leadership must identify which functions are critical and test the recovery sequence. A question about risk acceptance should point to authorized management, not an individual technician.

Domain 3: Identity and Access Management Concepts, 20%

IAM covers identity and access processes. Identification is the claimed identity; authentication verifies it; authorization grants or denies permitted actions; accounting records activity. Multifactor authentication uses different factor categories, such as something known and something possessed. Two passwords do not provide two independent categories. Least privilege limits access to what work requires; separation of duties divides sensitive tasks among people.

Access reviews check whether permissions remain appropriate after job changes or project completion. Roles can group permissions by function, but role membership must still be managed. A terminated employee’s access should be removed promptly. An employee who changes departments may retain an old role unless access is reviewed. Authentication is not a replacement for authorization: proving who a user is does not mean every record should be available.

Worked example: a user signs in with a valid password and MFA but can view a customer list outside the user’s duties. Authentication is functioning; authorization is too broad. The appropriate action is to review and narrow permissions according to least privilege. Requiring a new password alone would not correct the access grant.

Domain 4: Networking and Cloud Security Concepts, 21.3%

This domain covers basic networking, network security, cloud models and shared responsibility. Firewalls filter traffic according to rules. Segmentation separates systems to limit unnecessary communication and contain compromise. Encryption protects data in transit. Secure configuration and access controls help protect cloud resources. The candidate should understand basic network function and the reason for common controls rather than implement a full enterprise network.

Cloud responsibility depends on the service and layer. The provider protects its facilities, hardware and underlying cloud infrastructure. Customers manage identities, data and many workload configurations. A virtual-machine customer generally patches the guest operating system; using a managed service shifts some operations to the provider but does not remove customer duties for access and data. AI security concepts include protecting models and data, validating outputs and recognizing automated threats.

Worked example: a company exposes a cloud storage bucket publicly by applying an overly broad access policy. The customer must correct the policy and assess exposure. If the issue were an unauthorized person entering the cloud provider’s facility, physical infrastructure protection would be the provider’s responsibility. Name the layer before assigning responsibility.

Domain 5: Security Operations and Incident Response, 17.3%

Security operations includes monitoring, threat intelligence, incident handling, evidence and recovery. A response plan commonly prepares the organization, identifies and analyzes events, contains the incident, eradicates the cause, recovers service and captures lessons. Follow documented authority and communications. Preserve relevant evidence and record actions. A security alert is a signal to investigate, not automatic proof that compromise occurred.

Threat intelligence informs detection and prioritization, but should be evaluated for reliability and relevance. Logs may support investigation, but access to them should be controlled. Containment limits damage; eradication removes the cause; recovery restores service safely. These are different phases. Resetting a password may be part of response, while rebuilding a host before evidence collection may harm an investigation.

Worked example: a staff member receives a suspicious attachment but does not open it. The immediate response is to avoid opening it and report it under the organization’s process. If the attachment executed and the device is communicating with an attacker, follow the incident plan to contain the device and preserve evidence. The scenario’s stage changes the correct action.

Cross-domain scenarios

A lost laptop containing encrypted customer data may involve confidentiality, encryption, physical security, incident reporting and governance. The best answer depends on what the prompt asks: protect data at rest, notify a responsible party, investigate exposure or restore a device. A single situation can touch multiple domains, but the item generally asks for one particular decision. Look at the requested action, not just the nouns in the story.

A phishing email that impersonates an executive can involve awareness, authentication, financial controls and incident reporting. Verify an unusual request through a trusted channel. If credentials may have been disclosed, follow access-remediation and incident procedures. Do not treat a clever email filter as the only control; people and process remain part of defense.

How to use domain weights while studying

  1. Read the current exam outline and list its tasks under the five domains.
  2. Mark each task strong, uncertain or new based on whether you can explain and apply it.
  3. Use the published weights to ensure enough time goes to principles, IAM and networking/cloud security.
  4. Spend additional time where your understanding is weakest, even if that domain has a smaller share.
  5. Practice mixed scenarios that require identifying the domain clue and choosing the best control or next action.

The weights are not quotas and do not predict CAT item count. A candidate should not skip governance because it is 17.3 percent or assume networking will contribute exactly 21 questions. Use the percentages to balance preparation, then measure readiness with fresh scenarios across all five domains.

The current outline has five domains effective September 1, 2026, with weights from 17.3% to 24%.

Security Principles is 24%; Security Governance 17.3%; IAM Concepts 20%; Networking and Cloud Security Concepts 21.3%; and Security Operations and Incident Response 17.3%.

No. Weights describe the exam blueprint. The CAT presents a variable number of items and does not provide a fixed public domain count for each candidate.

The 2026 outline integrates foundational AI security concepts across the domains, including governance, data protection and automated threat awareness.

How the 2026 structure changes study emphasis

The updated outline makes Security Governance a separate domain and uses explicit IAM and Networking and Cloud Security titles. A candidate who studied the prior blueprint should not assume that familiar topic labels still group the same way. Make a crosswalk from old notes to the current domains, then add missing tasks and update the weights. The change is organizational as well as topical, so the current outline should guide both what you study and how you evaluate coverage.

The Security Operations and Incident Response domain places response and operational thinking together. Learn how monitoring, threat information and incident steps connect. A detection signal must be assessed; containment can limit damage; eradication removes the cause; recovery restores a safe service. Memorizing a list of phases is not enough if you cannot identify which phase a scenario describes.

Security Principles often asks which security objective is at risk. Unauthorized disclosure points to confidentiality; unauthorized modification threatens integrity; inability to use a service affects availability. Governance asks who has authority and how organizational risk decisions are recorded. IAM asks whether an identity was verified and whether its permissions are appropriate. Distinguishing these question types prevents selecting a technical fix for a governance problem.

Networking and Cloud Security can overlap with IAM and operations. An excessive cloud role is an IAM configuration weakness; a cloud provider’s physical data-center controls fall on the provider side of shared responsibility. A suspicious network connection may call for monitoring and response, while a firewall rule concerns permitted traffic. State the exact layer and requested action to find the best answer.

Additional scenario practice

A company’s finance director asks for a plan that allows staff to process invoices during a flood that closes the office. The focus is business continuity because an essential business function must continue. Restoring a damaged server later is disaster recovery. A second data center could support availability, but the organization still needs procedures and assigned roles.

A departing contractor’s account remains active. The immediate control is removing or disabling access and reviewing activity. This is identity lifecycle and authorization. A password reset for remaining employees does not directly remove the contractor’s account. If investigation finds misuse, incident response may also be needed.

An analyst sees an alert that a server sent unusual traffic to an unfamiliar address. The alert is not yet proof of compromise; investigate according to monitoring and incident procedures. If malicious activity is confirmed, contain the host while preserving relevant evidence. This tests operational sequence and evidence care, not just the ability to name a monitoring tool.

Use the outline as a coverage checklist

For each domain, write one sentence about the purpose, list the key terms you can define, and add an example where you would apply them. If a term cannot be explained without copying a definition, it needs more work. Then use mixed questions to test whether you can choose between related concepts under a scenario. Review the official outline again near your exam date so your study map remains aligned to the September 2026 version.

Common questions

How many domains are on the current CC exam?

Five domains. The current outline took effect September 1, 2026.

What is the largest CC domain?

Security Principles is 24%, slightly larger than Networking and Cloud Security Concepts at 21.3%.

Do the weights set an exact number of questions?

No. They are average blueprint weights, and the CAT item count varies.

Is AI included in the 2026 CC outline?

Yes. Foundational AI security considerations are integrated throughout the current outline.