ISC2 CC Guide: Certified in Cybersecurity

Comprehensive ISC2 CC exam guide covering security principles, incident response, access control, network security, security operations, and final review.

This Certified in Cybersecurity guide helps CC candidates build the entry-level security judgment ISC2 tests: identify the asset, name the risk, choose the right control type, preserve evidence, and follow the correct operational sequence.

Use the domain chapters for learning, the section lessons for close-answer distinctions, the study plan for sequencing, the cheat sheet for last-mile review, the sample questions for decision practice, the FAQ for scope checks, the resources page for ISC2 exam references, and the glossary when control names blur together.

At a glance

Item Guide value
Vendor ISC2
Exam or credential Certified in Cybersecurity
Code or shorthand CC
Study level Entry cybersecurity
Current outline used here Effective October 1, 2025
Upcoming outline note ISC2 says a new outline becomes effective September 1, 2026
Current exam format CAT, 100-125 items, 2 hours, passing grade 700/1000
Guide shape Start-here page, five domain chapters, objective lessons, study plan, cheat sheet, sample questions, FAQ, resources, and glossary.

Current ISC2 CC domain map

Domain Weight What to master in this guide
Security Principles 26% CIA, authentication, non-repudiation, privacy, risk, controls, ethics, policies, procedures, standards, laws, and governance.
BC, DR, and Incident Response 10% Business continuity, disaster recovery, incident response purpose, roles, sequence, communication, recovery, and evidence.
Access Controls Concepts 22% Physical access controls, monitoring, authorized versus unauthorized personnel, least privilege, separation of duties, DAC, MAC, and RBAC.
Network Security 24% OSI/TCP/IP basics, ports, common attacks, IDS/IPS, firewalls, segmentation, VPNs, NAC, cloud service models, and hybrid environments.
Security Operations 18% Data security, encryption, retention, logging, hardening, patching, policies, awareness training, social engineering, and safe AI-tool use.

How the exam thinks

    flowchart LR
	  S["Scenario"] --> A["Asset"]
	  A --> R["Risk"]
	  R --> C["Control objective"]
	  C --> T["Control type or process step"]
	  T --> E["Evidence, recovery, or governance proof"]

CC questions are foundational, but they are not random vocabulary checks. Most wrong answers fail because they choose a tool before naming the risk, confuse two adjacent concepts, or break the correct operational sequence.

How to use this guide

  1. Start with the study plan if you need a structured path through the current ISC2 outline.
  2. Read the five domain chapters in order if you are new to cybersecurity.
  3. Use section lessons when a concept pair keeps causing missed questions.
  4. Use the cheat sheet before a mixed practice set and again when you want a fast control review.
  5. Use the sample questions for decision practice with explanations.
  6. Check the FAQ and resources pages before scheduling because ISC2 has announced an outline update for September 1, 2026.
  7. Use the glossary when two controls, roles, or security terms feel interchangeable.

Common weak-answer patterns

If the stem asks about… Weak answer Stronger CC habit
security principle naming a tool immediately classify confidentiality, integrity, availability, authentication, privacy, or non-repudiation first
risk treating all risks as vulnerabilities separate asset, threat, vulnerability, likelihood, impact, and treatment
access control confusing sign-in with permission separate identification, authentication, authorization, and accountability
incident response restoring before containment follow detection, analysis, containment, eradication, recovery, and lessons learned
continuity saying “backup” only connect BIA, BCP, DRP, RTO, RPO, recovery test, and communication
network security choosing one perimeter device combine segmentation, secure protocols, IDS/IPS, hardening, monitoring, and cloud/shared responsibility

Exam decision habit

ISC2 entry-level questions reward risk-first thinking: asset, threat, control objective, evidence, and business impact. If two answers sound safe, keep the one that best protects confidentiality, integrity, availability, privacy, accountability, and recovery without skipping policy or evidence.

Source status

This guide is aligned to ISC2’s Certified in Cybersecurity exam outline effective October 1, 2025. ISC2 currently notes that a new CC outline becomes effective September 1, 2026, so use the resources page for the current official outline before scheduling late-2026 attempts.

In this section

Revised on Monday, June 15, 2026