This Certified in Cybersecurity guide helps CC candidates build the entry-level security judgment ISC2 tests: identify the asset, name the risk, choose the right control type, preserve evidence, and follow the correct operational sequence.
Use the domain chapters for learning, the section lessons for close-answer distinctions, the study plan for sequencing, the cheat sheet for last-mile review, the sample questions for decision practice, the FAQ for scope checks, the resources page for ISC2 exam references, and the glossary when control names blur together.
At a glance
| Item |
Guide value |
| Vendor |
ISC2 |
| Exam or credential |
Certified in Cybersecurity |
| Code or shorthand |
CC |
| Study level |
Entry cybersecurity |
| Current outline used here |
Effective October 1, 2025 |
| Upcoming outline note |
ISC2 says a new outline becomes effective September 1, 2026 |
| Current exam format |
CAT, 100-125 items, 2 hours, passing grade 700/1000 |
| Guide shape |
Start-here page, five domain chapters, objective lessons, study plan, cheat sheet, sample questions, FAQ, resources, and glossary. |
Current ISC2 CC domain map
| Domain |
Weight |
What to master in this guide |
| Security Principles |
26% |
CIA, authentication, non-repudiation, privacy, risk, controls, ethics, policies, procedures, standards, laws, and governance. |
| BC, DR, and Incident Response |
10% |
Business continuity, disaster recovery, incident response purpose, roles, sequence, communication, recovery, and evidence. |
| Access Controls Concepts |
22% |
Physical access controls, monitoring, authorized versus unauthorized personnel, least privilege, separation of duties, DAC, MAC, and RBAC. |
| Network Security |
24% |
OSI/TCP/IP basics, ports, common attacks, IDS/IPS, firewalls, segmentation, VPNs, NAC, cloud service models, and hybrid environments. |
| Security Operations |
18% |
Data security, encryption, retention, logging, hardening, patching, policies, awareness training, social engineering, and safe AI-tool use. |
How the exam thinks
flowchart LR
S["Scenario"] --> A["Asset"]
A --> R["Risk"]
R --> C["Control objective"]
C --> T["Control type or process step"]
T --> E["Evidence, recovery, or governance proof"]
CC questions are foundational, but they are not random vocabulary checks. Most wrong answers fail because they choose a tool before naming the risk, confuse two adjacent concepts, or break the correct operational sequence.
How to use this guide
- Start with the study plan if you need a structured path through the current ISC2 outline.
- Read the five domain chapters in order if you are new to cybersecurity.
- Use section lessons when a concept pair keeps causing missed questions.
- Use the cheat sheet before a mixed practice set and again when you want a fast control review.
- Use the sample questions for decision practice with explanations.
- Check the FAQ and resources pages before scheduling because ISC2 has announced an outline update for September 1, 2026.
- Use the glossary when two controls, roles, or security terms feel interchangeable.
Common weak-answer patterns
| If the stem asks about… |
Weak answer |
Stronger CC habit |
| security principle |
naming a tool immediately |
classify confidentiality, integrity, availability, authentication, privacy, or non-repudiation first |
| risk |
treating all risks as vulnerabilities |
separate asset, threat, vulnerability, likelihood, impact, and treatment |
| access control |
confusing sign-in with permission |
separate identification, authentication, authorization, and accountability |
| incident response |
restoring before containment |
follow detection, analysis, containment, eradication, recovery, and lessons learned |
| continuity |
saying “backup” only |
connect BIA, BCP, DRP, RTO, RPO, recovery test, and communication |
| network security |
choosing one perimeter device |
combine segmentation, secure protocols, IDS/IPS, hardening, monitoring, and cloud/shared responsibility |
Exam decision habit
ISC2 entry-level questions reward risk-first thinking: asset, threat, control objective, evidence, and business impact. If two answers sound safe, keep the one that best protects confidentiality, integrity, availability, privacy, accountability, and recovery without skipping policy or evidence.
Source status
This guide is aligned to ISC2’s Certified in Cybersecurity exam outline effective October 1, 2025. ISC2 currently notes that a new CC outline becomes effective September 1, 2026, so use the resources page for the current official outline before scheduling late-2026 attempts.
In this section
-
Security Principles
Study ISC2 CC Security Principles: CIA, authentication, privacy, risk, controls, ethics, governance, and policy basics.
-
Information Assurance
Study ISC2 CC information assurance: confidentiality, integrity, availability, authentication, non-repudiation, and privacy.
-
Risk, Controls, Ethics, and Governance
Study ISC2 CC risk management, control types, ISC2 Code of Ethics, policies, procedures, standards, laws, and governance.
-
Business Continuity, Disaster Recovery, and Incident Response
Study ISC2 CC business continuity, disaster recovery, and incident response concepts for entry-level cybersecurity roles.
-
Business Continuity and Disaster Recovery
Study ISC2 CC business continuity and disaster recovery: BIA, BCP, DRP, RTO, RPO, backups, tests, and recovery priorities.
-
Incident Response
Study ISC2 CC incident response: preparation, detection, analysis, containment, eradication, recovery, evidence, and lessons learned.
-
Access Controls Concepts
Study ISC2 CC access control concepts: physical controls, monitoring, least privilege, separation of duties, DAC, MAC, and RBAC.
-
Physical Access Controls
Study ISC2 CC physical access controls: badges, gates, guards, CCTV, alarms, logs, facilities, and authorized personnel.
-
Logical Access Controls
Study ISC2 CC logical access controls: least privilege, separation of duties, DAC, MAC, RBAC, MFA, and identity lifecycle.
-
Network Security
Study ISC2 CC network security: OSI, TCP/IP, ports, threats, IDS/IPS, firewalls, segmentation, NAC, VPNs, cloud, and hybrid.
-
Networking Models, Ports, and Applications
Study ISC2 CC networking basics: OSI model, TCP/IP, IPv4, IPv6, Wi-Fi, ports, protocols, and applications.
-
Network Threats and Attacks
Study ISC2 CC network threats and attacks: DDoS, virus, worm, Trojan, MITM, side-channel, IDS, HIDS, NIDS, IPS, firewalls, and antivirus.
-
Network Security Infrastructure
Study ISC2 CC network security infrastructure: data centers, redundancy, DMZ, VLAN, VPN, micro-segmentation, NAC, IoT, cloud, MSP, and hybrid.
-
Security Operations
Study ISC2 CC security operations: data security, encryption, logging, hardening, configuration management, policies, and awareness training.
-
Data Security and Logging
Study ISC2 CC data security and logging: symmetric encryption, asymmetric encryption, hashing, classification, retention, destruction, and monitoring.
-
System Hardening and Configuration Management
Study ISC2 CC hardening and configuration management: baselines, updates, patches, secure settings, documentation, approval, rollback, and verification.
-
Policies and Awareness Training
Study ISC2 CC best-practice security policies and awareness training: data handling, passwords, AUP, BYOD, change management, privacy, and social engineering.
-
ISC2 CC Cheat Sheet: Core Controls and Risk Basics
ISC2 CC cheat sheet for core controls, risk basics, traps, and final review.
-
ISC2 CC Study Plan: 30, 60, and 90 Days
ISC2 CC 30-, 60-, and 90-day study plan with topic order, review loops, and final-week priorities.
-
ISC2 CC Sample Questions with Explanations
ISC2 CC sample questions with explanations, traps, and topic labels.
-
ISC2 CC FAQ: Exam Format, Topics, and Prep
ISC2 CC FAQ for exam format, topics, prep strategy, practice, and common candidate traps.
-
ISC2 CC Resources: Official Links and Study Tools
ISC2 CC resources for official links, blueprint checks, study tools, and source review.
-
ISC2 CC Glossary: Core Controls and Risk Terms
ISC2 CC glossary of core controls, risk terms, traps, and decision cues.