ISC2 CC FAQ for exam format, topics, prep strategy, practice, and common candidate traps.
Start with Security Principles because it is the largest current domain and frames the rest of the exam. Then move through BC/DR/incident response, access controls, network security, and security operations.
As of May 24, 2026, ISC2 lists CC as a CAT exam with 100-125 items, 2 hours, multiple choice and advanced item types, and a passing grade of 700 out of 1000. Verify the official outline before scheduling.
Yes. ISC2 says the current CC outline is effective October 1, 2025 and that a new CC exam outline becomes effective September 1, 2026. Use the current outline if your exam date is before that change, and recheck ISC2 if scheduling near or after September 1, 2026.
The highest-risk trap is: Tool-first security. The better move is: Start with asset, risk, policy, and control objective.
No. You need vocabulary, but the safer exam habit is classification: decide whether the stem is about CIA, risk, access control, response sequence, network control placement, data handling, hardening, or policy behavior.
At CC level, keep AI security foundational. Think data leakage in public tools, model poisoning as an integrity risk, service-account least privilege, AI-assisted monitoring that still needs human validation, and governance for automated decisions.
Use practice questions after a focused read, not before any context. For every miss, write the tested lane, the constraint, the correct rule, and why each distractor failed.
Use the official ISC2 source for live details such as exam name, active outline, upcoming outline date, price, duration, CAT format, delivery method, languages, and domain weights.