ISC2 · free study guide

ISC2 CC study guide

Certified in Cybersecurity

Free ISC2 CC study guide and exam blueprint. 100 questions in 120 minutes. Written from ISC2's Exam Outline eff. 1 Sep 2026, last checked 22 July 2026. Domain weightings, glossary, and practice questions with worked explanations.

Written from ISC2's Exam Outline eff. 1 Sep 2026. Last checked against that document on 22 July 2026.
100 questions 120 minutes 5 domains
Orientation

The exam just changed.

If you are studying for the CC right now, you are studying for a moving target, and almost nobody has noticed. ISC2 replaced the entire CC exam outline effective September 1, 2026. This is not a light refresh. A domain was removed, a new one was added, and three more were renamed and rescoped. Every study guide, video series, and practice bank written before this year is now describing an exam that no longer exists.

Which exam will you sit?
Sitting on or after September 1, 2026? You get the new outline, and this material is built for it.

Sitting before September 1, 2026? You get the older outline (effective October 1, 2025), which had a standalone "Business Continuity, Disaster Recovery & Incident Response" domain and no Governance or Cloud domain. Most of the content here still applies, but the weighting and structure differ. If your test date is close to the boundary, confirm it before you book.

What actually changed

Old outline (to Aug 31, 2026)New outline (from Sep 1, 2026)
Security Principles, 26%Security Principles, 24%
BC, DR & Incident Response, 10%Security Governance, 17.3% (new)
Access Controls Concepts, 22%Identity and Access Management, 20%
Network Security, 24%Networking and Cloud Security, 21.3%
Security Operations, 18%Security Operations and Incident Response, 17.3%

Business continuity and disaster recovery did not disappear. They moved inside the new Governance domain as "redundancy." Incident response moved into Security Operations. In exchange you get genuinely new material: cloud security as a named topic, measuring cybersecurity effectiveness with metrics and dashboards, security testing including red, blue, and purple teaming, and quantum resistant cryptography. AI security concepts are also woven through all five domains rather than sitting in one place.

The other thing that changed
For nearly four years the CC was free through the One Million Certified in Cybersecurity program. ISC2 closed that program to new participants on May 20, 2026. The CC is now a standard paid exam: $199 plus a $50 annual maintenance fee once you certify. Anyone who already holds an unexpired voucher can still sit through December 31, 2026. If an article tells you the CC is free, it was written before May.

What you are walking into

The CC is a computerized adaptive test (CAT). It delivers between 100 and 125 items in 2 hours, mixing multiple choice with what ISC2 calls advanced item types. Scoring is scaled and you need 700 out of 1000. There is no published percentage, and because it adapts, two candidates do not see the same questions. You cannot return to a previous question once you answer it, so commit as you go.

There are no prerequisites and no experience requirement. ISC2 recommends basic IT familiarity, nothing more. This is the deliberate on-ramp to the field, and it is the same organization that runs the CISSP, so passing it also teaches you how ISC2 writes questions.

What this practice tool reproduces, and what it cannot
No static bank can reproduce adaptive testing, because CAT selects each item based on how you have answered so far. This mock is a fixed-length linear approximation at 100 items with a 2 hour clock, weighted exactly to the new blueprint. It gives you breadth, pacing, and the reasoning style. Treat a consistently strong score as a readiness signal, not as a simulation of the algorithm.

How to think about CC questions

A common mistake is preparing for the CC as though it were a small CISSP. It is not. The CISSP asks you to choose the best answer among several defensible management decisions. The CC asks you to apply a foundational concept to a straightforward situation: pick the right access control model for a scenario, name the correct network device, choose the appropriate next step in an incident. The answers are more clear-cut. Learn the concepts precisely and the exam is fair.

The order that works

Your study plan

Exam Outline

What the exam is made of.

Five domains under the outline effective September 1, 2026. The spread is unusually flat: the largest is 24% and the smallest 17.3%, so there is no domain you can afford to ignore.

24%Principles17.3%Governance20%IAM21.3%Network & Cloud17.3%Ops & IR
Five domains 100-125 adaptive items

This is the flattest blueprint in the catalog. Compare it to the PMP, where one domain carries 41%, or the old CC outline, where a domain carried just 10%. Here every domain sits between 17.3% and 24%, which means study time should be spread far more evenly than candidates usually expect. There is no safe domain to skim.

The five domains

DomainWeightWhat it covers
1. Security Principles24%CIA, AAA, non-repudiation, privacy, the risk management lifecycle, governance concepts, control types, due care and due diligence, the ISC2 Code of Ethics.
2. Security Governance17.3%GRC planning, redundancy (business continuity and disaster recovery), security awareness and organizational culture, and measuring effectiveness with metrics, KRIs, and dashboards.
3. Identity and Access Management (IAM)20%The identity lifecycle (roles, provisioning, review, deprovisioning), least privilege, separation of duties, and the access control models.
4. Networking and Cloud Security21.3%OSI and TCP/IP, IPv4 and IPv6, VPNs, firewalls and ports, wireless, embedded and IoT, segmentation, defense in depth, zero trust, and cloud characteristics, service models, deployment models, and shared responsibility.
5. Security Operations and Incident Response17.3%Data handling and encryption (including quantum resistant), logging and monitoring, event triage, threat actors and intelligence, incident response plans and exercises, asset lifecycle, change management, and security testing.

The format

DeliveryComputerized adaptive testing (CAT) in all available languages.
Items100 to 125. The algorithm stops when it has enough evidence.
Time2 hours.
Item typesMultiple choice and advanced item types.
Pass mark700 out of 1000, scaled. No published percentage.
NavigationNo going back. Once answered, an item is locked.
ExperienceNone required. Basic IT familiarity recommended.
WherePearson VUE test center.
Cost$199 exam, plus $50 annual maintenance fee once certified.
AccreditationANAB, ISO/IEC 17024. Approved under U.S. DoDM 8140.03.
Where pre-2026 material will fail you
Three areas are effectively new and will not appear in older study guides: cloud security (the five essential characteristics, service and deployment models, shared responsibility), measuring cybersecurity effectiveness (key metrics, KRIs, dashboards, scorecards), and security testing (red, blue, and purple teaming, vulnerability scanning, static and dynamic analysis, threat modeling, physical penetration testing). Quantum resistant cryptography is also named explicitly for the first time.
Domain 1 24% · largest

Security principles.

The largest domain and the vocabulary the other four are written in. Everything here is definitional and precise, which makes it the highest-return studying you can do: get these terms exactly right and questions across the whole exam become easier.

1.1 Cybersecurity concepts

1.2 Risk management

1.3 Governance concepts

Learn this hierarchy cold. The CC asks which document type fits a described situation.

DocumentWhat it is
Regulations and lawsExternally imposed and legally binding. Non-compliance brings penalties.
PolicyHigh-level management intent and direction. Mandatory.
StandardSpecific mandatory requirements supporting a policy (for example ISO or CIS benchmarks).
ProcedureStep-by-step instructions for carrying something out. Mandatory.
GuidelineRecommended good practice. Not mandatory.

1.4 Control types

1.5 Professional and ethical conduct

Domain 2 17.3% · new domain

Security governance.

Brand new in the September 2026 outline. This domain did not exist before, and it absorbed business continuity and disaster recovery from the old Domain 2 while adding genuinely new material on measuring whether security is actually working. If your study guide predates 2026, this entire section is missing from it.

2.1 Governance, Risk, and Compliance (GRC)

2.2 Redundancy: business continuity and disaster recovery

This is where BC and DR now live. The distinction between them is heavily tested.

Business Continuity (BC)Disaster Recovery (DR)
GoalKeep the business operating during a disruptionRestore systems and data after one
ScopeThe whole organization: people, process, facilities, communicationPrimarily IT systems and infrastructure
Question it answersHow do we keep working?How do we get it back?

2.3 Security awareness

2.4 Measuring cybersecurity effectiveness

New material, and the part most likely to catch out anyone using older resources.

Domain 3 20%

Identity and access management.

Renamed and widened from the old "Access Controls Concepts." The models are the same, but the new outline adds the full identity lifecycle, so it is no longer enough to know what RBAC is. You need to know how an identity is created, reviewed, and removed.

3.1 The identity lifecycle

An identity has a beginning, a middle, and an end. Most real-world breaches exploit a failure at one of these stages.

StageWhat happens
Roles definitionDecide what access each job function legitimately needs, before anyone is granted anything.
ProvisioningCreate the account and grant access, at onboarding or role change. Grant the minimum needed.
ReviewPeriodically recertify that each person's access is still appropriate. This is what catches privilege creep.
DeprovisioningRemove access promptly when someone leaves or changes role. Failing here leaves orphaned accounts.

3.2 Logical access controls

The access control models

Given a scenario, name the model. This is one of the most reliably tested items on the exam.

ModelWho decides accessTypical use
DAC (Discretionary)The owner of the resource, at their discretionFile permissions on a shared drive. Flexible but easy to over-share.
MAC (Mandatory)The system, using classification labels and clearancesGovernment and military. Most rigid; users cannot change permissions.
RBAC (Role-Based)Assigned to job roles, and users are placed in rolesMost common in business. Scales well.

The tells: if a user chooses who to share with, it is DAC. If the system enforces labels the user cannot override, it is MAC. If access follows a job title, it is RBAC.

Physical access controls

Domain 4 21.3% · cloud is new

Networking and cloud security.

The old outline covered networks. The new one adds cloud security as a named section, with specific vocabulary ISC2 expects you to reproduce. That vocabulary is the single most likely place for an older study guide to leave you unprepared.

4.1 Computer networking

4.2 Network security architecture

4.3 Cloud security

The five essential characteristics
ISC2 names these explicitly, so learn them as a set: broad network access (reachable over the network from many devices), rapid elasticity (scales up and down quickly with demand), measured service (usage is metered and billed), on-demand self-service (you provision it yourself without human help), and resource pooling (one provider's shared resources serve many customers).
Service modelYou manageProvider manages
IaaS (Infrastructure)OS, applications, dataHardware, network, virtualization
PaaS (Platform)Your applications and dataOS, runtime, infrastructure
SaaS (Software)Your data, users, and configurationNearly everything else
Domain 5 17.3%

Security operations and incident response.

The old Security Operations domain absorbed incident response and grew substantially. It now also covers threat intelligence, asset lifecycle, and security testing, including red, blue, and purple teaming. Several of these topics are new to the CC.

5.1 Data security

5.2 Security operations

5.3 Incident response

The order matters, and containment comes before eradication. Stop the spread first.

PhaseWhat happens
1. PreparationBuild the plan, team, and tools before anything happens.
2. Detection and analysisIdentify that something is wrong and understand its scope.
3. ContainmentLimit the spread and the damage.
4. EradicationRemove the cause from the environment.
5. RecoveryRestore systems to normal operation and verify.
6. Post-incidentLessons learned, so it goes better next time.

5.4 Asset protection

5.5 Security testing

Reference

Glossary.

High-yield terms as the September 2026 CC outline uses them, weighted toward the distinctions the exam turns on and the material that is new this revision.

AAA
Authentication (proving who you are), Authorization (what you may do), Accounting (recording what you did).
Access control vestibule
A two-door enclosed space letting one person through at a time to prevent tailgating. Formerly called a mantrap.
Asset lifecycle
Acquisition, deployment, maintenance, disposal. You cannot protect what you have not inventoried.
BC vs DR
Business Continuity keeps the whole organization operating during disruption. Disaster Recovery restores IT systems afterward. BC is the umbrella.
CIA triad
Confidentiality, Integrity, Availability. The three goals security protects.
Cloud: five characteristics
Broad network access, rapid elasticity, measured service, on-demand self-service, resource pooling.
Control types
Technical (in technology), Administrative (in policy and people), Physical (in the real world).
DAC / MAC / RBAC
Owner decides / system enforces labels / access follows job role.
Defense in depth
Layered, diverse controls so no single failure exposes the asset.
Due care vs due diligence
Due care is acting as a reasonable person would to protect assets. Due diligence is the investigation and verification behind it.
Event vs incident
An event is any observable occurrence. An incident is an event that harms or threatens security.
Incident response order
Preparation, Detection and Analysis, Containment, Eradication, Recovery, Post-incident. Containment before eradication.
ISC2 Code of Ethics
Four canons in priority order: protect society; act honorably; serve principals diligently; advance the profession. Earlier canons win conflicts.
KPI vs KRI
A KPI measures performance against a goal (backward-looking). A KRI gives early warning that risk is rising (forward-looking).
Least privilege vs separation of duties
Least privilege limits how much one person can access. Separation of duties splits a process so no one person completes it alone.
MFA
Combining authentication factors of different types (know, have, are). Two passwords is not MFA.
Non-repudiation
Inability to credibly deny an action. Provided by digital signatures.
Orphaned account
An active account belonging to someone who has left. A deprovisioning failure and a classic audit finding.
Privilege creep
Access accumulating as someone changes roles without old rights removed. Caught by access reviews.
Quantum resistant cryptography
Algorithms designed to withstand attack by future large-scale quantum computers. New to this outline.
Red / blue / purple team
Red attacks, blue defends, purple is the collaboration that turns findings into improvements.
Risk terms
Asset (something of value), threat (potential danger), vulnerability (weakness a threat exploits), risk (likelihood and impact combined).
Risk treatment
Mitigate, transfer, avoid, accept. Acceptance is a documented management decision.
RTO vs RPO
RTO is how fast a system must be restored. RPO is how much data you can afford to lose, which drives backup frequency.
Shared responsibility model
The provider secures the cloud; you secure what you put in it. Your data and user access are always yours.
Zero Trust
Never trust, always verify. Every request evaluated on identity, device, and context regardless of network location.
Common questions

ISC2 CC exam questions, answered

How many questions are on the ISC2 CC exam?

The ISC2 CC exam has 100 questions and lasts 120 minutes. ISC2 uses a scaled score rather than a published percentage, so there is no fixed pass mark to quote.

What is on the ISC2 CC exam?

The exam covers 5 domains: Principles (24%), Governance (17.3%), IAM (20%), Network & Cloud (21.3%), Ops & IR (17.3%). These weightings come from ISC2's Exam Outline eff. 1 Sep 2026.

Is this ISC2 CC material current?

Yes. This guide was written from ISC2's own published outline, Exam Outline eff. 1 Sep 2026, and last checked against that document on 22 July 2026. That date is shown on every page so you can judge for yourself rather than take our word for it.

Are there free ISC2 CC practice questions?

Yes. Sample questions with full worked explanations are free and need no account. The complete question bank and the full-length 100-question timed mock are paid.

Practise it

The guide above is free. The question bank and the full-length timed mock are the paid part.

Open CC →
Other exams:
PMP · CAPM · PMI-ACP · PSM I · PRINCE2 · ITIL · ISTQB CTFL · Network+ · Security+ · CISSP · AWS CCP

Cutscores is independent and is not affiliated with, authorised by, endorsed by or sponsored by ISC2 or any certification body. CC and all certification names and marks are the property of their respective owners, and are used here only to describe which exam this material prepares you for. We do not reproduce live exam content.