ISC2 · free study guide
ISC2 CC study guide
Certified in Cybersecurity
Free ISC2 CC study guide and exam blueprint. 100 questions in 120 minutes. Written from ISC2's Exam Outline eff. 1 Sep 2026, last checked 22 July 2026. Domain weightings, glossary, and practice questions with worked explanations.
Written from ISC2's Exam Outline eff. 1 Sep 2026. Last checked against that document on 22 July 2026.
100 questions
120 minutes
5 domains
Orientation
The exam just changed.
If you are studying for the CC right now, you are studying for a moving target, and almost nobody has noticed. ISC2 replaced the entire CC exam outline effective September 1, 2026. This is not a light refresh. A domain was removed, a new one was added, and three more were renamed and rescoped. Every study guide, video series, and practice bank written before this year is now describing an exam that no longer exists.
Which exam will you sit?
Sitting on or after September 1, 2026? You get the new outline, and this material is built for it.
Sitting before September 1, 2026? You get the older outline (effective October 1, 2025), which had a standalone "Business Continuity, Disaster Recovery & Incident Response" domain and no Governance or Cloud domain. Most of the content here still applies, but the weighting and structure differ. If your test date is close to the boundary, confirm it before you book.
What actually changed
| Old outline (to Aug 31, 2026) | New outline (from Sep 1, 2026) |
| Security Principles, 26% | Security Principles, 24% |
| BC, DR & Incident Response, 10% | Security Governance, 17.3% (new) |
| Access Controls Concepts, 22% | Identity and Access Management, 20% |
| Network Security, 24% | Networking and Cloud Security, 21.3% |
| Security Operations, 18% | Security Operations and Incident Response, 17.3% |
Business continuity and disaster recovery did not disappear. They moved inside the new Governance domain as "redundancy." Incident response moved into Security Operations. In exchange you get genuinely new material: cloud security as a named topic, measuring cybersecurity effectiveness with metrics and dashboards, security testing including red, blue, and purple teaming, and quantum resistant cryptography. AI security concepts are also woven through all five domains rather than sitting in one place.
The other thing that changed
For nearly four years the CC was free through the One Million Certified in Cybersecurity program. ISC2 closed that program to new participants on May 20, 2026. The CC is now a standard paid exam: $199 plus a $50 annual maintenance fee once you certify. Anyone who already holds an unexpired voucher can still sit through December 31, 2026. If an article tells you the CC is free, it was written before May.
What you are walking into
The CC is a computerized adaptive test (CAT). It delivers between 100 and 125 items in 2 hours, mixing multiple choice with what ISC2 calls advanced item types. Scoring is scaled and you need 700 out of 1000. There is no published percentage, and because it adapts, two candidates do not see the same questions. You cannot return to a previous question once you answer it, so commit as you go.
There are no prerequisites and no experience requirement. ISC2 recommends basic IT familiarity, nothing more. This is the deliberate on-ramp to the field, and it is the same organization that runs the CISSP, so passing it also teaches you how ISC2 writes questions.
What this practice tool reproduces, and what it cannot
No static bank can reproduce adaptive testing, because CAT selects each item based on how you have answered so far. This mock is a fixed-length linear approximation at 100 items with a 2 hour clock, weighted exactly to the new blueprint. It gives you breadth, pacing, and the reasoning style. Treat a consistently strong score as a readiness signal, not as a simulation of the algorithm.
How to think about CC questions
A common mistake is preparing for the CC as though it were a small CISSP. It is not. The CISSP asks you to choose the best answer among several defensible management decisions. The CC asks you to apply a foundational concept to a straightforward situation: pick the right access control model for a scenario, name the correct network device, choose the appropriate next step in an incident. The answers are more clear-cut. Learn the concepts precisely and the exam is fair.
The order that works
- Blueprint first. Five domains, and unlike the old outline none of them is small. The lightest is 17.3%.
- Security Principles is the foundation at 24%, and its vocabulary (CIA, AAA, risk, control types) reappears everywhere else.
- Do not skip the new material. Cloud security and governance metrics are where pre-2026 study guides will leave you blind.
- Drill the models and the lists. Access control models, control types, cloud service models, incident response steps. The CC rewards precise recall of small structured sets.
Your study plan
Exam Outline
What the exam is made of.
Five domains under the outline effective September 1, 2026. The spread is unusually flat: the largest is 24% and the smallest 17.3%, so there is no domain you can afford to ignore.
24%Principles17.3%Governance20%IAM21.3%Network & Cloud17.3%Ops & IR
Five domains
100-125 adaptive items
This is the flattest blueprint in the catalog. Compare it to the PMP, where one domain carries 41%, or the old CC outline, where a domain carried just 10%. Here every domain sits between 17.3% and 24%, which means study time should be spread far more evenly than candidates usually expect. There is no safe domain to skim.
The five domains
| Domain | Weight | What it covers |
| 1. Security Principles | 24% | CIA, AAA, non-repudiation, privacy, the risk management lifecycle, governance concepts, control types, due care and due diligence, the ISC2 Code of Ethics. |
| 2. Security Governance | 17.3% | GRC planning, redundancy (business continuity and disaster recovery), security awareness and organizational culture, and measuring effectiveness with metrics, KRIs, and dashboards. |
| 3. Identity and Access Management (IAM) | 20% | The identity lifecycle (roles, provisioning, review, deprovisioning), least privilege, separation of duties, and the access control models. |
| 4. Networking and Cloud Security | 21.3% | OSI and TCP/IP, IPv4 and IPv6, VPNs, firewalls and ports, wireless, embedded and IoT, segmentation, defense in depth, zero trust, and cloud characteristics, service models, deployment models, and shared responsibility. |
| 5. Security Operations and Incident Response | 17.3% | Data handling and encryption (including quantum resistant), logging and monitoring, event triage, threat actors and intelligence, incident response plans and exercises, asset lifecycle, change management, and security testing. |
The format
| Delivery | Computerized adaptive testing (CAT) in all available languages. |
| Items | 100 to 125. The algorithm stops when it has enough evidence. |
| Time | 2 hours. |
| Item types | Multiple choice and advanced item types. |
| Pass mark | 700 out of 1000, scaled. No published percentage. |
| Navigation | No going back. Once answered, an item is locked. |
| Experience | None required. Basic IT familiarity recommended. |
| Where | Pearson VUE test center. |
| Cost | $199 exam, plus $50 annual maintenance fee once certified. |
| Accreditation | ANAB, ISO/IEC 17024. Approved under U.S. DoDM 8140.03. |
Where pre-2026 material will fail you
Three areas are effectively new and will not appear in older study guides: cloud security (the five essential characteristics, service and deployment models, shared responsibility), measuring cybersecurity effectiveness (key metrics, KRIs, dashboards, scorecards), and security testing (red, blue, and purple teaming, vulnerability scanning, static and dynamic analysis, threat modeling, physical penetration testing). Quantum resistant cryptography is also named explicitly for the first time.
Domain 1 24% · largest
Security principles.
The largest domain and the vocabulary the other four are written in. Everything here is definitional and precise, which makes it the highest-return studying you can do: get these terms exactly right and questions across the whole exam become easier.
1.1 Cybersecurity concepts
- The CIA triad: Confidentiality (only authorized people see it), Integrity (it is not altered), Availability (it is there when needed). Nearly every control maps to one of these three.
- AAA: Authentication (proving who you are), Authorization (what you are allowed to do), Accounting (recording what you did). Note the new outline names all three, where the old one named only authentication.
- Authentication factors: something you know (password), something you have (token), something you are (biometric). Multi-factor authentication (MFA) combines factors of different types. Two passwords is not MFA.
- Non-repudiation: you cannot credibly deny you did it. Digital signatures provide this.
- Privacy: the individual's right to control how their personal information is collected and used, distinct from confidentiality, which is the organization's duty to protect it.
1.2 Risk management
- The vocabulary, precisely: an asset is something of value; a threat is a potential danger; a vulnerability is a weakness a threat could exploit; risk is the likelihood and impact of that happening. Threats exploit vulnerabilities, not the other way round.
- The lifecycle: identify risks, assess them (likelihood and impact), treat them, then monitor and review continuously.
- Treatment options: mitigate (reduce it), transfer (insure or outsource it), avoid (stop doing the activity), accept (knowingly bear it). Acceptance is a legitimate, documented management decision, not a failure.
- Risk tolerance is how much risk the organization is willing to live with, and it drives which treatment is chosen.
1.3 Governance concepts
Learn this hierarchy cold. The CC asks which document type fits a described situation.
| Document | What it is |
| Regulations and laws | Externally imposed and legally binding. Non-compliance brings penalties. |
| Policy | High-level management intent and direction. Mandatory. |
| Standard | Specific mandatory requirements supporting a policy (for example ISO or CIS benchmarks). |
| Procedure | Step-by-step instructions for carrying something out. Mandatory. |
| Guideline | Recommended good practice. Not mandatory. |
1.4 Control types
- Technical (also called logical): implemented in technology. Firewalls, encryption, access control lists, antivirus.
- Administrative (also called managerial): implemented through people and process. Policies, procedures, training, background checks.
- Physical: implemented in the real world. Locks, fences, guards, badge readers, cameras.
- The exam gives an example and asks for the category. A security guard is physical. A policy requiring background checks is administrative. Disk encryption is technical.
1.5 Professional and ethical conduct
- Due care is doing what a reasonable, prudent person would do to protect the organization. Due diligence is the investigation and ongoing verification that informs it. Diligence is the research; care is the responsible action.
- The ISC2 Code of Ethics has four canons, and their order is the answer to conflict questions:
1. Protect society, the common good, necessary public trust and confidence, and the infrastructure.
2. Act honorably, honestly, justly, responsibly and legally.
3. Provide diligent and competent service to principals.
4. Advance and protect the profession.
- When two canons conflict, the earlier canon wins. Protecting society outranks serving your employer. ISC2 tests this directly.
Domain 2 17.3% · new domain
Security governance.
Brand new in the September 2026 outline. This domain did not exist before, and it absorbed business continuity and disaster recovery from the old Domain 2 while adding genuinely new material on measuring whether security is actually working. If your study guide predates 2026, this entire section is missing from it.
2.1 Governance, Risk, and Compliance (GRC)
- Governance is the structure of decision-making: who sets direction, who approves, who is accountable. Security exists to support the organization's mission, not the other way round.
- Risk is the discipline of identifying and treating what could go wrong. Compliance is meeting external obligations from law, regulation, and contract.
- Bringing all three together in one program is the point of GRC: it prevents security decisions being made in isolation from legal duty and business risk.
- Frameworks and tools give you a ready-made structure rather than inventing one: ISO/IEC 27001 for a certifiable management system, the NIST Cybersecurity Framework for risk-based organization, CIS Controls for prioritized technical baselines.
2.2 Redundancy: business continuity and disaster recovery
This is where BC and DR now live. The distinction between them is heavily tested.
| Business Continuity (BC) | Disaster Recovery (DR) |
| Goal | Keep the business operating during a disruption | Restore systems and data after one |
| Scope | The whole organization: people, process, facilities, communication | Primarily IT systems and infrastructure |
| Question it answers | How do we keep working? | How do we get it back? |
- BC is the broader umbrella; DR is a component within it.
- Business impact analysis (BIA) identifies which functions are critical and how long they can be down, producing the recovery priorities everything else follows.
- RTO (recovery time objective) is how quickly a system must be restored. RPO (recovery point objective) is how much data you can afford to lose, which drives backup frequency.
- Redundancy in practice: backups, alternate sites (hot, warm, cold), redundant power (UPS for the immediate gap, generators for the long haul), and geographic dispersion so one regional disaster cannot take out both production and its backup.
2.3 Security awareness
- Organizational culture matters more than any single training session. Where leadership visibly treats security as important, people report mistakes instead of hiding them.
- Social engineering manipulates people rather than technology. Phishing (email), vishing (voice call), smishing (SMS), pretexting, tailgating, and impersonation are the forms to recognize.
- Password protection: unique passwords per account, a password manager, MFA everywhere it is offered, and never sharing credentials.
- People are simultaneously the largest attack surface and, trained well, the most adaptable sensor an organization has.
2.4 Measuring cybersecurity effectiveness
New material, and the part most likely to catch out anyone using older resources.
- Key performance indicators (KPIs) measure how well something is performing against a goal, looking backward at results (for example, percentage of systems patched within the target window).
- Key risk indicators (KRIs) are forward-looking early warnings that risk exposure is rising before a loss occurs (for example, a climbing number of unpatched critical vulnerabilities). KPI measures performance; KRI warns of risk.
- Dashboards present live metrics visually for ongoing monitoring. Scorecards track performance against targets over time. Reports give a fuller narrative for a specific audience.
- Match the presentation to the audience: executives need risk and business impact to make decisions, technical teams need specifics to act on.
Domain 3 20%
Identity and access management.
Renamed and widened from the old "Access Controls Concepts." The models are the same, but the new outline adds the full identity lifecycle, so it is no longer enough to know what RBAC is. You need to know how an identity is created, reviewed, and removed.
3.1 The identity lifecycle
An identity has a beginning, a middle, and an end. Most real-world breaches exploit a failure at one of these stages.
| Stage | What happens |
| Roles definition | Decide what access each job function legitimately needs, before anyone is granted anything. |
| Provisioning | Create the account and grant access, at onboarding or role change. Grant the minimum needed. |
| Review | Periodically recertify that each person's access is still appropriate. This is what catches privilege creep. |
| Deprovisioning | Remove access promptly when someone leaves or changes role. Failing here leaves orphaned accounts. |
- Privilege creep is the accumulation of permissions as someone moves between roles without old access being revoked. Access reviews are the control that catches it.
- Orphaned accounts are active accounts belonging to people who have left. They are a classic audit finding and a favorite attacker foothold.
- The lifecycle now applies to non-human identities too: service accounts, bots, and automated AI agents need the same provisioning, review, and deprovisioning discipline.
3.2 Logical access controls
- Principle of Least Privilege (PoLP): every user and process gets the minimum access needed to do its job, and nothing more. It limits the damage from both mistakes and compromise.
- Separation of Duties (SoD): split a sensitive task so no single person can complete it alone. The person who requests a payment should not be the person who approves it. This makes fraud require collusion.
- These two are frequently confused. Least privilege limits how much one person can access; separation of duties splits a process across people.
The access control models
Given a scenario, name the model. This is one of the most reliably tested items on the exam.
| Model | Who decides access | Typical use |
| DAC (Discretionary) | The owner of the resource, at their discretion | File permissions on a shared drive. Flexible but easy to over-share. |
| MAC (Mandatory) | The system, using classification labels and clearances | Government and military. Most rigid; users cannot change permissions. |
| RBAC (Role-Based) | Assigned to job roles, and users are placed in roles | Most common in business. Scales well. |
The tells: if a user chooses who to share with, it is DAC. If the system enforces labels the user cannot override, it is MAC. If access follows a job title, it is RBAC.
Physical access controls
- Barriers and entry: fences, bollards, locks, badge systems, gates, turnstiles, and an access control vestibule (formerly mantrap), a two-door airlock that lets one person through at a time to stop tailgating.
- Monitoring: security guards, CCTV, alarm systems, and access logs. Guards can exercise judgment; cameras record for later.
- Environmental design uses lighting, sightlines, and landscaping to discourage intrusion and make surveillance natural.
- The distinction between authorized and unauthorized personnel underpins all of it: visitors are escorted, badges are visible, and areas are zoned by sensitivity.
Domain 4 21.3% · cloud is new
Networking and cloud security.
The old outline covered networks. The new one adds cloud security as a named section, with specific vocabulary ISC2 expects you to reproduce. That vocabulary is the single most likely place for an older study guide to leave you unprepared.
4.1 Computer networking
- The OSI model, seven layers: Physical, Data Link, Network, Transport, Session, Presentation, Application. Attacks and devices map to layers, ARP poisoning at Layer 2, IP spoofing at Layer 3, and so on.
- The TCP/IP model condenses these into four: Network Access, Internet, Transport, Application.
- IPv4 uses 32-bit addresses (about 4.3 billion, now exhausted). IPv6 uses 128-bit addresses, solving exhaustion and building in features IPv4 bolted on.
- Ports identify services on a host. Worth knowing: 22 SSH, 25 SMTP, 53 DNS, 80 HTTP, 443 HTTPS, 3389 RDP.
- VPNs create an encrypted tunnel across an untrusted network so remote users reach internal resources securely.
- Wireless: WPA3 is the current Wi-Fi security standard; WEP and WPA are broken or outdated. Bluetooth brings its own risks such as unauthorized data theft from a paired device.
- Embedded systems and IoT: industrial control systems (ICS), medical devices, and smart devices often cannot be patched or taken offline, so they are isolated by segmentation rather than fixed.
4.2 Network security architecture
- Segmentation divides a network so a compromise in one part cannot move freely into another. Firewall zones and the DMZ separate public-facing services from internal systems; VLANs create logical segments; micro-segmentation goes down to individual workloads.
- Defense in depth layers multiple different controls so no single failure exposes the asset. If the firewall is bypassed, encryption, access control, and monitoring are still in the way.
- Zero Trust (ZT): never trust, always verify. Every request is evaluated on identity, device, and context regardless of whether it comes from inside the network. It replaces the old assumption that the interior is safe.
- Defenses: firewalls filter traffic by rules; an IDS detects and alerts; an IPS detects and blocks. A NIDS watches the network, a HIDS watches one host. Antivirus and scanning cover the endpoint.
- Threats to recognize: DDoS, virus, worm, Trojan, on-path (man-in-the-middle), and side-channel attacks.
4.3 Cloud security
The five essential characteristics
ISC2 names these explicitly, so learn them as a set: broad network access (reachable over the network from many devices), rapid elasticity (scales up and down quickly with demand), measured service (usage is metered and billed), on-demand self-service (you provision it yourself without human help), and resource pooling (one provider's shared resources serve many customers).
| Service model | You manage | Provider manages |
| IaaS (Infrastructure) | OS, applications, data | Hardware, network, virtualization |
| PaaS (Platform) | Your applications and data | OS, runtime, infrastructure |
| SaaS (Software) | Your data, users, and configuration | Nearly everything else |
- Deployment models: public (shared, provider-owned), private (dedicated to one organization), community (shared by organizations with common needs), hybrid (a combination, with data and applications moving between them).
- The shared responsibility model is the single most tested cloud idea: the provider secures the cloud, you secure what you put in it. Responsibility shifts toward the provider as you move from IaaS to PaaS to SaaS, but your data and your user access are always yours.
- MSP (managed service provider) and SLA (service-level agreement) matter here too: the SLA defines the measurable service levels a provider must meet.
Domain 5 17.3%
Security operations and incident response.
The old Security Operations domain absorbed incident response and grew substantially. It now also covers threat intelligence, asset lifecycle, and security testing, including red, blue, and purple teaming. Several of these topics are new to the CC.
5.1 Data security
- Data handling: classification assigns a sensitivity level so protection is proportional; labeling marks it so people know how to treat it; masking hides part of a value (showing only the last four digits); sanitization removes data from media before disposal or reuse.
- Encryption: symmetric uses one shared key and is fast, suited to bulk data. Asymmetric uses a public/private key pair, slower but solving key exchange and enabling digital signatures. Hashing is one-way and proves integrity, not confidentiality.
- Quantum resistant cryptography is named for the first time in this outline. The concern is that a future large-scale quantum computer could break today's asymmetric algorithms, so new algorithms are being standardized now. Attackers can also harvest encrypted data today to decrypt later.
5.2 Security operations
- Logging and monitoring: logs record what happened; monitoring watches for what matters. A SIEM aggregates logs from across the environment and correlates them into alerts.
- Event triage: not everything is an incident. An event is any observable occurrence; an incident is one that harms or threatens security. Triage means prioritizing by severity and impact and correlating related signals into a single picture rather than chasing them individually.
- Threat actors and motivations: nation-states (espionage, well resourced), organized crime (financial gain), hacktivists (political or philosophical), insiders (already trusted), and unskilled attackers using others' tools.
- Cyber threat intelligence is collected, analyzed information about adversaries and their methods, used to prioritize defenses before an attack rather than after.
- Threat frameworks give a shared structure for describing adversary behavior, such as MITRE ATT&CK's catalog of tactics and techniques or the Cyber Kill Chain's attack stages.
5.3 Incident response
The order matters, and containment comes before eradication. Stop the spread first.
| Phase | What happens |
| 1. Preparation | Build the plan, team, and tools before anything happens. |
| 2. Detection and analysis | Identify that something is wrong and understand its scope. |
| 3. Containment | Limit the spread and the damage. |
| 4. Eradication | Remove the cause from the environment. |
| 5. Recovery | Restore systems to normal operation and verify. |
| 6. Post-incident | Lessons learned, so it goes better next time. |
- The incident response plan (IRP) documents roles, contacts, escalation paths, and communication so nobody improvises under pressure.
- IR exercises keep the plan real. A tabletop walks through a scenario in discussion with no systems touched, which is the low-risk way to find gaps before a real incident does.
5.4 Asset protection
- Asset lifecycle management: you cannot protect what you do not know you have, so an accurate inventory underpins everything else. Assets move through acquisition, deployment, maintenance, and disposal.
- End of life (EOL) software and devices no longer receive security updates, so known vulnerabilities in them are never fixed. They must be replaced, or isolated and compensated for if replacement is impossible.
- Configuration and change management: establish secure baselines, apply updates and patches, and put changes through documented approval with a rollback plan. Unmanaged change is one of the most common causes of incidents.
5.5 Security testing
- The teams: red attacks (simulating an adversary), blue defends and detects, and purple is the collaboration between them so findings turn into improved defenses rather than just a report.
- Application testing: vulnerability scanning finds known weaknesses automatically; static analysis examines code without running it; dynamic analysis tests the running application; threat modeling identifies what could go wrong during design, before code exists.
- Physical penetration testing tests the human and physical layers: phishing to see who clicks, tailgating through a door behind an employee, and impersonation of staff or vendors.
Reference
Glossary.
High-yield terms as the September 2026 CC outline uses them, weighted toward the distinctions the exam turns on and the material that is new this revision.
- AAA
- Authentication (proving who you are), Authorization (what you may do), Accounting (recording what you did).
- Access control vestibule
- A two-door enclosed space letting one person through at a time to prevent tailgating. Formerly called a mantrap.
- Asset lifecycle
- Acquisition, deployment, maintenance, disposal. You cannot protect what you have not inventoried.
- BC vs DR
- Business Continuity keeps the whole organization operating during disruption. Disaster Recovery restores IT systems afterward. BC is the umbrella.
- CIA triad
- Confidentiality, Integrity, Availability. The three goals security protects.
- Cloud: five characteristics
- Broad network access, rapid elasticity, measured service, on-demand self-service, resource pooling.
- Control types
- Technical (in technology), Administrative (in policy and people), Physical (in the real world).
- DAC / MAC / RBAC
- Owner decides / system enforces labels / access follows job role.
- Defense in depth
- Layered, diverse controls so no single failure exposes the asset.
- Due care vs due diligence
- Due care is acting as a reasonable person would to protect assets. Due diligence is the investigation and verification behind it.
- Event vs incident
- An event is any observable occurrence. An incident is an event that harms or threatens security.
- Incident response order
- Preparation, Detection and Analysis, Containment, Eradication, Recovery, Post-incident. Containment before eradication.
- ISC2 Code of Ethics
- Four canons in priority order: protect society; act honorably; serve principals diligently; advance the profession. Earlier canons win conflicts.
- KPI vs KRI
- A KPI measures performance against a goal (backward-looking). A KRI gives early warning that risk is rising (forward-looking).
- Least privilege vs separation of duties
- Least privilege limits how much one person can access. Separation of duties splits a process so no one person completes it alone.
- MFA
- Combining authentication factors of different types (know, have, are). Two passwords is not MFA.
- Non-repudiation
- Inability to credibly deny an action. Provided by digital signatures.
- Orphaned account
- An active account belonging to someone who has left. A deprovisioning failure and a classic audit finding.
- Privilege creep
- Access accumulating as someone changes roles without old rights removed. Caught by access reviews.
- Quantum resistant cryptography
- Algorithms designed to withstand attack by future large-scale quantum computers. New to this outline.
- Red / blue / purple team
- Red attacks, blue defends, purple is the collaboration that turns findings into improvements.
- Risk terms
- Asset (something of value), threat (potential danger), vulnerability (weakness a threat exploits), risk (likelihood and impact combined).
- Risk treatment
- Mitigate, transfer, avoid, accept. Acceptance is a documented management decision.
- RTO vs RPO
- RTO is how fast a system must be restored. RPO is how much data you can afford to lose, which drives backup frequency.
- Shared responsibility model
- The provider secures the cloud; you secure what you put in it. Your data and user access are always yours.
- Zero Trust
- Never trust, always verify. Every request evaluated on identity, device, and context regardless of network location.
Common questions
ISC2 CC exam questions, answered
How many questions are on the ISC2 CC exam?
The ISC2 CC exam has 100 questions and lasts 120 minutes. ISC2 uses a scaled score rather than a published percentage, so there is no fixed pass mark to quote.
What is on the ISC2 CC exam?
The exam covers 5 domains: Principles (24%), Governance (17.3%), IAM (20%), Network & Cloud (21.3%), Ops & IR (17.3%). These weightings come from ISC2's Exam Outline eff. 1 Sep 2026.
Is this ISC2 CC material current?
Yes. This guide was written from ISC2's own published outline, Exam Outline eff. 1 Sep 2026, and last checked against that document on 22 July 2026. That date is shown on every page so you can judge for yourself rather than take our word for it.
Are there free ISC2 CC practice questions?
Yes. Sample questions with full worked explanations are free and need no account. The complete question bank and the full-length 100-question timed mock are paid.
Practise it
The guide above is free. The question bank and the full-length timed mock are the paid part.
Open CC →