This guide covers all official exam objectives for the ISC2 Certified in Cybersecurity (CC) certification, organized into focused chapters for effective learning.
This guide works best as a loop: read a chapter, test yourself with practice questions, look up unfamiliar terms in the glossary, then move to the next chapter.
16 chapters covering every exam objective. Each chapter includes key concepts, exam tips, common traps, comparison tables, and a 5-question quiz at the end.
Start Chapter 1Free timed and untimed practice with instant feedback and full explanations. Pick 10–120 questions per session. Filter by domain to drill your weak areas.
Go to practice testEvery CCterm defined and searchable. Use it when a chapter mentions a concept you haven't seen before or want a quick refresher on.
Browse glossaryExam blueprint, domain weights, passing score, duration, cost, and registration links. Start here if you're new to this certification.
View exam guideIntroduction to Security Principles
Objective 1.1 · Understand the fundamental concepts of information security, including confidentiality, integrity, availability (CIA triad), and non-repudiation.
Authentication and Authorization Methods
Objective 1.2 · Identify and compare authentication and authorization methods, such as passwords, biometrics, MFA, and access control models.
Security Governance and Compliance
Objective 1.3 · Describe security governance, compliance requirements, and the role of policies, standards, and procedures.
Risk Management and Security Controls
Objective 1.4 · Explain risk management concepts and types of security controls (administrative, technical, physical).
Security Awareness and Training
Objective 1.5 · Understand the importance of security awareness, training, and social engineering prevention.
Access Control Fundamentals
Objective 2.1 · Describe the principles of access control, including least privilege, need-to-know, and separation of duties.
Physical Access Controls
Objective 2.2 · Identify physical access controls, such as locks, guards, biometrics, and environmental controls.
Logical Access Controls
Objective 2.3 · Understand logical access control methods, including passwords, tokens, certificates, and access control lists.
Network Security Foundations
Objective 3.1 · Describe basic networking concepts, protocols (TCP/IP, OSI model), and common network threats.
Network Security Components and Controls
Objective 3.2 · Identify network security devices and controls, such as firewalls, VPNs, IDS/IPS, and network segmentation.
Secure Network Architecture and Design
Objective 3.3 · Explain secure network design principles, including DMZs, VLANs, and defense in depth.
Wireless and Remote Access Security
Objective 3.4 · Understand wireless security protocols and remote access security methods (e.g., VPN, RDP).
Security Operations Basics
Objective 4.1 · Describe the role of security operations, including monitoring, logging, and incident detection.
Incident Response and Management
Objective 4.2 · Explain the incident response lifecycle and the steps involved in managing security incidents.
Business Continuity and Disaster Recovery
Objective 5.1 · Describe business continuity (BC) and disaster recovery (DR) concepts and their role in organizational resilience.
BC/DR Planning and Testing
Objective 5.2 · Understand the planning, testing, and maintenance of business continuity and disaster recovery plans.
Free CC practice questions with full explanations. Test what you learn chapter by chapter.
CC Practice Questions