ISC2 · Free Practice Questions · Last reviewed May 2026
36real exam-style questions organised by domain, each with the correct answer highlighted and a plain-English explanation of why it's right — and why the others are wrong.
18% of exam · 6 sample questions below
Which tier in a Security Operations Center (SOC) is primarily responsible for triaging alerts and determining whether to escalate?
SOC Manager
Tier 3
Tier 2
Tier 1
Tier 1 analysts perform initial alert triage, validating whether an alert is a true positive and deciding escalation to Tier 2. This matches the stem's requirement for the tier that triages and determines escalation, distinguishing it from Tier 2 investigation and Tier 3 threat hunting.
A security analyst notices repeated failed login attempts from an internal IP address to a domain controller, followed by a successful login. Which log type is most likely to provide detailed evidence of this activity?
Application logs
Firewall logs
System logs
Authentication logs
Authentication logs capture the granular Kerberos and NTLM events on the domain controller, recording each failed attempt (Event ID 4625) and the subsequent successful logon (Event ID 4624) with source IP, account name and logon type. This directly satisfies the stem's requirement for detailed evidence of the brute-force pattern.
An organization must comply with PCI DSS log retention requirements. What is the minimum retention period for logs, and how long must they be immediately available for analysis?
24 months retention, 12 months immediately available
6 months retention, 1 month immediately available
12 months retention, 3 months immediately available
PCI DSS requires audit logs retained for at least 12 months, with the most recent 3 months immediately available for analysis. This satisfies the stem's two-part constraint, balancing forensic history against the cost of keeping older logs readily searchable.
12 months retention, 6 months immediately available
A security administrator is implementing measures to protect log integrity. Which of the following is the most effective method to prevent tampering with logs after they are generated?
Rotating logs daily
Encrypting logs with a symmetric key
Storing logs on the local system drive
Using write-once storage
Write-once storage enforces immutability at the media or object layer, so once a log entry is committed it cannot be altered or deleted, even by privileged accounts. This directly satisfies the requirement to prevent post-generation tampering rather than merely detecting it.
Which of the following is an indicator of a phishing email?
The email has a professional signature with contact information
The email includes a link that directs to a website with a domain similar to, but not exactly, the company's official domain
Lookalike domains use typosquatting or homoglyph characters to imitate a legitimate domain, so the link appears trustworthy while directing victims to attacker-controlled infrastructure. This domain mismatch is a reliable phishing indicator, unlike generic greetings or marketing footers.
The email comes from a known colleague and contains a file attachment they mentioned earlier
The email is sent during regular business hours
What is the primary purpose of using security baselines derived from CIS Benchmarks?
To ensure all systems have the same software versions
To monitor network traffic for anomalies
To automate patch deployment
To establish a secure starting point for system configuration
CIS Benchmarks encode consensus hardening settings, so applying them yields a documented, secure starting configuration rather than a bespoke one. This satisfies the stem's aim of a repeatable baseline against which drift and deviations can be measured and remediated.
Want more Security Operations practice?
Practice this domainWhich OSI layer is responsible for routing packets across networks using IP addresses?
Layer 1 - Physical
Layer 3 - Network
Layer 3, the Network layer, handles logical addressing and path selection, so routers use IP addresses to forward packets between distinct networks. Layers 2 and 4 lack routable addressing, making Layer 3 the layer that satisfies the routing requirement in the stem.
Layer 4 - Transport
Layer 2 - Data Link
A security analyst notices unusual traffic from an internal workstation to an external IP address on port 25. Which protocol is most likely being used?
SMTP
Port 25 is the standard TCP port for SMTP, used for sending and relaying email. Outbound traffic from an internal workstation to an external address on this port suggests the host is acting as a mail client or, more likely in this scenario, a compromised machine sending spam.
FTP
DNS
HTTP
In the OSI model, which layer uses MAC addresses to forward frames and supports VLANs?
Layer 2 - Data Link
Layer 2, the Data Link layer, forwards frames using MAC addresses and supports VLANs through 802.1Q tagging, which inserts a VLAN identifier into the Ethernet frame header. This satisfies the stem's requirement for the layer that both addresses frames by MAC and provides VLAN segmentation.
Layer 4 - Transport
Layer 3 - Network
Layer 1 - Physical
An attacker captures network traffic and forges the source IP address to impersonate a trusted host. Which type of network threat is this?
Sniffing
Spoofing
Forging the source IP address to impersonate a trusted host is IP address spoofing. The attacker manipulates the packet header's source field so the receiver believes traffic originates from a legitimate system, enabling masquerade and bypassing trust-based access controls.
Man-in-the-middle
Denial of Service
A security engineer is configuring a network security device that can block malicious HTTP requests based on application-layer inspection. Which device type is most suitable?
Intrusion Prevention System (IPS)
Network-based Intrusion Detection System (NIDS)
Web Application Firewall (WAF)
A Web Application Firewall inspects HTTP request contents at the application layer, matching signatures and rules against payloads, URLs and headers. This lets it block malicious HTTP requests, which a packet-filtering firewall or traditional IPS cannot do at that layer.
Stateful firewall
Which TCP segment is sent to initiate the three-way handshake?
ACK
SYN-ACK
FIN
SYN
SYN initiates the three-way handshake by carrying the synchronise flag with an initial sequence number, prompting the server to reply with SYN-ACK before the client's ACK completes connection setup. This directly satisfies the stem's requirement for the segment that starts the handshake, distinguishing it from data or teardown segments.
Want more Network Security practice?
Practice this domain26% of exam · 6 sample questions below
Which principle of the CIA triad ensures that data is not disclosed to unauthorized individuals?
Authentication
Confidentiality
Confidentiality directly prevents unauthorised disclosure by restricting data access to approved parties only. It is the CIA principle concerned with secrecy, unlike integrity (unauthorised modification) or availability (timely access). This satisfies the stem's requirement that data is not disclosed to unauthorised individuals.
Integrity
Availability
Which of the following is an example of a Type 2 authentication factor?
PIN
Password
Smart card
A smart card is something the user possesses, which defines a Type 2 possession factor. It is not a knowledge factor (Type 1) nor an inherence factor (Type 3), so it satisfies the question's requirement for a possession-based example.
Fingerprint
An organization implements redundant servers and failover mechanisms to ensure continuous operation during a power outage. Which goal of the CIA triad is primarily being addressed?
Confidentiality
Integrity
Authentication
Availability
Redundant servers and failover maintain uptime when a component or power source fails, directly preserving access to systems and data. Availability is the CIA goal concerned with ensuring authorised users can reach resources when required.
According to the (ISC)² Code of Ethics, which of the following obligations takes the highest priority?
Advance the profession
Act honourably
Provide diligent service
Protect society
The (ISC)² Code of Ethics places the safety and welfare of society, the public trust, and the infrastructure above all other obligations. Duties to principals and employers rank lower, so protecting society takes precedence when interests conflict.
A security analyst is reviewing a log that shows an unauthorized user attempted to modify a payroll database. Which security principle is most directly threatened?
Confidentiality
Non-repudiation
Integrity
Modifying a payroll database alters stored data, so its accuracy and trustworthiness are directly threatened. Integrity guarantees data remains unaltered by unauthorised parties; confidentiality concerns disclosure and availability concerns access, neither of which the modification attempt targets.
Availability
A company is evaluating a new cloud service provider. As part of due diligence, they review the provider's security certifications, conduct a site visit, and check references. This process is an example of which risk management strategy?
Risk acceptance
Risk mitigation
Due diligence
Due diligence is the investigative process of verifying a provider's claims before contracting, exactly matching the site visits, certification reviews and reference checks described. It satisfies the stem's requirement to assess risk through pre-engagement scrutiny rather than transferring, avoiding or accepting it.
Risk transfer
Want more Security Principles practice?
Practice this domain5% of exam · 6 sample questions below
A company is developing a business continuity plan. Which document identifies critical business functions and their dependencies, including the maximum acceptable downtime?
Disaster Recovery Plan (DRP)
Business Continuity Plan (BCP)
Incident Response Plan (IRP)
Business Impact Analysis (BIA)
A Business Impact Analysis identifies critical business functions, maps their dependencies, and quantifies the maximum acceptable downtime and data loss, producing the recovery objectives a continuity plan needs. It is the document that establishes those tolerances.
An organization's recovery time objective (RTO) for its customer database is 4 hours, and the recovery point objective (RPO) is 1 hour. The database is backed up every hour using full backups. A disaster occurs at 2:00 PM, and the last successful backup was at 1:00 PM. The system is restored and operational at 5:30 PM, but data from 1:00 PM to 2:00 PM is lost. Which statement is correct?
Both the RTO and RPO were met.
Restoration finished at 5:30 PM, 3.5 hours after the 2:00 PM disaster, inside the 4-hour RTO. The last backup at 1:00 PM means only one hour of data was lost, matching the 1-hour RPO, so both targets were satisfied.
The RTO was met, but the RPO was exceeded.
The RTO was exceeded, but the RPO was met.
Both the RTO and RPO were exceeded.
During a disaster recovery test, an organization uses a warm site. The site has partially configured servers and network infrastructure but lacks recent data. The recovery team expects to have the system operational within 2 days. Which recovery metric is most directly addressed by the warm site's capabilities?
Recovery Point Objective (RPO)
Recovery Time Objective (RTO)
A warm site provides partially configured infrastructure, enabling systems to be operational within roughly two days. That timeframe directly defines the Recovery Time Objective, the maximum acceptable downtime, rather than data loss measured by RPO.
Maximum Tolerable Downtime (MTD)
Work Recovery Time (WRT)
An organization stores backup data on a tape drive (onsite) and also replicates critical data to a cloud storage service. This practice best exemplifies which backup rule?
Incremental backup strategy
Differential backup strategy
Full backup strategy
3-2-1 backup rule
The 3-2-1 rule requires three copies of data, on two different media types, with one copy held offsite. Tape and cloud storage satisfy the two-media requirement, while cloud replication provides the offsite copy, directly matching the stem's onsite tape plus cloud arrangement.
Which recovery site strategy provides the shortest recovery time objective (RTO), typically measured in hours, by maintaining a fully mirrored environment that can be activated immediately?
Warm site
Reciprocal agreement
Cold site
Hot site
A hot site maintains fully mirrored hardware, software and near-live data replication, so operations resume within hours rather than days. This directly satisfies the stem's shortest-RTO constraint, unlike warm or cold sites, which require restoration or configuration before activation.
A security analyst detects unusual outbound network traffic from a server that typically only handles internal file sharing. The traffic appears to be exfiltrating sensitive data. Which phase of the incident response process should the analyst initiate next?
Containment
Analysis
Analysis follows detection: the analyst must validate the alert, scope the exfiltration, and determine impact before escalating. This phase satisfies the stem's need to confirm and understand the suspicious outbound traffic prior to containment or eradication.
Lessons learned
Eradication
Want more Business Continuity, Disaster Recovery, and Incident Response practice?
Practice this domain22% of exam · 6 sample questions below
Which principle ensures that users are granted only the minimum permissions necessary to perform their job functions?
Defense in depth
Least privilege
Least privilege grants each user only the minimum permissions their job requires, limiting blast radius if credentials are compromised. It directly satisfies the stem's constraint of minimum necessary access, unlike broader models such as role-based or discretionary access.
Separation of duties
Need-to-know
A security administrator is reviewing physical access controls. Which control is considered an external perimeter security measure?
Biometric reader on server room door
Cable locks on laptops
Visitor badge policy
Fencing around the property
Fencing defines the outer physical boundary of a site, delaying or deterring intruders before they reach the building. It therefore operates as an external perimeter measure, satisfying the stem's requirement, whereas locks and badge readers sit at internal entry points.
An organization implements a policy where no single employee can approve a financial transaction over $10,000; a second manager must also approve. This is an example of which access control principle?
Separation of duties
Separation of duties splits a sensitive task across multiple people so no single individual holds end-to-end authority. Requiring a second manager's approval for transactions above $10,000 enforces this by preventing one employee from both initiating and authorising payment, directly satisfying the stem's dual-approval constraint.
Least privilege
Need-to-know
Defense in depth
Which of the following is an example of a logical access control?
Security guard at entrance
Visitor logbook
Fence around building
Password complexity policy
Password complexity policies are logical controls because they govern how a subject authenticates to a system, rather than physically restricting entry. They satisfy the stem's requirement for a logical access control by enforcing rules on credentials within Microsoft Entra ID, unlike fences, locks or guards, which are physical controls.
According to NIST SP 800-63, which password policy is most recommended?
Allow short passwords but require numbers and symbols
Use complex passwords with special characters and minimal length
Enforce a minimum length of 8 characters and check against breached password lists
NIST SP 800-63B advises against composition and rotation rules, favouring length and blocklist screening. An eight-character minimum combined with checking against breached password lists directly satisfies that guidance, blocking compromised credentials without imposing complexity or expiry requirements.
Require frequent password changes every 30 days
What is the process of claiming an identity called?
Authentication
Authorization
Accountability
Identification
Identification is the act of a subject presenting a claimed identity, such as a username, before any proof is offered. Authentication then verifies that claim, and authorisation grants access. The question asks specifically about claiming, so identification is the process named.
Want more Access Controls Concepts practice?
Practice this domain5% of exam · 6 sample questions below
During a ransomware incident, the incident response team isolates affected systems. Which of the following is the NEXT best step?
Preserve forensic evidence from the isolated systems.
Isolation halts propagation but volatile evidence such as memory and running processes degrades quickly. Capturing forensic artefacts from the isolated hosts before remediation preserves the timeline and attacker indicators, satisfying the need to understand the intrusion while preventing further encryption.
Wipe and rebuild all affected systems.
Notify law enforcement immediately.
Pay the ransom to restore operations quickly.
An organization's recovery time objective (RTO) for its customer database is 4 hours. During a disaster, the backup restore process takes 2 hours, but reconfigure and test tasks add another 3 hours. Which action best addresses this gap?
Conduct the restore test only during annual disaster recovery drills.
Reduce the recovery point objective (RPO) to minimize data loss.
Increase the RTO to 6 hours.
Automate the configuration and validation steps after restore.
Restore takes two hours, but manual reconfiguration and validation add three, totalling five hours and breaching the four-hour RTO. Automating those post-restore configuration and validation steps removes manual delay, bringing total recovery within the four-hour objective.
A company's business continuity plan includes an alternate work site with full IT capabilities. Which type of recovery site does this describe?
Hot site
A hot site is a fully equipped alternate facility with hardware, connectivity and data already operational, enabling near-immediate resumption. It satisfies the full IT capabilities requirement because recovery needs no equipment provisioning or restoration from backup, unlike warm or cold sites.
Mobile site
Cold site
Warm site
Which TWO actions are appropriate during the identification phase of incident response?
Conduct a post-mortem analysis.
Correlate alerts from multiple sources.
Correlating alerts from multiple sources consolidates indicators during identification, distinguishing genuine incidents from isolated noise. This satisfies the phase's goal of scoping and validating what occurred, enabling accurate classification before containment or eradication activities begin.
Review system logs for anomalies.
Reviewing system logs for anomalies surfaces evidence of malicious or unexpected activity, supporting the identification phase's objective of detecting and scoping an incident. Log analysis confirms whether alerts represent genuine compromise, informing subsequent containment and eradication decisions.
Restore data from backups.
Disconnect affected systems from the network.
Based on the incident log, at which step did the incident response team contain the threat?
14:30 - Scanned system, detected Trojan.Downloader
14:45 - Removed malware via AV
14:25 - Isolated WKS-045 from network
Isolating WKS-045 at 14:25 satisfies the containment requirement by severing the compromised endpoint's network connectivity, preventing lateral movement and further command-and-control communication. Containment means limiting spread, not eradication or recovery, so this action directly matches the incident response phase the question asks about.
14:35 - Escalated to incident handler
You are the incident response lead for a financial services company. At 09:00, the SOC detects unusual outbound traffic from a server in the DMZ to an external IP known to be a command-and-control (C2) server. The server runs a legacy application that cannot be patched. The server is critical for customer transactions, but an alternate manual process can sustain operations for up to 4 hours. The CTO wants to keep the server online to avoid customer impact. The CEO is concerned about data exfiltration. The compliance officer reminds you of regulatory requirements to report breaches within 72 hours. Which action should you take FIRST?
Report the incident to the regulatory authority immediately.
Perform a forensic analysis of the server to determine the scope of compromise.
Disconnect the server from the network and activate the manual process.
Disconnecting the server immediately halts the active C2 channel, stopping potential data exfiltration while the unpatched legacy application cannot be remediated. The four-hour manual process comfortably covers containment and investigation, and rapid isolation supports the 72-hour breach reporting obligation.
Keep the server online under close monitoring to minimize customer disruption.
Want more Business Continuity, DR & Incident Response practice?
Practice this domainThe CC exam has 100 questions and must be completed in 120 minutes. The passing score is 700/1000.
Scenario-based questions covering exam objectives with detailed answer explanations.
The exam covers 6 domains: Security Operations, Network Security, Security Principles, Business Continuity, Disaster Recovery, and Incident Response, Access Controls Concepts, Business Continuity, DR & Incident Response. Questions are weighted by domain — higher-weight domains appear more on your actual exam.
No. These are original exam-style practice questions written against the official ISC2 CC exam objectives. They are not copied from the real exam. Courseiva focuses on genuine understanding, not memorisation of braindumps.
Courseiva tracks your accuracy per domain and routes you toward weak areas automatically. Free, no account required.