Reinforce CC concepts with active-recall study cards covering all 6 blueprint domains. Each card shows the question on the front and the correct answer with a full explanation on the back.
Flashcards work through active recall — the process of retrieving information from memory rather than passively re-reading it. Research consistently shows that active recall produces stronger, longer-lasting memory than re-reading study guides. For CC preparation, this means flashcards are one of the highest-return study tools available.
Attempt recall first
Read the CC question on each card, pause, and attempt to formulate the answer in your own words before revealing. This retrieval attempt — even if wrong — dramatically strengthens memory compared to immediately reading the answer.
Review wrong cards again
When you get a card wrong, note it and add it back to your review pile. Spaced repetition — seeing difficult cards more frequently — is the mechanism that makes flashcard study far more efficient than linear reading.
Study by domain
Group your CC flashcard sessions by domain for the first 3–4 weeks. Master one domain before moving to the next. In the final week, shuffle all cards together to test cross-domain recall — which is what the real CC exam requires.
Short sessions beat marathon reviews
20–30 flashcard cards per session, done daily, produces better retention than a single 200-card marathon session. Five short daily sessions per week over 4 weeks gives you over 400 total card reviews — enough to reliably pass CC.
Sample cards from the CC flashcard bank. Read the question, think of the answer, then read the explanation below.
Which tier in a Security Operations Center (SOC) is primarily responsible for triaging alerts and determining whether to escalate?
Tier 1
Tier 1 analysts are the first line of defense in a SOC, responsible for monitoring incoming alerts, performing initial triage, and deciding whether to escalate to Tier 2. They follow predefined playbooks to filter false positives and validate true positives. This role is explicitly designed for rapid alert assessment, not deep investigation or management.
A security analyst notices repeated failed login attempts from an internal IP address to a domain controller, followed by a successful login. Which log type is most likely to provide detailed evidence of this activity?
Authentication logs
Authentication logs record login attempts, successes, failures, source IP addresses, timestamps, and account names, making them the definitive source for investigating repeated failed logins followed by a successful login. Domain controllers log authentication events (e.g., Windows Security Event ID 4625 for failed logon and 4624 for successful logon) that directly capture this pattern. This is the primary evidence source for credential-based attacks like brute force or password spraying.
An organization must comply with PCI DSS log retention requirements. What is the minimum retention period for logs, and how long must they be immediately available for analysis?
12 months retention, 3 months immediately available
PCI DSS requires logs to be retained for at least 12 months, with the most recent 3 months immediately available for review.
Which OSI layer is responsible for routing packets across networks using IP addresses?
Layer 3 - Network
The Network layer (Layer 3) is responsible for logical addressing and routing. It uses IP addresses to determine the best path for packets to travel from source to destination across different networks. Protocols like IP (IPv4/IPv6), OSPF, and BGP operate at this layer to perform routing decisions.
A security analyst notices unusual traffic from an internal workstation to an external IP address on port 25. Which protocol is most likely being used?
SMTP
SMTP (Simple Mail Transfer Protocol) operates over TCP port 25 by default for relaying and receiving email. Unusual outbound traffic on port 25 from an internal workstation often indicates a compromised host sending spam or a malware infection attempting to exfiltrate data via email. The other protocols listed use different default ports: FTP uses 20/21, DNS uses 53, and HTTP uses 80.
In the OSI model, which layer uses MAC addresses to forward frames and supports VLANs?
Layer 2 - Data Link
The Data Link layer (Layer 2) is responsible for framing, MAC addressing, and forwarding frames within a local network segment. VLANs (802.1Q) are a Layer 2 construct that logically segments a switch into multiple broadcast domains, and VLAN tags are inserted into Ethernet frames — making Layer 2 the correct answer. Switches use MAC address tables to forward frames and enforce VLAN membership.
An attacker captures network traffic and forges the source IP address to impersonate a trusted host. Which type of network threat is this?
Spoofing
Spoofing is the act of forging a source IP address (or other identity field) to impersonate a trusted host. In this scenario, the attacker captures traffic and crafts packets with a falsified source IP to make them appear to originate from a trusted system. This is the definition of IP spoofing, a foundational network threat.
Which principle of the CIA triad ensures that data is not disclosed to unauthorized individuals?
Confidentiality
Confidentiality is the CIA triad principle that ensures information is not disclosed to unauthorized individuals, systems, or processes. It is enforced through encryption, access controls, and data classification. Authentication verifies identity but does not itself guarantee confidentiality, and integrity and availability address different properties.
Which of the following is an example of a Type 2 authentication factor?
Smart card
A Type 2 authentication factor is something you have, such as a physical device or token. A smart card is a physical object that a user possesses and inserts into a reader or taps, making it a classic example of a possession factor. Therefore, smart card is the correct answer.
An organization implements redundant servers and failover mechanisms to ensure continuous operation during a power outage. Which goal of the CIA triad is primarily being addressed?
Availability
Availability ensures that systems and data are accessible to authorized users when needed, and redundant servers with failover mechanisms directly support continuous operation during outages. This is the core goal of the availability pillar of the CIA triad. Confidentiality and integrity address different concerns, so availability is the correct answer.
According to the (ISC)² Code of Ethics, which of the following obligations takes the highest priority?
Protect society
The (ISC)² Code of Ethics Canons are ordered by priority, and the first canon — 'Protect society, the common good, necessary public trust and confidence, and the infrastructure' — takes precedence over all others. This means that when obligations conflict, the safety and welfare of society outweigh duties to employers, clients, or the profession. The remaining canons (act honorably, provide diligent service, advance the profession) are subordinate to this top-level obligation.
A company is developing a business continuity plan. Which document identifies critical business functions and their dependencies, including the maximum acceptable downtime?
Business Impact Analysis (BIA)
A Business Impact Analysis (BIA) identifies critical business functions, their dependencies, and the maximum acceptable downtime (MTD) and recovery objectives. It is the foundational analysis that feeds the BCP and DRP. The question's description of identifying critical functions and dependencies with maximum acceptable downtime is the textbook definition of a BIA.
Which principle ensures that users are granted only the minimum permissions necessary to perform their job functions?
Least privilege
The principle of least privilege states that users (and processes) should be granted only the minimum permissions necessary to perform their job functions, reducing the attack surface and limiting the blast radius of a compromised account. It is a foundational access-control principle in cybersecurity and is explicitly tested in the ISC2 CC exam. Defense in depth, separation of duties, and need-to-know are related but distinct concepts.
A security administrator is reviewing physical access controls. Which control is considered an external perimeter security measure?
Fencing around the property
Fencing around the property is an external perimeter security measure because it establishes the outermost physical boundary of the facility, deterring and delaying unauthorized entry before an attacker reaches the building. Perimeter controls focus on the site's outer edge, while the other options protect interior assets or personnel behavior. Fencing, bollards, lighting, and gates are classic examples of external perimeter defenses.
An organization implements a policy where no single employee can approve a financial transaction over $10,000; a second manager must also approve. This is an example of which access control principle?
Separation of duties
Requiring two separate approvals for a high-value transaction is the classic definition of separation of duties: no single individual has enough authority to complete a sensitive action alone. This prevents fraud and error by distributing control across multiple people.
During a ransomware incident, the incident response team isolates affected systems. Which of the following is the NEXT best step?
Preserve forensic evidence from the isolated systems.
After isolating affected systems during a ransomware incident, the next best step is to preserve forensic evidence from those systems. This ensures that data such as memory dumps, logs, and encrypted files are captured intact for analysis, which is critical for understanding the attack vector, identifying the ransomware variant, and potentially recovering data without paying the ransom. Forensic preservation must occur before any remediation steps like wiping or rebuilding, as those actions would destroy the evidence needed for investigation and legal proceedings.
The CC flashcard bank covers all 6 official blueprint domains published by ISC2. Cards are distributed proportionally, so domains with higher exam weight have more cards.
Domain Coverage
Security Operations
Network Security
Security Principles
Business Continuity, Disaster Recovery, and Incident Response
Access Controls Concepts
Business Continuity, DR & Incident Response
Both flashcards and practice questions are evidence-based study tools. The difference is in what they train:
Flashcards — concept retention
Best for memorising definitions, acronyms, protocol behaviours, command syntax, and conceptual distinctions. Use flashcards to build the foundational vocabulary that CC questions assume you know.
Best in: weeks 1–3
Practice tests — application
Best for applying concepts to realistic scenarios, eliminating distractors, and building exam stamina.CC questions test scenario reasoning — not just recall — so practice tests are essential.
Best in: weeks 3–6
The most effective CC study plan combines both: use flashcards for the first 2–3 weeks to build conceptual foundations, then shift to practice tests and mock exams in the final 2–3 weeks to apply and benchmark that knowledge. Most candidates who pass on their first attempt use both tools.
Yes. Courseiva provides free CC flashcards across all official exam domains. Every card includes the correct answer and a full explanation of why it is right and why the distractors are wrong. The platform also includes topic-based practice, mock exams, and readiness tracking — no account required.
Courseiva has 989+ original CC flashcards across all 6 exam blueprint domains. New cards are added regularly as the question bank grows. All cards are checked against the official ISC2 exam objectives, with editorial oversight from an experienced network and security engineer.
Courseiva flashcards are purpose-built for IT certification exams. Unlike generic flashcard platforms where content quality varies, every Courseiva card is mapped to the official CC exam blueprint, written by engineers who hold the certification, and includes a full explanation of the correct answer and why the distractors are wrong. This explanation quality is what separates genuine learning from rote memorisation.
Courseiva is a web platform — an internet connection is required. For offline study, we recommend creating free Courseiva account, using the platform in your browser, and using your device's offline capabilities if your browser supports offline web apps.
Save your results, see which domains need more work, and get spaced repetition recommendations — all free.
Sign Up FreeFree forever · Every certification included