Sample questions
ISC2 Certified in Cybersecurity CC practice questions
A small e-commerce company hosts its web application on a single server with a public IP address. The server runs a Linux OS with Apache, MySQL, and PHP. The company recently exper…
A financial institution requires that no single employee can both initiate and approve a wire transfer. This policy enforces which security principle?
An organization wants to implement defense in depth for its web application. Which combination of controls best illustrates this principle?
A security incident report indicates that an employee used their access to view confidential records unrelated to their job. Which security principle was most likely violated?
A security analyst notices that a user has been granted access to files beyond their job function. Which principle is violated?
A company experiences a ransomware attack that encrypts all files on a server. Which security control would MOST effectively allow recovery without paying the ransom?
A company is deploying a security device that inspects HTTP and HTTPS traffic, applies OWASP rules, and can block malicious requests before they reach the web server. Which device…
During a vulnerability scan, the security team discovers a critical vulnerability on a public-facing server. According to best practices, what should the team do next?
A helpdesk technician receives a report that a user in the finance department cannot access a shared folder on the server. The same server is accessible from other departments. Wha…
Which TWO are true about a differential backup? (Select two.)
Business Continuity, DR & Incident ResponsemediumSee the answer and why each option is right or wrong →An organization encrypts all sensitive data at rest and in transit. Which principle of the CIA triad is primarily being addressed?
A company requires all visitors to sign in, wear a visible badge, and be escorted while on premises. This is an example of:
A security administrator is implementing controls to protect a server room. Which TWO physical security layers should be included as part of a defense-in-depth strategy? (Select TW…
A company is implementing a data loss prevention (DLP) solution. Which strategy BEST balances security and productivity when monitoring outgoing email?
An organization implements a policy where no single employee can approve a financial transaction over $10,000; a second manager must also approve. This is an example of which acces…
Which THREE are differences between a hot site and a cold site? (Select three.)
Business Continuity, DR & Incident ResponsehardSee the answer and why each option is right or wrong →Which TWO of the following are best practices for password management in a corporate environment?
A company's security policy requires that all sensitive data be encrypted at rest and in transit. However, a recent breach occurred because an attacker exploited a misconfigured we…
A security operations center (SOC) analyst is investigating a potential data exfiltration. Which two indicators are most likely signs of data exfiltration?
A company has implemented a role-based access control (RBAC) system. A new employee in the finance department is granted the 'Finance User' role, which allows them to view invoices…
You are the IT security officer for a hospital that handles protected health information (PHI). The hospital uses an electronic health record (EHR) system. You receive a report tha…
A company wants to segment its network into separate broadcast domains to improve performance and security. Which device should be used to achieve this?
A security team is investigating a potential ARP spoofing attack on the local network. Which two measures can effectively detect or prevent such attacks? (Choose two.)
Drag and drop the steps for the incident response process according to NIST into the correct order.