Courseiva
← Back to ISC2 Certified in Cybersecurity CC questions

Scenario-based practice

Refer to the Exhibit Practice Questions

Practise ISC2 Certified in Cybersecurity CC practice questions — original exam-style scenarios covering every exam domain, with detailed explanations, wrong-answer analysis, and common exam traps.

15
scenario questions
CC
exam code
ISC2
vendor

Scenario guide

How to approach refer to the exhibit practice questions

Practise exhibit-style questions that ask you to read a topology, table, command output or diagram before choosing the best answer.

Quick answer

Exhibit-style questions test whether you can read a topology, command output, diagram or table before choosing the best answer.

How to extract the relevant detail from an exhibit.

How topology, command output or routing information affects the answer.

How to avoid answering from memory before reading the evidence.

How to map the exhibit back to the exam objective.

Related practice questions

Related CC topic practice pages

Scenario questions usually connect to one or more exam topics. Use these links to review the underlying concepts behind the scenario.

Practice set

Practice scenarios

Question 1easymultiple choice
Full question →

Refer to the exhibit. A user with this policy tries to list objects in a container but gets an access denied error. What is the most likely reason?

Exhibit

{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Action": "s3:GetObject",
      "Resource": "arn:aws:s3:::bucket1/*"
    }
  ]
}
Question 2mediummultiple choice
Full question →

An analyst reviews the exhibit. Which security principle is being violated by allowing root login via SSH?

Exhibit

Refer to the exhibit.

```
Oct 15 10:23:45 server sshd[1234]: Failed password for root from 192.168.1.100 port 22 ssh2
Oct 15 10:23:46 server sshd[1234]: Failed password for root from 192.168.1.100 port 22 ssh2
Oct 15 10:23:47 server sshd[1234]: Failed password for root from 192.168.1.100 port 22 ssh2
Oct 15 10:23:48 server sshd[1234]: Failed password for root from 192.168.1.100 port 22 ssh2
Oct 15 10:23:49 server sshd[1234]: Failed password for root from 192.168.1.100 port 22 ssh2
```
Question 3mediummultiple choice
Full question →

Refer to the exhibit. A security engineer applies this storage access policy to restrict access. Users outside the 10.0.0.0/16 network report being denied access, which is expected. However, users inside that network also report access denied. What is the likely issue?

Exhibit

{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Action": "s3:GetObject",
      "Resource": "arn:aws:s3:::company-bucket/*",
      "Condition": {
        "IpAddress": {
          "aws:SourceIp": "10.0.0.0/16"
        }
      }
    },
    {
      "Effect": "Deny",
      "Action": "*",
      "Resource": "*",
      "Condition": {
        "NotIpAddress": {
          "aws:SourceIp": "10.0.0.0/16"
        }
      }
    }
  ]
}
Question 4easymultiple choice
Full question →

The exhibit shows recent authentication logs. What type of attack is most likely indicated?

Exhibit

Refer to the exhibit.

```
Mar 15 08:45:23 server sshd[1234]: Failed password for admin from 192.168.1.100 port 22
Mar 15 08:45:26 server sshd[1234]: Failed password for admin from 192.168.1.100 port 22
Mar 15 08:45:29 server sshd[1234]: Failed password for admin from 192.168.1.100 port 22
Mar 15 08:45:32 server sshd[1234]: Accepted password for admin from 192.168.1.100 port 22
```
Question 5mediummultiple choice
Full question →

Refer to the exhibit. A security analyst is reviewing firewall logs and notices repeated denied TCP packets from 192.0.2.10 to internal hosts. The packets are being denied by the access-group "OUTSIDE_IN". What is the most likely reason for these denials?

Exhibit

Refer to the exhibit.

=== syslog output ===
Jan 15 09:23:45 firewall01 %ASA-4-106023: Deny tcp src outside:192.0.2.10/3456 dst inside:10.0.0.5/22 by access-group "OUTSIDE_IN" [0x0, 0x0]
Jan 15 09:23:46 firewall01 %ASA-4-106023: Deny tcp src outside:192.0.2.10/3457 dst inside:10.0.0.5/23 by access-group "OUTSIDE_IN" [0x0, 0x0]
Jan 15 09:23:47 firewall01 %ASA-4-106023: Deny tcp src outside:192.0.2.10/3458 dst inside:10.0.0.5/80 by access-group "OUTSIDE_IN" [0x0, 0x0]
Jan 15 09:23:48 firewall01 %ASA-4-106023: Deny tcp src outside:192.0.2.10/3459 dst inside:10.0.0.6/22 by access-group "OUTSIDE_IN" [0x0, 0x0]
Jan 15 09:23:49 firewall01 %ASA-4-106023: Deny tcp src outside:192.0.2.10/3460 dst inside:10.0.0.6/23 by access-group "OUTSIDE_IN" [0x0, 0x0]
Question 6hardmultiple choice
Full question →

Refer to the exhibit. Which security principle is being supported by the logging of these events?

Exhibit

Mar 15 09:45:22 server sshd[1234]: Failed password for invalid user admin from 10.0.0.5 port 22 ssh2
Mar 15 09:45:23 server sshd[1235]: Failed password for invalid user admin from 10.0.0.5 port 22 ssh2
Mar 15 09:45:24 server sshd[1236]: Failed password for invalid user admin from 10.0.0.5 port 22 ssh2
Question 7hardmultiple choice
Full question →

An analyst reviews the exhibit. What security principle is best demonstrated by this policy?

Exhibit

Refer to the exhibit.

```
{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Action": "s3:GetObject",
      "Resource": "arn:aws:s3:::bucket1/*",
      "Condition": {
        "IpAddress": {"aws:SourceIp": "10.0.0.0/24"}
      }
    },
    {
      "Effect": "Deny",
      "Action": "s3:*",
      "Resource": "arn:aws:s3:::bucket2/*"
    }
  ]
}
```
Question 8mediummultiple choice
Full question →

Refer to the exhibit. A security analyst observes repeated outbound connection attempts from an internal server to external IP addresses on a non-standard port. What is the MOST likely interpretation?

Exhibit

[2025-03-05 14:32:18] BLOCK: src=10.0.2.100 dst=203.0.113.50 port=4444 proto=TCP rule=IDS_Alert_Signature
[2025-03-05 14:32:19] BLOCK: src=10.0.2.100 dst=203.0.113.51 port=4444 proto=TCP
[2025-03-05 14:32:20] BLOCK: src=10.0.2.100 dst=203.0.113.52 port=4444 proto=TCP
Question 9easymultiple choice
Full question →

Refer to the exhibit. An SOC analyst pulled this log snippet. Which type of attack is most likely in progress?

Exhibit

2023-10-15 14:32:01 DENY TCP 10.0.1.10 192.168.1.1 80 8080
2023-10-15 14:32:02 DENY TCP 10.0.1.11 192.168.1.1 80 8080
2023-10-15 14:32:03 DENY TCP 10.0.1.12 192.168.1.1 80 8080
Question 10hardmultiple choice
Full question →

Refer to the exhibit. An IDS generates this alert for traffic from an internal server (10.1.1.50) to an external IP on port 443. The security team investigates and finds that the server is a web application that normally uses TLS 1.2. What does this alert most likely indicate?

Exhibit

Refer to the exhibit.

[IDS Alert Log]
Timestamp: 2024-03-15 10:23:45
Signature: ET POLICY Outgoing SSLv3 Handshake (Possible SSL Stripping)
Source IP: 10.1.1.50
Destination IP: 203.0.113.10
Protocol: TCP
Port: 443
Payload: [Hex dump of ClientHello with version 3.0]
Question 11easymultiple choice
Full question →

Refer to the exhibit. The security principle demonstrated by the default policy is:

Exhibit

iptables -P INPUT DROP
iptables -A INPUT -p tcp --dport 22 -j ACCEPT
Question 12hardmultiple choice
Full question →

Refer to the exhibit. What type of event is this?

Exhibit

Event ID 4625: An account failed to log on. Subject: Security ID: NULL_SID, Account Name: - , Account Domain: -; Logon Type: 3; Account For Which Logon Failed: Security ID: NULL SID, Account Name: administrator; Failure Reason: Unknown user name or bad password; Workstation Name: PC123; Source Network Address: 10.0.0.99;
Question 13hardmultiple choice
Full question →

Refer to the exhibit. The IDS alert indicates a possible SpyEye botnet check-in from an internal host. What immediate action should the analyst take?

Exhibit

Refer to the exhibit.

```
[IDS Alert] Signature: ET TROJAN Win32/SpyEye Checkin
Source IP: 10.10.10.5 -> Destination IP: 203.0.113.50
Time: 2023-03-15 14:32:45
Alert: Priority 1
```
Question 14mediummultiple choice
Full question →

Refer to the exhibit. ``` -rw-r-x--- 1 user1 developers 1024 Apr 12 10:00 config.cfg ``` The security policy states that only the file owner (user1) and members of the developers group should be able to read the file. Which change is necessary to align with the principle of least privilege?

Exhibit

Refer to the exhibit.
```
-rw-r-x--- 1 user1 developers 1024 Apr 12 10:00 config.cfg
```
The security policy states that only the file owner (user1) and members of the developers group should be able to read the file. Which change is necessary to align with the principle of least privilege?
Question 15hardmultiple choice
Full question →

Refer to the exhibit. Which statement best describes compliance with the recovery objectives?

Exhibit

Backup Configuration:
- Full backup: Every Sunday at 01:00
- Incremental backup: Every 4 hours
- RTO: 4 hours
- RPO: 1 hour

These CC practice questions are part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style CC questions with detailed explanations, topic-based practice, mock exams, readiness tracking, and study analytics.