CC:网络安全认证 Practice Exam — CC:Certified in Cybersecurity

1. The question bank is cloud‑connected and updates automatically; no manual re‑acquisition is required.

2. Start practicing right after activating the question bank. It supports simultaneous use on websites and mini‑programs, with one‑click bilingual switching for each question.

3. Functions include online practice, mock tests, note‑taking, wrong‑question recording, etc., valid for one year.

4. Recommended practice order: Turn on review mode to browse questions → Complete sequential practice → Take mock exams for pre‑test self‑assessment.

5. Activation codes can be purchased by clicking Buy Now on the right or via our official Tmall flagship store.

6. For inquiries, contact customer service through mini‑program, WeChat, WhatsApp or LINE.

Exam information

1. Basic Exam Information (CC)

Item  Details

-

Certification Name  ISC² Certified in Cybersecurity (CC)

Exam Code:  CC

Certification Body:  ISC² (International Information System Security Certification Consortium)

Certification Level:  Entry-level / Junior Cybersecurity Certification

Exam Format:  Since October 1, 2025, the traditional linear exam has been fully replaced by Computerized Adaptive Testing (CAT)

Delivery Mode:  Online proctored exam via Pearson VUE OnVUE or on-site exam at authorized test centers, available globally

Question Types:  Single-choice questions and multiple-choice questions

Number of Questions:  100 – 125 questions. The total quantity and difficulty are dynamically adjusted based on each candidate’s performance under the CAT model.

Exam Duration:  2 hours (120 minutes), including check-in and system preparation time

Passing Score:  700 out of 1000 (scaled scoring system). Only the pass/fail result will be displayed after the exam; the exact score will not be released.

Exam Fee:  $199 USD (taxes excluded), uniform price worldwide

Available Languages:  English, Simplified Chinese, Japanese, German, Spanish and other languages

Certification Validity:  3 years (effective from 2026; certificates issued prior are lifetime valid)

Recertification Requirements:  Earn 60 CPE (Continuing Professional Education) credits within every 3-year cycle, or retake the current version of the CC exam

Accreditation  ANAB accredited and compliant with the ISO/IEC 17024 international standard. It is a globally recognized entry-level cybersecurity certification.




2. Certification Objectives & Target Audience

Core Certification Objectives

This certification validates that candidates possess the fundamental knowledge, skills and competencies required for entry-level cybersecurity roles. It verifies proficiency in basic security best practices, policies and procedures, laying a solid foundation for a career in cybersecurity.


Target Audience

1. IT Professionals: Practitioners seeking to transition from general IT to the cybersecurity field

2. Career Changers: Professionals from non-IT backgrounds with a passion for cybersecurity who intend to launch a new career

3. Students: University students and fresh graduates who wish to obtain an industry-recognized entry credential before employment

4. Cross-functional IT Staff: System administrators, network engineers, software developers and other IT roles looking to expand cybersecurity capabilities

5. Cybersecurity Enthusiasts: Individuals with a strong interest in cybersecurity who want to learn systematically and obtain professional certification




3. Registration Requirements & Procedures

Registration Prerequisites

1. No work experience required: Anyone with enthusiasm and motivation to enter the cybersecurity industry is eligible to apply.

2. No academic background restrictions: Open to candidates with all educational backgrounds.

3. No prerequisite certifications: As the foundational credential in the ISC² certification portfolio, no prior certification is required.


Registration & Exam Procedures

1. Register an ISC² Account

  - Visit the official ISC² certification portal: https://www.isc2.org/certifications/cc

  - Complete account registration and personal profile setup.


2. Schedule the Exam

  - Select your preferred exam language and delivery mode (online proctoring or on-site testing).

  - You will be redirected to the Pearson VUE platform to complete scheduling.

  - Submit the payment of $199 USD (credit card and PayPal are accepted).


3. Preparations for Online Exams

  - Conduct the exam in a quiet, private room free from other people.

  - Use a Windows or macOS computer equipped with a functional webcam and microphone.

  - Ensure a stable internet connection (recommended bandwidth: 5 Mbps or above).

  - Install the Pearson VUE OnVUE proctoring software.

  - Prepare a valid government-issued ID (passport, driver’s license or national ID card) for identity verification.


4. Take the Exam

  - Log in 30 minutes in advance for sign-in and device inspection.

  - Comply strictly with proctoring rules; the entire exam session will be video-monitored.

  - No reference materials, books or communication devices are allowed during the exam.


5. Results & Certification

  - The pass/fail result will be displayed immediately after exam completion.

  - An e-certificate and digital badge will be issued within 1 to 3 business days upon passing.

  - You can view and manage your certification in your ISC² account dashboard.




4. Exam Content & Weighting (Effective October 1, 2025)

The CC exam covers five core domains with a total weighting of 100%:


1. Security Principles (26%)

- Core security concepts: CIA Triad (Confidentiality, Integrity, Availability), AAA (Authentication, Authorization, Accounting)

- Security governance and risk management: policies, procedures, standards, guidelines and risk assessment methodologies

- Security controls and defensive strategies: Defense in Depth, Principle of Least Privilege, mainstream security frameworks (NIST, ISO/IEC 27001)

- Laws, regulations and compliance: data protection regulations (GDPR, PIPL), intellectual property and cybersecurity laws


2. Business Continuity, Disaster Recovery & Incident Response (BC/DR/IR) (10%)

- Business Impact Analysis (BIA) and risk assessment

- Development of Disaster Recovery Plans (DRP) and Business Continuity Plans (BCP)

- Incident response lifecycle: Preparation, Detection, Containment, Eradication, Recovery and Post-Incident Review

- Backup strategies and understanding of Recovery Point Objective (RPO) and Recovery Time Objective (RTO)


3. Access Controls (22%)

- Differentiation and implementation of physical access controls and logical access controls

- Identity management and authentication methods: Multi-Factor Authentication (MFA), Single Sign-On (SSO) and biometrics

- Access control models: Discretionary Access Control (DAC), Mandatory Access Control (MAC), Role-Based Access Control (RBAC)

- Privileged Access Management (PAM) and account management best practices


4. Network Security (24%)

- Fundamentals of networking: OSI seven-layer model, TCP/IP protocol suite, IP addressing, network ports and services

- Network security devices: firewalls, Intrusion Detection Systems (IDS), Intrusion Prevention Systems (IPS), VPNs and proxy servers

- Identification and mitigation of common network attacks: DDoS, man-in-the-middle attacks, ARP spoofing, DNS hijacking, etc.

- Wireless security: WPA3 Wi-Fi encryption standards and security configuration for wireless access points


5. Security Operations (18%)

- Security monitoring and log management: SIEM systems, log analysis and security event detection

- System hardening and configuration management: baseline configuration, patch management and vulnerability scanning

- Malware defense: identification and protection against viruses, worms, ransomware, trojans and other threats

- Security awareness and training: user security awareness programs and social engineering defense




5. Exam Preparation Recommendations

Study Plan

Phase 1: Foundation Building (2 – 3 weeks)

- Learn basic cybersecurity concepts and terminology.

- Get familiar with core knowledge across the five exam domains.

- Complete the free ISC² online course *CC Readiness*.

- Dive deep into detailed content of each domain and master all knowledge points specified in the exam outline.

- Read the official exam guide to clarify the exam focus and depth of knowledge required.

- Take advantage of free ISC² Level Up online courses.

- Get accustomed to the CAT format and complete adaptive practice tests.


Core Learning Resources

- ISC² CC Official Exam Outline (October 2025 Version): https://www.isc2.org/certifications/cc/cc-certification-exam-outline

- Free Level Up Courses: https://learn.isc2.org/


Key Preparation Tips

1. Grasp core concepts: Prioritize understanding fundamental theories including the CIA Triad, access control models and networking basics.

2. Focus on security best practices: The exam emphasizes practical application rather than rote memorization of theories.

3. Adapt to the CAT format: Complete adaptive practice tests in advance to get used to dynamic difficulty adjustments.

4. Time management: You need to finish 100–125 questions within 2 hours, with an average of 48 to 72 seconds per question. Do not spend excessive time on difficult items.

5. Prioritize comprehension over memorization: The CC exam assesses your ability to understand and apply cybersecurity concepts.




6. Certification Value & Career Development

Core Certification Value

1. Industry entry credential: A globally recognized entry-level certification that validates fundamental cybersecurity capabilities.

2. Starting point for career advancement: As the foundation of the ISC² certification path, it paves the way for advanced credentials such as SSCP and CISSP.

3. Enhance employability: A standout credential on resumes that improves competitiveness for junior cybersecurity positions.

4. Salary advantage: According to ISC² salary surveys, entry-level cybersecurity professionals with the CC certification earn 10%–15% more than non-certified peers.

5. Global recognition: ANAB-accredited and ISO/IEC 17024 compliant, valid and acknowledged worldwide.


Typical Career Path

Entry-Level Roles (Available after earning CC)

- Junior Cybersecurity Analyst

- Security Operations Center (SOC) Analyst

- System Security Administrator

- Security Compliance Specialist

- Cybersecurity Support Engineer


Career Progression Path

- Pursue advanced certifications: SSCP (Systems Security Certified Practitioner) → CISSP (Certified Information Systems Security Professional)

- Specialize in niche fields: Cloud Security (CCSP), Application Security, Penetration Testing, etc.

- After accumulating 2–3 years of work experience, advance to senior roles such as Cybersecurity Engineer and Security Architect.



Sample questions

CC:网络安全认证 · Q1
Question: #1 Which of the following is NOT an ethical canon of the ISC2?
  • A.
    Protect society, the common good, necessary public trust and confidence, and the infrastructure
  • B.
    Provide active and qualified service to principal
  • C.
    Advance and protect the profession
  • D.
    Act honorably, honestly, justly, responsibly and legally

Answer: B

The Code of Ethics states, "Provide diligent and competent service to principals," not "Provide active and qualified service to principals."; all other options are valid canons of the Code of Ethics (see ISC2 Study Guide, Domain 1). "Provide active and qualified service to principals" is not listed among the ISC2 ethical canons, which focus on broader societal, professional and ethical guidelines rather than specific service obligations to principals. The other options are incorrect because they directly reflect ISC2's ethical canons. "Protect society, the common good, necessary public trust, and infrastructure" emphasizes the responsibility of cybersecurity professionals to protect broader societal interests. "Act honorably, honestly, fairly, responsibly, and legally" outlines the personal integrity and ethical behavior expected of professionals. "Advance and protect the profession" encourages actions that enhance the credibility and standards of the cybersecurity field. Each of these principles is closely aligned with ISC2's commitment to ethics and professional conduct in cybersecurity. Domain Understand ISC2 Code of Ethics
CC:网络安全认证 · Q2
Question: #2 Which of the following is NOT an example of a physical security control?
  • A.
    Security cameras
  • B.
    Remote control electronic locks
  • C.
    Biometric access controls
  • D.
    Firewalls

Answer: D

Firewalls are network security devices that monitor and control incoming and outgoing network traffic based on predetermined security rules to create a barrier between a trusted internal network and untrusted external networks, such as the Internet, to prevent unauthorized access to the network. Firewalls are not physical controls; they are a type of technical control. For example, an organization might use a firewall to block incoming connections from certain IP addresses that are known to be associated with malicious activity. This setup helps protect the network from unauthorized access, viruses, or denial-of-service attacks. The firewall acts as a filter, allowing or blocking traffic based on the network administrator's set of security rules. On the other hand, security cameras, lighting, and guards are all examples of physical security controls. Security cameras monitor and record physical activity in and around a facility. Lighting enhances visibility and can deter criminal activity by making it difficult for intruders to hide. Guards are personnel employed to protect property and individuals by maintaining a physical presence to prevent and deter illegal or unauthorized activity. Each of these controls directly impacts the physical security of an environment by adding layers of protection against physical threats. Domain Understand Security Controls
CC:网络安全认证 · Q3
Question: #3 Which type of attack attempts to trick the user into revealing personal information by sending a fraudulent message?
  • A.
    Cross-Site Scripting
  • B.
    Trojans
  • C.
    Phishing
  • D.
    Denials of Service

Answer: C

A phishing attack emails a fraudulent message to trick the recipient into disclosing sensitive information to the attacker. A Cross-Site Scripting attack tries to execute code on another website. Trojans are software that appear legitimate, but that have hidden malicious functions. Trojans may be sent in a message, but are not the message themselves. A denial of service attack (DoS) consists in compromising the availability of a system or service through a malicious overload of requests, which causes the activation of safety mechanisms that delay or limit the availability of that system or service. Domain Understand Network (Cyber) Threats and Attacks
CC:网络安全认证 · Q4
Question: #4 Which of the following is NOT a feature of a cryptographic hash function?
  • A.
    Useful
  • B.
    Deterministic
  • C.
    Reversible
  • D.
    Unique

Answer: C

A cryptographic hash function should be unique, deterministic, useful, tamper-evident (also referred to as 'the avalanche effect' or 'integrity assurance') and non-reversible (also referred to as 'one-way'). Nonreversible means it is impossible to reverse the hash function to derive the original text of a message from its hash output value (see ISC2 Study Guide, chapter 5, module 1, under Encryption Overview). Thus, the 'reversible' feature is not a feature of a hash function. Domain Understand Data Security
CC:网络安全认证 · Q5
Question: #5 Which physical access control would be MOST effective against tailgating?
  • A.
    Turnstiles
  • B.
    Barriers
  • C.
    Locks
  • D.
    Fences

Answer: A

Turnstiles are designed to allow only one person through at a time, making them the most effective physical access control against tailgating. Tailgating occurs when an unauthorized person follows an authorized person into a secured area. For example, consider a secure corporate office that uses a turnstile at the main entrance. Each employee has a unique badge. When the card is swiped, the turnstile allows one person through. If another person tries to follow (or bypass) without swiping the card, the turnstile remains locked, effectively preventing unauthorized access. The other options are not as effective against tailgating. Fences and barriers are wrong because while they can restrict access to an area, they do not prevent tailgating once an authorized person opens a gate or barrier. Locks are also incorrect because, like fences and barriers, they can secure an area but do not prevent tailgating. Once an authorized person unlocks a door, an unauthorized person can easily follow them inside. Domain Understand Physical Access Controls

FAQ

How many practice questions are available for CC:网络安全认证?

This question bank includes 600 CC:网络安全认证 practice questions covering single and multiple choice, each with answers and explanations.

Are CC:网络安全认证 practice questions available in Chinese and English?

Yes, CC:网络安全认证 practice questions are provided in both Chinese and English.

Can I try CC:网络安全认证 practice questions for free?

Yes. Free sample questions are available on this page, and the full question bank is available after signing up on Zhangxuetu.