ISC2 Certified in Cybersecurity (CC) practice questions

214 free questions with answers and explanations.

Practice test
  1. 1.A company is implementing a new cloud-based application. The security team needs to ensure that data transmitted between the company's on-premises network and the cloud provider's infrastructure is encrypted and authenticated. Which protocol suite is specifically designed to provide secure communication over an IP network, commonly used in this scenario for site-to-site connections?Network Security
  2. 2.A system administrator is tasked with securing all endpoints within the organization, including laptops, desktops, and servers. The goal is to detect and respond to advanced threats, such as fileless malware and sophisticated ransomware, beyond what traditional antivirus can handle. Which security solution specifically focuses on comprehensive endpoint protection and response capabilities?Network Security
  3. 3.A network administrator is troubleshooting connectivity issues in a corporate office. They observe that devices on different floors cannot communicate with each other, even though they are all connected to the same physical network infrastructure. What network topology characteristic might be causing this issue if logical separation is intended?Network Security
  4. 4.A small office is setting up its first network and wants to ensure that all internal devices can communicate with each other and with the internet securely. They are on a limited budget and need a device that can manage network traffic, assign IP addresses, and provide basic firewall capabilities. Which network device would best meet these requirements?Network Security
  5. 5.A system administrator is configuring a new web server that will host a public-facing e-commerce application. To ensure that only legitimate web traffic (HTTP/HTTPS) can reach the server and to prevent other types of network attacks, which network protocol ports should be explicitly opened on the firewall for this server?Network Security
  6. 6.A company requires all employees to use their corporate laptops for work, even when traveling. The security policy states that these laptops must always be connected to the corporate network securely, regardless of their physical location or the underlying internet connection. Which technology ensures continuous, secure communication back to the corporate network without requiring manual user initiation for every session?Network Security
  7. 7.A company is experiencing slow network performance and occasional data packet loss. An administrator suspects network congestion or faulty equipment. Which core network protocol is primarily responsible for ensuring reliable, ordered, and error-checked delivery of data streams between applications?Network Security
  8. 8.A small business wants to protect its internal network from unauthorized access while allowing employees to browse the internet. Which network device is primarily responsible for filtering incoming and outgoing network traffic based on a defined set of security rules?Network Security
  9. 9.A company is implementing a new security policy that requires all remote employees to securely access the corporate network as if they were physically present in the office. They need a solution that encrypts all traffic and provides a secure tunnel over the public internet. Which technology should they choose?Network Security
  10. 10.A company is implementing a new policy for managing mobile devices used by employees. The policy requires enforcing screen lock passcodes, remotely wiping lost devices, and ensuring specific applications are installed or restricted. Which security solution is specifically designed to centrally manage and secure mobile devices?Network Security
  11. 11.A security team is designing a network architecture for a new data center. They want to implement a highly available and secure perimeter that allows public access to web servers while strictly protecting internal databases. The design includes redundant firewalls and routers, placing the web servers in a neutral zone, and isolating internal resources. What specific network topology concept are they primarily applying?Network Security
  12. 12.A security analyst is investigating a potential data breach where sensitive employee records were exfiltrated from an internal server. The investigation reveals that the attacker gained access through a web application vulnerability and then used this access to move laterally within the network. Which security measure, if properly implemented, would have been most effective in preventing the lateral movement of the attacker to the sensitive data server?Network Security
  13. 13.A large organization with multiple branch offices needs a solution to monitor network traffic for suspicious activity and automatically block known attack patterns in real-time. Which network security device is best suited for both detecting and preventing such malicious activities?Network Security
  14. 14.A company policy mandates that all data exchanged between its internal network and its cloud-hosted applications must be encrypted in transit and authenticated. The company uses Amazon Web Services (AWS) for its cloud infrastructure. Which security measure is most appropriate for securing this communication?Network Security
  15. 15.A security auditor is reviewing a company's remote access solution. They note that employees connect to the internal network using a client application that encrypts all traffic and creates a secure tunnel over the public internet. What type of remote access technology is most likely being utilized?Network Security
  16. 16.A security analyst is investigating a suspected intrusion on the corporate network. They observe unusual outbound traffic patterns and multiple failed login attempts on a critical server. To gain real-time visibility into these activities and correlate events from various network devices and applications, which security solution should the analyst primarily rely on?Network Security
  17. 17.A security auditor is reviewing the configuration of a corporate firewall. The auditor notices a rule that permits 'any' source IP address to connect to an internal web server (port 80/TCP) but restricts access to only 'trusted' destination IP addresses. This rule is directly followed by a rule that implicitly denies all other traffic. What is the most significant security concern with this specific firewall rule related to the internal web server?Network Security
  18. 18.A healthcare organization is designing its network infrastructure and must ensure that patient records (PHI) are strictly isolated from the general administrative network and guest Wi-Fi. Access to PHI must be restricted to authorized medical personnel only. Which network design principle is most critical for achieving this separation and access control?Network Security
  19. 19.A cybersecurity incident response team is investigating a sophisticated attack where an attacker bypassed traditional perimeter defenses. They suspect that malicious code was executed directly on an endpoint, which then communicated with a command-and-control (C2) server. To detect such advanced threats and provide detailed visibility into endpoint activities, which security solution would be most effective?Network Security
  20. 20.A security team is implementing a new policy for mobile device security. Employees frequently use personal smartphones and tablets for work-related tasks, including accessing corporate email and cloud applications. The policy aims to enforce security configurations, manage applications, and remotely wipe data if a device is lost or stolen, without necessarily owning the devices. Which solution is most appropriate for achieving these goals?Network Security
  21. 21.A manufacturing company operates several industrial control systems (ICS) that are critical for production and cannot tolerate downtime. To protect these systems from external threats while allowing limited, controlled access for remote monitoring and maintenance, which network security architecture should be implemented to create a demilitarized zone (DMZ) for the ICS?Network Security
  22. 22.A network administrator is configuring a new Wi-Fi network for a school and needs to select the strongest encryption protocol available to protect sensitive student data. The network will support modern devices. Which Wi-Fi security standard should be prioritized?Network Security
  23. 23.A company is upgrading its network infrastructure and is considering using a protocol that ensures reliable, ordered, and error-checked delivery of data streams. Which of the following core network protocols best fits this description?Network Security
  24. 24.A global company uses a distributed network architecture with data centers and branch offices across different continents. They need a solution that can identify and block known malicious traffic patterns and signatures at the network perimeter before they reach internal systems, acting proactively. Which network security device is best suited for this proactive threat prevention?Network Security
  25. 25.A global technology company is developing a new social media platform. They are particularly concerned about adhering to the General Data Protection Regulation (GDPR) and other international privacy laws. To proactively address these concerns, they decide to embed privacy considerations into the platform's architecture and development process from the very beginning. This approach is best described as:Security Principles
  26. 26.A multinational financial institution is evaluating its overall cybersecurity posture. The board of directors has expressed a desire to accept a higher level of financial risk from cyber-incidents if the potential for higher returns from new digital initiatives is significant. Which concept is the board primarily demonstrating?Security Principles
  27. 27.A security auditor is examining a company's remote access solution. They discover that employees are using a generic, shared username and password for connecting to the company's internal resources from outside the network. Which security best practice is being violated, and what is the primary risk?Network Security
  28. 28.A financial services company processes millions of transactions daily. To ensure that each transaction can be undeniably linked to the specific user who initiated it, preventing them from later denying their actions, which security principle must be enforced?Security Principles
  29. 29.A network administrator is configuring a new switch for a department that handles sensitive customer data. To prevent unauthorized devices from connecting to specific switch ports, the administrator enables a feature that binds specific MAC addresses to individual ports. What security feature is being implemented?Network Security
  30. 30.A security team is conducting a post-incident review after a successful phishing attack led to a small data breach. They are analyzing the steps taken from the moment the attack was detected until the breach was contained and eradicated. Which phase of the incident response process are they primarily focused on?Security Principles
  31. 31.A government agency is updating its data handling procedures to comply with new legislation regarding classified information. The new rules specify that data classified as 'Top Secret' must be stored on systems physically isolated from all other networks and accessed only by personnel with specific clearances in a secured facility. This approach primarily aims to enforce which security principle?Security Principles
  32. 32.A company policy states that all employees must use a strong password of at least 12 characters, including uppercase, lowercase, numbers, and symbols. This policy is then specifically implemented through an automated system that enforces these rules during password creation and periodic changes. Which type of security control does the automated system represent?Security Principles
  33. 33.A company is implementing a new network-based Intrusion Detection System (IDS). To ensure the IDS can monitor all traffic traversing between the internal network and the internet without interfering with the traffic flow, where should the IDS sensor typically be placed?Network Security
  34. 34.A company is implementing a new policy that requires all employees to complete a mandatory online course on phishing awareness. What type of security control is this policy primarily categorized as?Security Principles
  35. 35.A network administrator is implementing a new wireless network in a corporate office. The security policy mandates the strongest available encryption and authentication protocols for Wi-Fi. Which Wi-Fi security standard should the administrator configure?Network Security
  36. 36.A software development team is adopting a 'shift-left' security approach for a new application. During which phase of the Software Development Life Cycle (SDLC) would security testing be MOST emphasized in this approach?Security Principles
  37. 37.A small e-commerce company is developing a new online payment gateway. To ensure that the payment process is secure and that only authorized transactions occur, they implement a system where each transaction must be approved by two different managers before it is processed. This control aims to prevent a single point of failure or malicious activity by one individual. Which security principle is primarily being addressed by this two-manager approval process?Security Principles
  38. 38.A healthcare provider is deploying a new electronic health record (EHR) system. The system must meet HIPAA regulations, which dictate strict rules for protecting patient data. The organization develops a document outlining mandatory actions and prohibitions for employees using the EHR, ensuring compliance and security. What type of security document is this?Security Principles
  39. 39.A healthcare organization is implementing a new electronic health record (EHR) system. They are particularly concerned about ensuring that patient data remains accurate and unaltered during storage and transmission. Which security principle is this organization primarily focused on maintaining?Security Principles
  40. 40.A financial institution is evaluating its risk exposure to a potential cyberattack that could disrupt its online banking services. They have determined that such an attack has a 'Moderate' likelihood of occurring and would result in 'High' financial and reputational damage. The institution has a stated 'risk appetite' that it will not accept any risks with an inherent risk level greater than 'Medium'. What is the most appropriate risk treatment strategy for this identified risk?Security Principles
  41. 41.During a security audit, it's discovered that several former employees still have active accounts with access to sensitive company resources. This directly violates the principle of 'least privilege'. Which core security principle is being undermined by this situation?Security Principles
  42. 42.A critical infrastructure organization operates a Supervisory Control and Data Acquisition (SCADA) system that manages power distribution. A recent risk assessment identified a severe vulnerability in an outdated component of the SCADA system, which, if exploited, could lead to widespread power outages. The organization has calculated the Single Loss Expectancy (SLE) for a successful attack at $5,000,000 and the Annualized Rate of Occurrence (ARO) as 0.2 (meaning an attack is expected once every five years). What is the Annualized Loss Expectancy (ALE) for this risk?Security Principles
  43. 43.A small non-profit organization is concerned about protecting sensitive donor information. They want to ensure that only authorized staff members can view this data. Which security principle are they primarily trying to uphold?Security Principles
  44. 44.A cybersecurity team is performing a comprehensive assessment of an organization's network infrastructure. They discover that several legacy servers are running outdated operating systems with known vulnerabilities for which no patches are available. Management decides to isolate these servers on a separate, heavily restricted network segment and implement an intrusion detection system (IDS) to monitor all traffic to and from them. Which risk treatment strategy is the organization primarily employing in this scenario?Security Principles
  45. 45.A government agency is updating its data handling procedures to comply with new legislation that mandates strict controls over personally identifiable information (PII). The agency must ensure that only authorized personnel can view sensitive citizen data, and that this data is protected from unauthorized disclosure. Which security principle is the primary focus of this mandate?Security Principles
  46. 46.An organization is conducting a risk assessment for its new cloud-based email system. They identify that a successful phishing attack could lead to a data breach, resulting in regulatory fines and reputational damage. What component of risk is being described by 'regulatory fines and reputational damage'?Security Principles
  47. 47.A multinational corporation is considering processing sensitive customer data in a cloud environment. Before migrating any data, the legal department conducts a thorough review of the cloud provider's data handling practices, security controls, and contractual agreements to ensure they align with the General Data Protection Regulation (GDPR) and other applicable regional data protection laws. What key aspect of security principles is the legal department primarily focusing on?Security Principles
  48. 48.A software development team is adopting a 'privacy by design' approach for a new application that handles personal user data. This means they are embedding privacy considerations into the entire development lifecycle from the outset, rather than adding them as an afterthought. Which key concept of data protection does 'privacy by design' most directly support?Security Principles
  49. 49.A security team is evaluating potential threats to a new cloud-based customer database. They identify a scenario where a disgruntled former employee, who still retains some old system credentials, could attempt to access and delete customer records. This scenario represents a specific type of risk component. Which component is being described?Security Principles
  50. 50.A security team is deploying a new web application that will handle sensitive customer data. They need to ensure that all communication between the client's browser and the web server is encrypted and that the server's identity is verified. Which protocol combination should be implemented?Network Security