Step2Study
IT & Technology100% Free

ISC2 Certified in Cybersecurity (CC)

Practice bank
214 Qs
Real exam
100 Qs
Time limit
120 min
Passing
700 out of 1000 points

Exam blueprint

Security Principles
24%
Business Continuity (BC), Disaster Recovery (DR) & Incident Response (IR) Concepts
16%
Access Controls Concepts
18%
Network Security
18%
Security Operations
24%

Practice

Untimed · instant feedback · 4 practice tests of 90 questions

Questions per test

Custom practice

Flashcard on every question Mental map when you miss

Exam simulation

4 timed tests · 100 questions each · 120 min · pass 70% · 214 questions in the bank

+50 XP per test · +100 XP for a pass

Random simulation (weighted by domain)

Everything is open to everyone. Create a free account to save scores, XP, badges and get progress emails.

Study with friends

Challenge a friend to beat your score.

ISC2 Certified in Cybersecurity (CC) practice test questions

Sample questions from the 214-question bank, with answers and explanations.

All questions
  1. 1. A company is implementing a new cloud-based application. The security team needs to ensure that data transmitted between the company's on-premises network and the cloud provider's infrastructure is encrypted and authenticated. Which protocol suite is specifically designed to provide secure communication over an IP network, commonly used in this scenario for site-to-site connections?

    Network Security

    • A. FTP (File Transfer Protocol)
    • B. SNMP (Simple Network Management Protocol)
    • C. SMTP (Simple Mail Transfer Protocol)
    • D. IPsec (Internet Protocol Security)
    Show answer

    D. IPsec (Internet Protocol Security)

    IPsec is a suite of protocols that provides cryptographic security services, including authentication and encryption, for IP communications. It's commonly used for securing VPNs, especially site-to-site connections.

  2. 2. A company requires all employees to use their corporate laptops for work, even when traveling. The security policy states that these laptops must always be connected to the corporate network securely, regardless of their physical location or the underlying internet connection. Which technology ensures continuous, secure communication back to the corporate network without requiring manual user initiation for every session?

    Network Security

    • A. Always-On VPN
    • B. Split Tunnel VPN
    • C. Clientless VPN
    • D. Site-to-Site VPN
    Show answer

    A. Always-On VPN

    An Always-On VPN automatically establishes and maintains a secure VPN connection whenever the device has internet access, ensuring continuous secure communication without user intervention.

  3. 3. A security auditor is reviewing a company's remote access solution. They note that employees connect to the internal network using a client application that encrypts all traffic and creates a secure tunnel over the public internet. What type of remote access technology is most likely being utilized?

    Network Security

    • A. File Transfer Protocol (FTP)
    • B. Remote Desktop Protocol (RDP)
    • C. Virtual Private Network (VPN)
    • D. Secure Shell (SSH)
    Show answer

    C. Virtual Private Network (VPN)

    VPNs are designed to create secure, encrypted tunnels over public networks like the internet, allowing remote users to access internal resources as if they were on the local network.

  4. 4. A cybersecurity incident response team is investigating a sophisticated attack where an attacker bypassed traditional perimeter defenses. They suspect that malicious code was executed directly on an endpoint, which then communicated with a command-and-control (C2) server. To detect such advanced threats and provide detailed visibility into endpoint activities, which security solution would be most effective?

    Network Security

    • A. Traditional Antivirus (AV)
    • B. Network Intrusion Detection System (NIDS)
    • C. Endpoint Detection and Response (EDR)
    • D. Security Information and Event Management (SIEM)
    Show answer

    C. Endpoint Detection and Response (EDR)

    EDR solutions continuously monitor endpoint activity for advanced threats, provide detailed visibility, and enable rapid response capabilities, which traditional AV and NIDS often lack for sophisticated, endpoint-centric attacks.

  5. 5. A company is experiencing slow network performance and occasional data packet loss. An administrator suspects network congestion or faulty equipment. Which core network protocol is primarily responsible for ensuring reliable, ordered, and error-checked delivery of data streams between applications?

    Network Security

    • A. ARP
    • B. TCP
    • C. ICMP
    • D. UDP
    Show answer

    B. TCP

    TCP (Transmission Control Protocol) is a connection-oriented protocol that provides reliable, ordered, and error-checked delivery of a stream of bytes between applications. It includes mechanisms for retransmission of lost packets and flow control, which directly relates to diagnosing issues like packet loss and congestion.

  6. 6. A large organization with multiple branch offices needs a solution to monitor network traffic for suspicious activity and automatically block known attack patterns in real-time. Which network security device is best suited for both detecting and preventing such malicious activities?

    Network Security

    • A. Content Filter
    • B. Intrusion Prevention System (IPS)
    • C. Network Access Control (NAC)
    • D. Intrusion Detection System (IDS)
    Show answer

    B. Intrusion Prevention System (IPS)

    An IPS actively monitors network traffic for malicious activity and can take automated actions, such as blocking traffic, to prevent attacks in real-time.

  7. 7. A global company uses a distributed network architecture with data centers and branch offices across different continents. They need a solution that can identify and block known malicious traffic patterns and signatures at the network perimeter before they reach internal systems, acting proactively. Which network security device is best suited for this proactive threat prevention?

    Network Security

    • A. Switch
    • B. Router
    • C. Intrusion Prevention System (IPS)
    • D. Load Balancer
    Show answer

    C. Intrusion Prevention System (IPS)

    An Intrusion Prevention System (IPS) actively monitors network traffic for malicious activity or policy violations and can automatically take action to block or prevent detected threats in real-time, making it ideal for proactive threat prevention at the network perimeter.

  8. 8. A company is implementing a new policy for managing mobile devices used by employees. The policy requires enforcing screen lock passcodes, remotely wiping lost devices, and ensuring specific applications are installed or restricted. Which security solution is specifically designed to centrally manage and secure mobile devices?

    Network Security

    • A. Security Information and Event Management (SIEM)
    • B. Mobile Device Management (MDM)
    • C. Data Loss Prevention (DLP)
    • D. Network Access Control (NAC)
    Show answer

    B. Mobile Device Management (MDM)

    MDM solutions provide centralized management capabilities for mobile devices, allowing organizations to enforce security policies, manage applications, and perform remote actions like wiping data.

  9. 9. A security analyst is investigating a potential data breach where sensitive employee records were exfiltrated from an internal server. The investigation reveals that the attacker gained access through a web application vulnerability and then used this access to move laterally within the network. Which security measure, if properly implemented, would have been most effective in preventing the lateral movement of the attacker to the sensitive data server?

    Network Security

    • A. Implementing a robust antivirus solution on all workstations.
    • B. Network segmentation between the web application server and the sensitive data server.
    • C. Regular security awareness training for employees.
    • D. Stronger password policies for user accounts.
    Show answer

    B. Network segmentation between the web application server and the sensitive data server.

    Network segmentation would isolate the web application server from the sensitive data server, making lateral movement significantly harder even after an initial compromise, thereby limiting the blast radius.

  10. 10. A security team is implementing a new policy for mobile device security. Employees frequently use personal smartphones and tablets for work-related tasks, including accessing corporate email and cloud applications. The policy aims to enforce security configurations, manage applications, and remotely wipe data if a device is lost or stolen, without necessarily owning the devices. Which solution is most appropriate for achieving these goals?

    Network Security

    • A. Mobile Device Management (MDM)
    • B. Virtual Private Network (VPN)
    • C. Basic Antivirus Software
    • D. Firewall on each device
    Show answer

    A. Mobile Device Management (MDM)

    Mobile Device Management (MDM) solutions allow organizations to enforce security policies, manage applications, configure settings, and remotely control (e.g., wipe) mobile devices, even if they are personally owned (BYOD), making it ideal for the described scenario.

  11. 11. A healthcare organization is designing its network infrastructure and must ensure that patient records (PHI) are strictly isolated from the general administrative network and guest Wi-Fi. Access to PHI must be restricted to authorized medical personnel only. Which network design principle is most critical for achieving this separation and access control?

    Network Security

    • A. Load Balancing
    • B. Redundant Network Links
    • C. Flat Network Topology
    • D. Network Segmentation
    Show answer

    D. Network Segmentation

    Network segmentation involves dividing a network into smaller, isolated sub-networks. This is crucial for isolating sensitive data like PHI, restricting access, and containing potential breaches, directly addressing the stated requirements.

  12. 12. A security analyst is investigating a suspected intrusion on the corporate network. They observe unusual outbound traffic patterns and multiple failed login attempts on a critical server. To gain real-time visibility into these activities and correlate events from various network devices and applications, which security solution should the analyst primarily rely on?

    Network Security

    • A. Firewall
    • B. Intrusion Detection System (IDS)
    • C. Antivirus Software
    • D. Security Information and Event Management (SIEM)
    Show answer

    D. Security Information and Event Management (SIEM)

    A SIEM system collects, aggregates, and correlates log data and security events from various sources across the network, providing a centralized platform for real-time monitoring, incident detection, and analysis of security incidents.

  13. 13. A system administrator is tasked with securing all endpoints within the organization, including laptops, desktops, and servers. The goal is to detect and respond to advanced threats, such as fileless malware and sophisticated ransomware, beyond what traditional antivirus can handle. Which security solution specifically focuses on comprehensive endpoint protection and response capabilities?

    Network Security

    • A. Data Loss Prevention (DLP)
    • B. Endpoint Detection and Response (EDR)
    • C. Network Access Control (NAC)
    • D. Unified Threat Management (UTM)
    Show answer

    B. Endpoint Detection and Response (EDR)

    Endpoint Detection and Response (EDR) solutions go beyond traditional antivirus by continuously monitoring endpoint activity, collecting data, and using advanced analytics to detect and respond to sophisticated threats like fileless malware and ransomware, providing comprehensive endpoint protection.

  14. 14. A company policy mandates that all data exchanged between its internal network and its cloud-hosted applications must be encrypted in transit and authenticated. The company uses Amazon Web Services (AWS) for its cloud infrastructure. Which security measure is most appropriate for securing this communication?

    Network Security

    • A. Virtual Private Cloud (VPC)
    • B. Security Groups
    • C. TLS/SSL Encryption
    • D. Direct Connect
    Show answer

    C. TLS/SSL Encryption

    TLS/SSL encryption is the primary protocol used to secure data in transit over networks, including between on-premises and cloud environments. It provides both encryption and authentication, fulfilling the policy requirement for securing data exchange.

  15. 15. A system administrator is configuring a new web server that will host a public-facing e-commerce application. To ensure that only legitimate web traffic (HTTP/HTTPS) can reach the server and to prevent other types of network attacks, which network protocol ports should be explicitly opened on the firewall for this server?

    Network Security

    • A. Port 25 (SMTP) and Port 110 (POP3)
    • B. Port 21 (FTP) and Port 23 (Telnet)
    • C. Port 22 (SSH) and Port 3389 (RDP)
    • D. Port 80 (HTTP) and Port 443 (HTTPS)
    Show answer

    D. Port 80 (HTTP) and Port 443 (HTTPS)

    HTTP (Port 80) and HTTPS (Port 443) are the standard ports for web traffic, which is essential for a public-facing e-commerce application.

  16. 16. A security team is designing a network architecture for a new data center. They want to implement a highly available and secure perimeter that allows public access to web servers while strictly protecting internal databases. The design includes redundant firewalls and routers, placing the web servers in a neutral zone, and isolating internal resources. What specific network topology concept are they primarily applying?

    Network Security

    • A. Bus topology
    • B. Demilitarized Zone (DMZ)
    • C. Ring topology
    • D. Star topology
    Show answer

    B. Demilitarized Zone (DMZ)

    A DMZ is a neutral zone, typically between two firewalls, used to host public-facing services like web servers, protecting the internal network from direct access.

  17. 17. A company is upgrading its network infrastructure and is considering using a protocol that ensures reliable, ordered, and error-checked delivery of data streams. Which of the following core network protocols best fits this description?

    Network Security

    • A. TCP (Transmission Control Protocol)
    • B. ICMP (Internet Control Message Protocol)
    • C. UDP (User Datagram Protocol)
    • D. ARP (Address Resolution Protocol)
    Show answer

    A. TCP (Transmission Control Protocol)

    TCP is a connection-oriented protocol that provides reliable, ordered, and error-checked delivery of data, making it suitable for applications requiring high data integrity.

  18. 18. A small office is setting up its first network and wants to ensure that all internal devices can communicate with each other and with the internet securely. They are on a limited budget and need a device that can manage network traffic, assign IP addresses, and provide basic firewall capabilities. Which network device would best meet these requirements?

    Network Security

    • A. Wireless Router
    • B. Hub
    • C. Repeater
    • D. Modem
    Show answer

    A. Wireless Router

    A wireless router combines the functions of a router (traffic management, IP assignment via DHCP), a switch (connecting multiple devices), and often a basic firewall, making it ideal for a small office with internet connectivity needs.

  19. 19. A network administrator is configuring a new Wi-Fi network for a school and needs to select the strongest encryption protocol available to protect sensitive student data. The network will support modern devices. Which Wi-Fi security standard should be prioritized?

    Network Security

    • A. WPA
    • B. WPA2
    • C. WEP
    • D. WPA3
    Show answer

    D. WPA3

    WPA3 is the latest and most secure Wi-Fi security standard, offering enhanced encryption, protection against brute-force attacks, and improved privacy compared to its predecessors.

  20. 20. A company is implementing a new security policy that requires all remote employees to securely access the corporate network as if they were physically present in the office. They need a solution that encrypts all traffic and provides a secure tunnel over the public internet. Which technology should they choose?

    Network Security

    • A. SMTP
    • B. HTTP/S
    • C. VPN
    • D. DNS
    Show answer

    C. VPN

    A Virtual Private Network (VPN) creates a secure, encrypted tunnel over a public network (like the internet), allowing remote users to access internal resources as if they were directly connected to the corporate network.

  21. 21. A network administrator is troubleshooting connectivity issues in a corporate office. They observe that devices on different floors cannot communicate with each other, even though they are all connected to the same physical network infrastructure. What network topology characteristic might be causing this issue if logical separation is intended?

    Network Security

    • A. Star topology
    • B. Bus topology
    • C. VLANs
    • D. Mesh topology
    Show answer

    C. VLANs

    VLANs (Virtual Local Area Networks) are used to logically segment a network, meaning devices on different VLANs cannot communicate without a Layer 3 device (router), even if on the same physical switch.

  22. 22. A small business wants to protect its internal network from unauthorized access while allowing employees to browse the internet. Which network device is primarily responsible for filtering incoming and outgoing network traffic based on a defined set of security rules?

    Network Security

    • A. Switch
    • B. Router
    • C. Access Point
    • D. Firewall
    Show answer

    D. Firewall

    A firewall is specifically designed to enforce security policies by controlling network traffic, making it the primary device for this protection.

  23. 23. A manufacturing company operates several industrial control systems (ICS) that are critical for production and cannot tolerate downtime. To protect these systems from external threats while allowing limited, controlled access for remote monitoring and maintenance, which network security architecture should be implemented to create a demilitarized zone (DMZ) for the ICS?

    Network Security

    • A. Screened Subnet (Triple-Homed) DMZ
    • B. Single Firewall DMZ
    • C. No DMZ, direct internet access
    • D. Dual-Homed Host DMZ
    Show answer

    A. Screened Subnet (Triple-Homed) DMZ

    A Screened Subnet (Triple-Homed) DMZ, also known as a three-legged DMZ, uses two firewalls: one between the internet and the DMZ, and another between the DMZ and the internal network. This provides the highest level of security for critical systems like ICS by creating two layers of defense and strict control over traffic flow, ideal for sensitive environments.

  24. 24. A security auditor is reviewing the configuration of a corporate firewall. The auditor notices a rule that permits 'any' source IP address to connect to an internal web server (port 80/TCP) but restricts access to only 'trusted' destination IP addresses. This rule is directly followed by a rule that implicitly denies all other traffic. What is the most significant security concern with this specific firewall rule related to the internal web server?

    Network Security

    • A. It exposes the web server to potential attacks from any external source.
    • B. It allows any internal user to access the web server.
    • C. It only allows access to port 80, not 443.
    • D. It prevents the web server from initiating outbound connections.
    Show answer

    A. It exposes the web server to potential attacks from any external source.

    The rule permits 'any' source IP address to connect to the internal web server on port 80 (HTTP). This means the web server is publicly accessible via HTTP, making it vulnerable to various attacks from the entire internet, regardless of the 'trusted' destination restriction which is misapplied (destination refers to the target of the connection, not the source).

  25. 25. A security team is deploying a new web application that will handle sensitive customer data. They need to ensure that all communication between the client's browser and the web server is encrypted and that the server's identity is verified. Which protocol combination should be implemented?

    Network Security

    • A. HTTPS with TLS
    • B. Telnet with SSH
    • C. HTTP with FTP
    • D. SMTP with POP3
    Show answer

    A. HTTPS with TLS

    HTTPS (Hypertext Transfer Protocol Secure) combines HTTP with TLS (Transport Layer Security) to provide encrypted communication and server identity verification for web traffic. This ensures data confidentiality and integrity, and authenticates the server to the client.

ISC2 Certified in Cybersecurity (CC) flashcards

Tap a card to flip it. 133 flashcards in the full deck.

  • IPsec (Internet Protocol Security)

    Flip card

    A suite of protocols for securing Internet Protocol (IP) communications by authenticating and encrypting each IP packet in a data stream.

    • Operates at the network layer (Layer 3) of the OSI model.
    • Provides confidentiality, integrity, and authenticity.
    • Commonly used to implement VPNs (Virtual Private Networks).
    Study this card →
  • Always-On VPN

    Flip card

    A type of Virtual Private Network that automatically establishes and maintains a secure connection to a corporate network whenever the device has internet connectivity, without requiring manual user initiation.

    • Ensures continuous security and policy enforcement for remote devices.
    • Enhances compliance and reduces security risks for mobile users.
    • Can be configured to enforce full tunnel or split tunnel depending on policy.
    Study this card →
  • Virtual Private Network (VPN)

    Flip card

    A technology that creates a secure, encrypted connection over a less secure network, such as the internet, allowing remote users to access private network resources.

    • Encrypts data between the client and the VPN server.
    • Creates a 'tunnel' for secure communication.
    • Allows remote users to appear as if they are physically on the corporate network.
    Study this card →
  • Endpoint Detection and Response (EDR)

    Flip card

    A cybersecurity solution that continuously monitors and collects data from endpoint devices, enabling the detection, investigation, and response to advanced threats.

    • Provides deep visibility into endpoint activities (processes, file changes, network connections).
    • Uses behavioral analytics and machine learning to detect anomalies.
    • Facilitates rapid incident response and threat hunting.
    Study this card →
  • TCP (Transmission Control Protocol)

    Flip card

    A core protocol of the Internet protocol suite that provides reliable, ordered, and error-checked delivery of a stream of bytes between applications running on hosts communicating over an IP network.

    • Connection-oriented (three-way handshake).
    • Guarantees delivery and order of packets.
    • Performs error checking and retransmission.
    Study this card →
  • Intrusion Prevention System (IPS)

    Flip card

    A network security device that monitors network traffic for malicious activity and automatically takes actions to prevent detected threats in real-time.

    • Actively blocks or drops malicious traffic.
    • Operates inline with network traffic.
    • Can use signature-based, anomaly-based, or policy-based detection.
    Study this card →
  • Mobile Device Management (MDM)

    Flip card

    Software that allows organizations to securely manage, monitor, and configure mobile devices, such as smartphones and tablets, used by employees.

    • Enforces security policies (e.g., passcodes, encryption).
    • Manages applications (installation, removal, updates).
    • Enables remote actions (e.g., locate, lock, wipe).
    Study this card →
  • Network Segmentation

    Flip card

    The practice of dividing a computer network into multiple smaller network segments, each acting as its own small network.

    • Reduces the attack surface by isolating critical assets.
    • Limits lateral movement of attackers within the network.
    • Improves network performance and security posture.
    Study this card →
  • Security Information and Event Management (SIEM)

    Flip card

    A security solution that centralizes the collection, storage, and analysis of security logs and events from across an organization's IT infrastructure to provide real-time threat detection and compliance reporting.

    • Aggregates logs from various sources (servers, firewalls, applications).
    • Correlates security events to identify patterns and potential incidents.
    • Provides real-time monitoring and alerting.
    Study this card →
  • TLS/SSL (Transport Layer Security/Secure Sockets Layer)

    Flip card

    Cryptographic protocols that provide secure communication over a computer network, primarily used for encrypting and authenticating data in transit between a client and a server.

    • Encrypts data to ensure confidentiality.
    • Provides authentication to verify identities.
    • Protects data integrity during transmission.
    Study this card →
  • Common Network Ports

    Flip card

    Standardized port numbers used by various network protocols to identify specific services running on a server.

    • Port 80: HTTP (Hypertext Transfer Protocol) for unencrypted web traffic.
    • Port 443: HTTPS (Hypertext Transfer Protocol Secure) for encrypted web traffic.
    • Firewalls use port numbers to filter traffic and enhance security.
    Study this card →
  • Demilitarized Zone (DMZ)

    Flip card

    A physical or logical subnetwork that separates an organization's local area network (LAN) from an untrusted network, usually the internet.

    • Provides an additional layer of security for the internal network.
    • Hosts public-facing servers (e.g., web, email, DNS).
    • Typically located between two firewalls (a screened subnet DMZ).
    Study this card →
  • Wireless Router

    Flip card

    A network device that combines the functions of a router, a switch, a wireless access point, and often a basic firewall to connect multiple devices to a local network and the internet.

    • Connects local devices to the internet.
    • Assigns IP addresses using DHCP.
    • Provides Wi-Fi connectivity.
    Study this card →
  • WPA3 (Wi-Fi Protected Access 3)

    Flip card

    The latest security protocol for Wi-Fi networks, offering robust encryption and improved protection against common attacks compared to older standards.

    • Uses 192-bit cryptographic strength in Enterprise mode.
    • Provides 'Simultaneous Authentication of Equals' (SAE) for stronger password-based authentication.
    • Offers enhanced privacy in open networks with 'Opportunistic Wireless Encryption' (OWE).
    Study this card →
  • VLAN (Virtual Local Area Network)

    Flip card

    A logical grouping of network devices that allows them to communicate as if they were on the same physical LAN, regardless of their physical location.

    • Segments a single physical switch into multiple virtual switches.
    • Improves security by isolating traffic.
    • Enhances network performance by reducing broadcast domains.
    Study this card →
  • Firewall

    Flip card

    A network security system that monitors and controls incoming and outgoing network traffic based on predetermined security rules.

    • Acts as a barrier between a trusted internal network and untrusted external networks.
    • Filters traffic based on IP addresses, port numbers, and protocols.
    • Can be hardware, software, or cloud-based.
    Study this card →
  • Screened Subnet DMZ (Triple-Homed)

    Flip card

    A network architecture that uses two firewalls to create a highly secure demilitarized zone (DMZ), completely isolating it from both the external network (internet) and the internal private network.

    • Employs two firewalls for enhanced security.
    • One firewall faces the internet, the other faces the internal network.
    • DMZ hosts are placed between these two firewalls.
    Study this card →
  • Firewall Rule Analysis

    Flip card

    The process of examining firewall rulesets to identify potential vulnerabilities, misconfigurations, or unintended access permissions that could compromise network security.

    • Rules are processed in order.
    • The first matching rule is applied.
    • Implicit 'deny all' is a common last rule.
    Study this card →
  • HTTPS and TLS

    Flip card

    HTTPS is the secure version of HTTP, using TLS (Transport Layer Security) to encrypt communication and verify the identity of the web server.

    • HTTPS ensures confidentiality and integrity of web data.
    • TLS provides encryption and authentication.
    • Essential for protecting sensitive data exchanged over the web.
    Study this card →
  • Intrusion Detection System (IDS)

    Flip card

    A security system that monitors network or system activities for malicious activity or policy violations and produces reports to a management station.

    • Passively monitors traffic, does not block it.
    • Detects anomalies, known attack signatures, or policy violations.
    • Can be network-based (NIDS) or host-based (HIDS).
    Study this card →
  • Technical Control

    Flip card

    Security safeguards implemented through hardware, software, or firmware that enforce security policies.

    • Automated and often invisible to the end-user.
    • Examples include firewalls, intrusion detection systems, encryption, and access control lists.
    • Works in conjunction with administrative and physical controls.
    Study this card →
  • Unique User Identification

    Flip card

    The practice of assigning a distinct and non-reusable identifier to each individual user accessing a system or network resource.

    • Essential for accountability and non-repudiation.
    • Facilitates auditing and incident response.
    • Prevents shared accounts that obscure individual actions.
    Study this card →
  • Risk Appetite

    Flip card

    The amount and type of risk that an organization is willing to pursue or retain in order to achieve its objectives. It's a high-level statement set by senior management and influences strategic decisions.

    • Set by senior management/board
    • Strategic, high-level decision
    • Guides risk management activities
    Study this card →
  • Privacy by Design (PbD)

    Flip card

    An approach to systems engineering that incorporates privacy and data protection into the entire lifecycle of technology, from the initial design phase to deployment and beyond. It emphasizes proactive rather than reactive measures.

    • Seven foundational principles
    • Proactive, not reactive
    • Privacy as the default setting
    Study this card →

Questions are original practice items written to match the published exam objectives. Step2Study is not affiliated with or endorsed by any certification body.