Training course
This is a free, self-paced reading course for ISC2 Certified in Cybersecurity (CC), the entry point into the profession, built for people stepping into their first security role, changing careers, or finishing a degree. CC requires no work experience, which means the course assumes none either: it starts from the vocabulary and builds the mental model a junior analyst is expected to bring on day one, rather than assuming you already administer systems. Passing CC also starts an ISC2 record that compounds as you move up through SSCP, CGRC, CCSP, and eventually CISSP.
The course is organized as one module per official exam domain, in the order ISC2 publishes them, and each module carries the domain’s published weight. Those weights are worth reading before you plan your time, because they are lopsided: Security Principles and Network Security together account for half the exam, while Business Continuity, Disaster Recovery & Incident Response Concepts is only 10%. The modules are built against the outline that took effect October 1, 2025, in which ISC2 wove foundational AI security through all five domains rather than adding a sixth, data poisoning as an integrity attack, AI-generated phishing and voice cloning as network threats, and the data-leakage risk of pasting confidential information into public chatbots.
What the course covers
Security Principles
Module 1 · 26%The heaviest domain and the conceptual foundation for everything else: the CIA triad, authentication factors and MFA, non-repudiation, privacy, the risk management process from identification through treatment (avoid, accept, mitigate, transfer) the three control categories, the ISC2 Code of Ethics canons in priority order, and the governance hierarchy of policies, standards, procedures, and guidelines. The AI thread starts here, with model poisoning framed as an integrity problem and leakage to public AI tools as a confidentiality problem.
Business Continuity, Disaster Recovery & Incident Response Concepts
Module 2 · 10%The lightest domain, but dense with the definitions the exam leans on: the purpose and components of BC, DR, and IR plans, the business impact analysis, RTO versus RPO, hot, warm, and cold recovery sites, the incident response lifecycle in order, why containment comes before eradication, and what a lessons-learned review is actually for.
Access Controls Concepts
Module 3 · 22%Physical and logical access side by side: tailgating and the vestibules that defeat it, badges, visitor accountability, and bollards on the physical end; identification, authentication, authorization, and accounting, least privilege, need to know, separation of duties, dual control, privileged account handling, and the DAC, MAC, RBAC, and rule-based model distinctions on the logical end. Provisioning and deprovisioning discipline, especially at termination, and privilege creep round out the module.
Network Security
Module 4 · 24%The most technical module and the one career-changers should budget the most time for: OSI layers and what routers and switches actually do, TCP versus UDP, well-known ports, IPv4 versus IPv6, and Wi-Fi security generations. Threats cover DoS and DDoS, on-path attacks, viruses, worms, trojans, ransomware, and AI-enhanced social engineering; defenses cover firewalls, IDS versus IPS, HIDS versus NIDS, SIEM, segmentation and VLANs, DMZs, VPNs, zero trust, cloud service and deployment models, and data-center fundamentals such as UPS-plus-generator power redundancy.
Security Operations
Module 5 · 18%The day-to-day discipline: data classification, handling, and proper media sanitization; encryption in transit and at rest, hashing for integrity, and symmetric versus asymmetric basics; logging, monitoring, and retention; configuration baselines, change management, patch management, and system hardening; and the policy suite (acceptable use, BYOD, password, data handling, and privacy) plus the awareness program that makes it stick. The 2025 outline expects the acceptable use conversation to cover generative AI tools explicitly.
How to use it
Read a module, then test that domain immediately with the CC practice exam and score each domain separately rather than looking at the total. Two patterns show up again and again in candidates who are new to the field: Network Security is where people without an IT background lose the most ground, so it usually deserves a second pass; and Business Continuity, Disaster Recovery & Incident Response Concepts is only 10% of the exam but almost pure definitions, which makes it the cheapest ten percent on the outline and a bad place to be leaking points. The course modules themselves require a free Certifym account to open.
For exam logistics, the adaptive format, the 100 to 125 items in two hours, the 700-out-of-1000 scaled cut score, the cost, and the fact that no work experience is required, see the CC certification guide.
ISC2 CC Training: Certified in Cybersecurity
Module 1: Security Principles 26% of exam
The foundation domain. Everything else in the CC exam β access control, networking, incident response, operations β sits on top of the ideas in this module. Expect the biggest slice of your exam questions to come from here, and expect them to be less about memorising acronyms than about recognising the right principle when you see it in a scenario.
- 1 What CC Is and Why It Matters 5 min Free preview
- 2 The CIA Triad: Confidentiality, Integrity, Availability 5 min π
- 3 Authentication, Authorization, and Accounting (AAA) 5 min π
- 4 Non-repudiation and Privacy 5 min π
- 5 Risk Basics: Threats, Vulnerabilities, and Impact 5 min π
- 6 Risk Management: Identify, Assess, Treat, Monitor 5 min π
- 7 Risk Treatment Options: Accept, Transfer, Mitigate, Avoid 5 min π
- 8 Security Controls: Categories and Types 5 min π
- 9 The ISC2 Code of Ethics 5 min π
- 10 Governance: Policies, Standards, Procedures, and Guidelines 5 min π
- 11 Regulatory and Legal Concepts 5 min π
- 12 Professional Ethics in Practice 4 min π
- 13 Domain 1 Wrap-Up and Study Notes 4 min π
Module 2: Business Continuity, Disaster Recovery, and Incident Response 10% of exam
The smallest of the five domains but a favourite for scenario questions. You are asked what should happen when things go wrong: how the organisation keeps operating, how it recovers, and how it handles security incidents in real time.
- 1 Business Continuity: Keeping the Lights On 5 min π
- 2 Disaster Recovery: Bringing Things Back 5 min π
- 3 Incident Response Basics 5 min π
- 4 Roles During an Incident: Who Does What 4 min π
- 5 Domain 2 Wrap-Up and Study Notes 4 min π
Module 3: Access Control Concepts 22% of exam
The second-largest domain. Access control is the day-to-day work of security teams β deciding who gets to see what, verifying that the people asking really are who they say they are, and making sure the privileges we hand out do not accumulate into a mess.
- 1 Access Control Fundamentals 5 min π
- 2 Physical Access Control 4 min π
- 3 Logical Access Control 4 min π
- 4 Identification and Authentication 5 min π
- 5 Passwords, Passphrases, and MFA 5 min π
- 6 Discretionary and Mandatory Access Control 5 min π
- 7 Role-Based Access Control (RBAC) 5 min π
- 8 Attribute-Based and Rule-Based Access Control 4 min π
- 9 Principle of Least Privilege and Segregation of Duties 5 min π
- 10 Privileged Access Management 4 min π
- 11 Domain 3 Wrap-Up and Study Notes 4 min π
Module 4: Network Security 24% of exam
Where security meets networks. This domain covers the vocabulary of networking, the common threats you meet on a network, and the controls used to defend it β firewalls, VPNs, segmentation, and the shared-responsibility model of the cloud. Almost a quarter of the exam lives here.
- 1 Networking Fundamentals for Security Pros 5 min π
- 2 The OSI Model and TCP/IP Basics 6 min π
- 3 Common Ports and Protocols 5 min π
- 4 IPv4 vs IPv6 and Network Addressing 5 min π
- 5 Common Threats and Attacks 6 min π
- 6 Wired and Wireless Networks 5 min π
- 7 Firewalls and Intrusion Detection 6 min π
- 8 Segmentation, VLANs, and DMZ 5 min π
- 9 Network Security Tools and Techniques 5 min π
- 10 Virtual Private Networks (VPNs) 4 min π
- 11 Cloud Basics and Shared Responsibility 5 min π
- 12 Domain 4 Wrap-Up and Study Notes 4 min π
Module 5: Security Operations 18% of exam
The daily work of running a security programme β handling data responsibly, using cryptography correctly, managing changes and configurations, and turning humans into partners rather than the weakest link. Almost a fifth of the exam sits here.
- 1 Data Handling and Classification 5 min π
- 2 Data Security: In Transit, At Rest, In Use 5 min π
- 3 Encryption Fundamentals 6 min π
- 4 Hashing and Digital Signatures 5 min π
- 5 Change Management Basics 5 min π
- 6 Configuration and Asset Management 4 min π
- 7 Security Awareness Training 4 min π
- 8 Common Security Policies 5 min π
- 9 Domain 5 Wrap-Up and Study Notes 4 min π
Frequently asked questions about the CC training course
Is the CC training course free?
Yes. The course costs nothing to read and opens once you are signed in to a free Certifym account, no payment and no card.
How is the course structured?
One module per official CC domain, in ISC2’s published order, with each module weighted to the domain’s published percentage. The weighting is deliberately uneven because the exam is: Security Principles at 26% and Network Security at 24% carry half the outline between them, and module 2 is short because its domain is worth 10%.
Does this replace ISC2’s official training?
No. ISC2 publishes the authoritative exam outline and runs its own official CC training. This course is an independent study companion written to be read in order alongside practice questions, not a substitute for the official outline, which you should download from isc2.org and check your preparation against.
Do I need any background before starting?
No. CC requires no work experience and neither does this course. It is written for people entering their first security role, changing careers, or finishing a degree. If you have no IT background at all, expect module 4 on Network Security to take the longest, since it assumes the least familiar material.
What should I do after finishing the course?
Move to the CC practice exam and work until each domain individually clears 70%. After the exam, the natural next rung is the SSCP once you are working in a hands-on security role.
Is the course current with the latest CC outline?
The modules are built against the outline that took effect October 1, 2025, whose defining change was weaving foundational AI security through all five domains. Note that ISC2 has announced a refreshed outline effective September 1, 2026, if your test date falls on or after that, download the updated outline from isc2.org and check it against this course before you finalize your study plan.
Trademark notice & independence. Certifym.net is operated by Certifym Exam Services, LLC and is not affiliated with, endorsed by, or sponsored by ISC2, Inc. CC®, CISSP®, SSCP®, CCSP®, CGRC®, and ISC2® are registered trademarks of ISC2, Inc. Certification names and marks are used solely to identify the certification for which these study materials are intended. The CC exam outline and its domain structure are the property of ISC2, Inc.; candidates should download the official, current exam outline directly from isc2.org.
All course content, questions, answers, and explanations on Certifym are original content created for study purposes. They are not actual ISC2 training materials or examination questions and are not represented as such. Studying with these materials does not guarantee a passing result on any live certification exam. Exam requirements, format, domain weights, pricing, and maintenance policies are set by ISC2 and may change; always verify current details on isc2.org before scheduling your exam.
