CC Training Course

Training course

This is a free, self-paced reading course for ISC2 Certified in Cybersecurity (CC), the entry point into the profession, built for people stepping into their first security role, changing careers, or finishing a degree. CC requires no work experience, which means the course assumes none either: it starts from the vocabulary and builds the mental model a junior analyst is expected to bring on day one, rather than assuming you already administer systems. Passing CC also starts an ISC2 record that compounds as you move up through SSCP, CGRC, CCSP, and eventually CISSP.

The course is organized as one module per official exam domain, in the order ISC2 publishes them, and each module carries the domain’s published weight. Those weights are worth reading before you plan your time, because they are lopsided: Security Principles and Network Security together account for half the exam, while Business Continuity, Disaster Recovery & Incident Response Concepts is only 10%. The modules are built against the outline that took effect October 1, 2025, in which ISC2 wove foundational AI security through all five domains rather than adding a sixth, data poisoning as an integrity attack, AI-generated phishing and voice cloning as network threats, and the data-leakage risk of pasting confidential information into public chatbots.

CC Foundational level 5 modules Domain-weighted Self-paced Free account

What the course covers

Security Principles

Module 1 · 26%

The heaviest domain and the conceptual foundation for everything else: the CIA triad, authentication factors and MFA, non-repudiation, privacy, the risk management process from identification through treatment (avoid, accept, mitigate, transfer) the three control categories, the ISC2 Code of Ethics canons in priority order, and the governance hierarchy of policies, standards, procedures, and guidelines. The AI thread starts here, with model poisoning framed as an integrity problem and leakage to public AI tools as a confidentiality problem.

Business Continuity, Disaster Recovery & Incident Response Concepts

Module 2 · 10%

The lightest domain, but dense with the definitions the exam leans on: the purpose and components of BC, DR, and IR plans, the business impact analysis, RTO versus RPO, hot, warm, and cold recovery sites, the incident response lifecycle in order, why containment comes before eradication, and what a lessons-learned review is actually for.

Access Controls Concepts

Module 3 · 22%

Physical and logical access side by side: tailgating and the vestibules that defeat it, badges, visitor accountability, and bollards on the physical end; identification, authentication, authorization, and accounting, least privilege, need to know, separation of duties, dual control, privileged account handling, and the DAC, MAC, RBAC, and rule-based model distinctions on the logical end. Provisioning and deprovisioning discipline, especially at termination, and privilege creep round out the module.

Network Security

Module 4 · 24%

The most technical module and the one career-changers should budget the most time for: OSI layers and what routers and switches actually do, TCP versus UDP, well-known ports, IPv4 versus IPv6, and Wi-Fi security generations. Threats cover DoS and DDoS, on-path attacks, viruses, worms, trojans, ransomware, and AI-enhanced social engineering; defenses cover firewalls, IDS versus IPS, HIDS versus NIDS, SIEM, segmentation and VLANs, DMZs, VPNs, zero trust, cloud service and deployment models, and data-center fundamentals such as UPS-plus-generator power redundancy.

Security Operations

Module 5 · 18%

The day-to-day discipline: data classification, handling, and proper media sanitization; encryption in transit and at rest, hashing for integrity, and symmetric versus asymmetric basics; logging, monitoring, and retention; configuration baselines, change management, patch management, and system hardening; and the policy suite (acceptable use, BYOD, password, data handling, and privacy) plus the awareness program that makes it stick. The 2025 outline expects the acceptable use conversation to cover generative AI tools explicitly.

How to use it

Read a module, then test that domain immediately with the CC practice exam and score each domain separately rather than looking at the total. Two patterns show up again and again in candidates who are new to the field: Network Security is where people without an IT background lose the most ground, so it usually deserves a second pass; and Business Continuity, Disaster Recovery & Incident Response Concepts is only 10% of the exam but almost pure definitions, which makes it the cheapest ten percent on the outline and a bad place to be leaking points. The course modules themselves require a free Certifym account to open.

For exam logistics, the adaptive format, the 100 to 125 items in two hours, the 700-out-of-1000 scaled cut score, the cost, and the fact that no work experience is required, see the CC certification guide.

← Back

What CC Is and Why It Matters

5 min read · Free preview

The ISC2 Certified in Cybersecurity (CC) is an entry-level certification for people who want a foot in the door of the security industry without needing years of experience first. It replaced and simplified what used to be a much steeper on-ramp. If you have never held a security job before, this is the credential ISC2 built for you.

The exam covers five domains: Security Principles, Business Continuity and Incident Response, Access Control, Network Security, and Security Operations. There are one hundred multiple-choice questions and you have two hours to answer them. The passing mark is seven hundred out of a possible one thousand — but that is a scaled score, not a raw percentage, so getting exactly seventy questions right is not the same as passing. Some questions weight more than others.

What CC proves is that you understand the vocabulary and the reasoning of the field. You know what a firewall is for, why we hash passwords instead of storing them in plaintext, and what a business impact analysis does. You do not need to be able to configure a Cisco ASA from the command line. That comes later, in roles or in more advanced certs.

Because this is your first cert, do not read like you are cramming for a graduate exam. Read to understand. If a lesson mentions the CIA triad and you do not immediately know what the letters stand for, stop and look them up. Concepts that feel fuzzy on the first pass will feel obvious on the third. The questions on the real exam reward recognition, not recall.

One more thing worth saying up front: CC is renewable. Once you pass, you will owe ISC2 a small annual maintenance fee and a modest number of continuing professional education credits each year. That is normal for professional certifications and is how the credential stays meaningful over time.

Frequently asked questions about the CC training course

Is the CC training course free?

Yes. The course costs nothing to read and opens once you are signed in to a free Certifym account, no payment and no card.

How is the course structured?

One module per official CC domain, in ISC2’s published order, with each module weighted to the domain’s published percentage. The weighting is deliberately uneven because the exam is: Security Principles at 26% and Network Security at 24% carry half the outline between them, and module 2 is short because its domain is worth 10%.

Does this replace ISC2’s official training?

No. ISC2 publishes the authoritative exam outline and runs its own official CC training. This course is an independent study companion written to be read in order alongside practice questions, not a substitute for the official outline, which you should download from isc2.org and check your preparation against.

Do I need any background before starting?

No. CC requires no work experience and neither does this course. It is written for people entering their first security role, changing careers, or finishing a degree. If you have no IT background at all, expect module 4 on Network Security to take the longest, since it assumes the least familiar material.

What should I do after finishing the course?

Move to the CC practice exam and work until each domain individually clears 70%. After the exam, the natural next rung is the SSCP once you are working in a hands-on security role.

Is the course current with the latest CC outline?

The modules are built against the outline that took effect October 1, 2025, whose defining change was weaving foundational AI security through all five domains. Note that ISC2 has announced a refreshed outline effective September 1, 2026, if your test date falls on or after that, download the updated outline from isc2.org and check it against this course before you finalize your study plan.

Trademark notice & independence. Certifym.net is operated by Certifym Exam Services, LLC and is not affiliated with, endorsed by, or sponsored by ISC2, Inc. CC®, CISSP®, SSCP®, CCSP®, CGRC®, and ISC2® are registered trademarks of ISC2, Inc. Certification names and marks are used solely to identify the certification for which these study materials are intended. The CC exam outline and its domain structure are the property of ISC2, Inc.; candidates should download the official, current exam outline directly from isc2.org.

All course content, questions, answers, and explanations on Certifym are original content created for study purposes. They are not actual ISC2 training materials or examination questions and are not represented as such. Studying with these materials does not guarantee a passing result on any live certification exam. Exam requirements, format, domain weights, pricing, and maintenance policies are set by ISC2 and may change; always verify current details on isc2.org before scheduling your exam.