ISC2 CC Certification

Certification guide

Certified in Cybersecurity (CC) is ISC2’s entry point into the profession, the credential built for people stepping into their first security role, changing careers, or finishing a degree, with no work experience required. It comes from the same certifying body behind the CISSP, which is exactly the point: passing the CC starts an ISC2 record that compounds as you move up through SSCP, CGRC, CCSP, and eventually CISSP. It proves to a hiring manager that you have a working command of security principles, access control, networking, operations, and incident response basics, the vocabulary and judgment a junior analyst is expected to bring on day one.

The exam outline in force today took effect October 1, 2025, and its defining change is AI. ISC2 wove foundational AI security through all five domains: data poisoning as an integrity attack on machine-learning models, AI-generated phishing and voice cloning as network threats, the “security of the AI workspace”, meaning the data-leakage risk when employees paste confidential information into public chatbots, and the governance expectation that acceptable use policies now cover generative AI tools. ISC2 has also announced a refreshed outline effective September 1, 2026, so if your test date falls after that, pull the updated outline before finalizing your plan. The exam itself is delivered as a computerized adaptive test at Pearson VUE: 100-125 items in two hours, scored against a 700-out-of-1000 scaled bar.

Exam: CC Format: CAT, 100-125 items Time: 2 hours Pass: 700 / 1000 scaled Domains: 5 Experience: none required Cost: $199 USD + $50 AMF

The five domains

Security Principles

Domain 1 · 26%

The heaviest domain and the conceptual foundation for everything else: the CIA triad, authentication factors and MFA, non-repudiation, privacy, the risk management process (identify, assess, treat, avoid, accept, mitigate, transfer), the three control categories (technical, administrative, physical), the ISC2 Code of Ethics canons in priority order, and the governance hierarchy of policies, standards, procedures, and guidelines. The AI thread starts here too, expect model poisoning framed as an integrity problem and data leakage to public AI tools framed as a confidentiality problem.

Business Continuity, Disaster Recovery & Incident Response Concepts

Domain 2 · 10%

The lightest domain, but dense with definitions the exam loves: the purpose and components of BC, DR, and IR plans, the business impact analysis, RTO versus RPO, hot/warm/cold recovery sites, the incident response lifecycle in order, why containment comes before eradication, and what a lessons-learned review is actually for. Ten questions’ worth of material you can lock down in an afternoon, do not leave these on the table.

Access Controls Concepts

Domain 3 · 22%

Physical and logical access side by side: tailgating and the vestibules that defeat it, badges, visitor accountability, and bollards on the physical end; identification-authentication-authorization-accounting, least privilege, need to know, separation of duties, dual control, privileged account handling, and the DAC/MAC/RBAC/rule-based model distinctions on the logical end. Provisioning and deprovisioning discipline, especially what happens the moment an employee is terminated, and privilege creep round out the domain.

Network Security

Domain 4 · 24%

The most technical domain and the one career-changers should budget the most time for: OSI layers and what routers and switches actually do, TCP versus UDP, well-known ports, IPv4 versus IPv6, and Wi-Fi security generations. Threats cover DoS/DDoS, on-path attacks, viruses, worms, trojans, ransomware, and AI-enhanced social engineering; defenses cover firewalls, IDS versus IPS, HIDS versus NIDS, SIEM, segmentation and VLANs, DMZs, VPNs, zero trust, cloud service and deployment models, and data-center fundamentals like UPS-plus-generator power redundancy.

Security Operations

Domain 5 · 18%

The day-to-day discipline: data classification, handling, and proper media sanitization; encryption in transit and at rest, hashing for integrity, and symmetric versus asymmetric basics; logging, monitoring, and retention; configuration baselines, change management, patch management, and system hardening; and the policy suite (acceptable use, BYOD, password, data handling, and privacy) plus the security awareness program that makes it stick. The 2025 outline expects the AUP conversation to include generative AI tools explicitly.

Practicing for it

Our practice exam mirrors the real thing where it counts: 100 questions stratified to the official domain weights (26 on security principles, 10 on BC/DR/IR, 22 on access controls, 24 on network security, and 18 on security operations) on a 120-minute timer. Every question is a one-best-answer item with plausible near-miss distractors and a full explanation of why the credited answer beats the alternatives, including the AI-integrated material from the October 2025 outline. The pass mark is set at 70%, an honest raw-score equivalent of ISC2’s 700/1000 scaled bar, and because the draw matches the official weights, a passing score here means you covered the whole outline, not luck in the heavy ones.

ISC2 CC - Practice Exam

Full-length 100-question ISC2 Certified in Cybersecurity practice exam stratified to the official domain weights (26/10/22/24/18), including the AI security concepts woven through the October 2025 exam…

100 questions 120 min pass 70%
Subscribe to start

Treat your results diagnostically. Score each domain separately: if you are strong in Domains 1 and 3 but leaking points in Domain 4, that is where the next study block goes, networking is where candidates without an IT background lose the most ground. And since Domain 2 is only ten percent of the exam but nearly pure definitions, it is the cheapest ten percent you will ever earn.

Frequently asked questions about CC

What is the ISC2 Certified in Cybersecurity (CC) certification?

CC is ISC2’s entry point into the profession, the credential built for people stepping into their first security role, changing careers, or finishing a degree. It comes from the same certifying body behind the CISSP, and it proves a working command of security principles, access control, networking, operations, and incident response basics: the vocabulary and judgment a junior analyst is expected to bring on day one.

How many questions are on the CC exam?

The CC exam is delivered as a computerized adaptive test (CAT) at Pearson VUE and serves 100-125 items, depending on how the adaptive engine converges on your ability estimate. There is no fixed question count you can plan around. The test ends when it has enough evidence to score you.

What is the passing score for CC?

You need 700 out of 1000 on ISC2’s scaled scoring system. Scaled scores are not raw percentages, but a fair working equivalent is 70% on a domain-weighted practice exam, which is exactly where the pass mark on Certifym’s CC practice set is placed.

How long is the CC exam and how much does it cost?

The exam runs two hours and costs $199 USD, plus a $50 annual maintenance fee (AMF) to keep the credential in good standing. It is delivered at Pearson VUE test centers.

Do I need work experience or prerequisites for CC?

No. CC requires no work experience, that is the whole design of the credential. It is aimed at candidates entering their first security role, changing careers, or finishing a degree, so there is nothing to document before you sit the exam.

What domains does the CC exam cover, and how are they weighted?

Five domains: Security Principles (26%), Business Continuity, Disaster Recovery & Incident Response Concepts (10%), Access Controls Concepts (22%), Network Security (24%), and Security Operations (18%). Security Principles and Network Security together account for half the exam, so they deserve the largest share of study time.

How hard is the CC exam?

CC is entry-level by design, but it is not trivial for career-changers. Network Security is the most technical domain and the one candidates without an IT background should budget the most time for: OSI layers, TCP versus UDP, well-known ports, IPv4 versus IPv6, firewalls, IDS versus IPS, SIEM, segmentation, VPNs, and zero trust. Domain 2 is the opposite case: only ten percent of the exam and nearly pure definitions, so it is the cheapest ten percent you will ever earn.

What changed in the October 2025 CC exam outline?

The defining change is AI. ISC2 wove foundational AI security through all five domains: data poisoning as an integrity attack on machine-learning models, AI-generated phishing and voice cloning as network threats, the “security of the AI workspace”, the data-leakage risk when employees paste confidential information into public chatbots, and the expectation that acceptable use policies now cover generative AI tools. ISC2 has also announced a refreshed outline effective September 1, 2026, so if your test date falls after that, pull the updated outline before finalizing your plan.

How should I prepare for the CC exam?

Work through the current exam outline domain by domain, then drill with weighted practice. Certifym’s CC practice exam runs 100 questions stratified to the official weights (26 security principles, 10 BC/DR/IR, 22 access controls, 24 network security, 18 security operations) on a 120-minute timer, with a full explanation of why the credited answer beats the near-miss alternatives. Score each domain separately and send the next study block to whichever one is leaking points.

How does CC compare with the SSCP?

CC is the starting line and SSCP is the next rung. CC requires no work experience and covers the fundamentals a junior analyst needs on day one; passing it starts an ISC2 record that compounds as you move up through SSCP, CGRC, CCSP, and eventually CISSP. If you are already working in a hands-on security operations role, SSCP is the natural follow-on.

Trademark notice & independence. Certifym.net is operated by Certifym Exam Services, LLC and is not affiliated with, endorsed by, or sponsored by ISC2, Inc. CC®, CISSP®, SSCP®, CCSP®, CGRC®, and ISC2® are registered trademarks of ISC2, Inc. The CC exam outline and its domain structure are the property of ISC2, Inc.; candidates should download the official, current exam outline directly from isc2.org.

All questions, answers, and explanations on Certifym are original content created for practice purposes. They are not actual ISC2 examination questions and are not represented as such. Practicing with these materials does not guarantee a passing result on any live certification exam.