TechNuggets Academy
CC

Free ISC2 Certified in Cybersecurity Practice Test

12 exam-style questions with full explanations — no sign-up. Score yourself, then close your gaps with the full course.

Exam fee ~$505 exam domainsLevel Beginner2 timed practice tests in the course
✅ Free practice — no sign-up📝 Real exam-style questions💡 Detailed explanations💸 30-day money-back via Udemy
Question 1 of 12 · Domain 1: Security Principles
A financial institution requires that when a customer submits a wire transfer request online, the customer cannot later deny having submitted it, and the bank can prove the customer's identity is genuine. Which security concept BEST addresses this requirement?
Non-repudiation ensures a party cannot deny having performed an action, typically achieved through mechanisms like digital signatures that bind an action to a verified identity.
Question 2 of 12 · Domain 2: Incident Response, Business Continuity, and Disaster Recovery Concepts
A ransomware variant encrypts files on a company's file server at 2 AM. The on-call analyst is paged by an EDR alert, isolates the affected server from the network, removes the malicious payload, restores files from the last clean backup, and documents lessons learned the following week. Which security process does this entire sequence of activities describe?
The sequence—detection (alert), containment (isolation), eradication (removing payload), recovery (restoring files), and post-incident review (lessons learned)—maps directly to the phases of the incident response lifecycle.
Question 3 of 12 · Domain 3: Access Controls Concepts
A corporate data center lobby has a small enclosed space with two interlocking doors: a person must close and lock the first door before the second door will open, and only one person is allowed inside at a time. What is the PRIMARY security purpose of this design?
This describes a mantrap (access control vestibule). Its core purpose is to physically enforce single-person entry so that an authenticated individual cannot be followed in by an unauthorized person (tailgating/piggybacking).
Question 4 of 12 · Domain 4: Network Security
A company's public-facing web server becomes completely unresponsive after receiving a massive flood of TCP SYN packets originating from thousands of distinct, spoofed source IP addresses simultaneously. Which type of attack does this scenario describe?
A flood of SYN packets from many distributed sources exhausting the server's connection resources is the classic signature of a DDoS SYN flood, an availability attack that overwhelms the TCP three-way handshake process.
Question 5 of 12 · Domain 5: Security Operations
A hospital is retiring several servers whose hard drives contained protected health information (PHI). IT plans to donate the drives to a local school once decommissioned, so the drives must remain functional and reusable. Which data sanitization method BEST meets this requirement?
NIST 800-88 defines 'Purge' as an appropriate sanitization method when media is leaving organizational control but must remain reusable — cryptographic erase or multi-pass overwrite destroys data recoverability while preserving drive functionality.
Question 6 of 12 · Domain 1: Security Principles
An organization determines that the cost of implementing additional controls for a rarely used legacy reporting tool exceeds the potential loss from a security incident affecting it. Instead of building additional controls, the organization purchases a cyber insurance policy to cover potential financial losses. Which risk treatment strategy does this represent?
Purchasing insurance shifts the financial impact of a risk to a third party (the insurer), which is the definition of risk transfer.
Question 7 of 12 · Domain 2: Incident Response, Business Continuity, and Disaster Recovery Concepts
A regional flood makes a company's headquarters building unusable for three months. During this time, the payroll, customer support, and order-processing teams must continue operating from an alternate location using pre-arranged staff, equipment, and procedures. Which plan is primarily responsible for ensuring these critical business functions continue during the disruption?
A business continuity plan (BCP) focuses on ensuring that essential business operations and functions continue during and after a disruptive event, which is exactly what is described here.
Question 8 of 12 · Domain 3: Access Controls Concepts
A finance department requires that the employee who creates a vendor payment request cannot be the same employee who approves that payment for disbursement. Which access control concept does this policy implement?
Segregation of duties (SoD) splits a critical process into multiple steps performed by different people so that no single individual can complete a fraudulent transaction end-to-end.
Question 9 of 12 · Domain 4: Network Security
At which layer of the OSI model does a network switch primarily operate when it forwards frames based on MAC address tables?
Standard switches build and use MAC address tables to forward Ethernet frames within a Layer 2 broadcast domain, which is why they are classified as Data Link layer devices.
Question 10 of 12 · Domain 5: Security Operations
A company needs to encrypt 500GB of files on a file server every night as part of an automated backup job. Performance and speed are critical concerns. Which type of encryption is BEST suited for this bulk encryption task?
Symmetric algorithms like AES use a single shared key and are computationally efficient, making them the standard choice for encrypting large volumes of data quickly.
Question 11 of 12 · Domain 1: Security Principles
A company requires all employees to complete an annual security awareness training course covering phishing recognition and password hygiene. Which type of security control is this?
Security awareness training is an administrative (management) control, established through policies and programs that shape personnel behavior and knowledge.
Question 12 of 12 · Domain 2: Incident Response, Business Continuity, and Disaster Recovery Concepts
An organization is creating documentation that will specifically guide the technical steps for rebuilding servers, restoring data from backups, and bringing the data center back online after a hurricane destroys the facility. Which document should this information be captured in?
A disaster recovery plan (DRP) specifically addresses restoring IT infrastructure, systems, and data after a disruptive event such as a natural disaster, which matches the described technical rebuilding and restoration activities.
Ready for the real thing?

The full course: two full-length practice tests, video lessons for every exam domain, hands-on labs and detailed explanations.

undefined $34.99 with code SECPREP34 — valid through Oct 11.

Get my $34.99 deal →

CC exam — quick answers

How much does the CC exam cost?

The exam fee is approximately $50 and varies by region — confirm current pricing with the certification vendor before you book.

What topics are on the exam?

It covers 5 domains: Security Principles (26%), Incident Response, Business Continuity, and Disaster Recovery Concepts (10%), Access Controls Concepts (22%), Network Security (24%), Security Operations (18%). The full course has a dedicated chapter, lab and practice-test coverage for each.

Is this practice test really free?

Yes — all questions on this page are free with explanations and no sign-up. The paid Udemy course adds two full-length timed exams, video lessons and hands-on labs.

How do I get the discount?

Use code SECPREP34 at checkout for $34.99 (list undefined) through Oct 11 — the enroll button applies it automatically.

Will this prepare me for the real exam?

The questions mirror the real exam's style and are mapped to the official domains. This is exam-focused preparation — combine the free test with the full course's timed simulations to gauge your readiness.

More free practice by exam domain:
Security Principles →Access Controls Concepts →Network Security →Security Operations →