ISC2 Certified in Cybersecurity (CC) Full-Length Practice Test
One hundred and four questions in 120 minutes. Ten independent CC practice tests follow the exam outline effective September 1, 2026, with an estimated scaled practice score measured against ISC2’s 700-point passing standard.
- 104 questions / 120 min
- Estimated scaled score
- 700 / 1000 benchmark
- 12 Select TWO questions
- 5 current CC domains
Choose one test, five, or the complete set
Every option uses the same 104-question format, the same 120-minute window and the same September 2026 CC blueprint. The difference is how many separate papers you get.
One test
104 questions
One complete 120-minute practice run
- 104 questions across all five current CC domains
- 92 single-answer and 12 Select TWO questions
- Estimated scaled practice score against 700
- An explanation for every question
All 10 tests
1,040 questions
Ten separate full-length CC papers
- 1,040 questions across the complete set
- 120 Select TWO questions across ten tests
- Same 25 / 18 / 21 / 22 / 18 domain allocation every time
- Same 42 easy / 44 medium / 18 hard difficulty mix
- A fresh full-length paper for each new benchmark
Five tests
520 questions
Five complete 120-minute practice runs
- 520 questions across five papers
- 60 Select TWO questions across the pack
- Same five-domain blueprint in every test
- Five separate papers for spaced practice
The September 2026 CC outline is now the live exam
ISC2’s updated Certified in Cybersecurity outline took effect on September 1, 2026. It keeps five domains but changes their names, weights and coverage, including foundational AI security across the outline.
| Current outline | Effective September 1, 2026 |
| Delivery | Computerized Adaptive Testing (CAT) |
| Exam length | 100–125 items |
| Time limit | 2 hours |
| Item formats | Multiple choice and advanced item types |
| Passing standard | 700 out of 1000 points |
| Result report | Pass/fail; no numerical score reported |
| Languages | English, Chinese, Japanese, German, Spanish |
| Testing | Pearson VUE testing centers |
| Work experience | None required |
| Standard exam fee | US$199 |
Written to the current outline
These ten practice tests use the five domains that came into force on September 1: Security Principles, Security Governance, Identity and Access Management Concepts, Networking and Cloud Security Concepts, and Security Operations and Incident Response.
The 104-question form is deliberate. ISC2 publishes a 100–125 item range for the live exam, while these papers hold the count fixed so your results are comparable from one practice test to the next.
The live CC exam is adaptive. These practice tests are linear. They cover the same current content areas and the same two-hour time budget without claiming to reproduce ISC2’s adaptive item selection or stopping rules.
Two hours of foundational security decisions
CC is an entry-level exam, but that does not make every answer obvious. The harder questions come from separating two related ideas: authentication from authorization, continuity from recovery, or a useful control from one that solves the wrong problem.
How it’s built
- 104 questions in a 120-minute practice window
- 92 single-answer questions
- 12 Select TWO questions, scored all-or-nothing
- 42 easy, 44 medium and 18 hard questions
- No negative marking in the practice engine
- Same five-domain allocation across all ten tests
What the questions ask
- Short workplace scenarios at junior cybersecurity level
- Security principles, controls and risk decisions
- Governance, resilience and security awareness
- Identity lifecycle, least privilege and access control
- Network, cloud, operations and incident-response concepts
- Foundational AI security where the current outline includes it
What comes back
- Estimated scaled practice score
- 700 used as the readiness benchmark
- An explanation on every question
- Why the correct option fits the scenario
- Why the strongest alternative is still wrong
Every 104-question test follows the new five-domain blueprint
Security Principles is the largest domain at 24%. The fixed practice form converts ISC2’s published weights into a repeatable 25 / 18 / 21 / 22 / 18 question split.
| Current CC domain | ISC2 average weight | Questions per practice test |
|---|---|---|
| 1. Security Principles | 24% | 25 |
| 2. Security Governance | 17.3% | 18 |
| 3. Identity And Access Management (IAM) Concepts | 20% | 21 |
| 4. Networking and Cloud Security Concepts | 21.3% | 22 |
| 5. Security Operations and Incident Response | 17.3% | 18 |
All 10 ISC2 Certified in Cybersecurity full-length practice tests
Each paper has 104 questions, a 120-minute practice window and the same five-domain allocation.
About the CC exam, and about these practice tests
The ISC2 Certified in Cybersecurity exam
How many questions are on the current ISC2 CC exam?
What score do you need to pass ISC2 CC?
Will I see a numerical score after the live exam?
What changed on September 1, 2026?
Do I need cybersecurity work experience before taking CC?
How much does the CC exam cost?
If I fail CC, when can I retake it?
How do I maintain the CC certification?
These full-length practice tests
Why does each practice test have 104 questions?
Do these practice tests reproduce ISC2 CAT delivery?
What question types are included?
How is the practice score shown?
Is there negative marking?
Does every question include an explanation?
Do all ten tests use the same domain distribution?
Can I buy one test instead of a pack?
Ten practice tests. 1,040 questions.
$9₹499£6.60€7.69
Work through the current September 2026 CC blueprint under the full two-hour clock, then use a fresh paper when you want the next benchmark.
Authors
-
Security Practice Test Editorial Team is the expert content team at SecurityPracticeTest.com dedicated to producing authoritative cybersecurity certification exam-prep resources. We create comprehensive practice tests, study materials, and exam-focused content for top security certifications including CompTIA Security+, SecurityX, PenTest+, CISSP, CCSP, SSCP, Certified in Cybersecurity (CC), CGRC, CISM, SC-900, SC-200, AZ-500, AWS Certified Security - Specialty, Professional Cloud Security Engineer, OSCP+, GIAC certifications, CREST certifications, Check Point, Cisco, Fortinet, and Palo Alto Networks exams. Our content is developed through careful review of official exam objectives, cybersecurity knowledge domains, and practical job-relevant concepts to help learners build confidence, strengthen understanding, and prepare effectively for certification success.
-
Sudhanshu Thakur: ReviewerEnterprise Technology and Digital Transformation Professional with 18+ years of experience in enterprise software, SaaS, industrial automation, and business consulting. Formerly associated with Rockwell Automation, Tech Mahindra, Emerson, ABB, L&T Infotech, and Hewlett Packard Enterprise.