ISC2 Certification

Certified in Cybersecurity (CC) Practice Test

Prepare for the ISC2 Certified in Cybersecurity exam with free practice tests aligned to the real CC format. Each test has 20 questions with a proportional timer matching the actual exam pace of 1.2 minutes per question.

10Practice Tests
200Total Questions
5Domains Covered
100%Free Forever

Mixed Set — Certified in Cybersecurity (CC) Practice Tests

Questions distributed across all 5 domains according to the official ISC2 CC exam blueprint. The highest-weighted domain — Security Principles — appears most frequently, just like the real exam.

About the Certified in Cybersecurity (CC) Exam

Everything you need to know about the CC exam format, who it is for, and why the ISC2 Certified in Cybersecurity credential is one of the best entry points into a professional cybersecurity career.

What Is the Certified in Cybersecurity (CC)?

The ISC2 Certified in Cybersecurity (CC) is an entry-level cybersecurity certification designed for individuals starting their security career — including career changers, recent graduates, IT professionals transitioning into security, and those with no prior cybersecurity experience. Launched by ISC2 as part of their One Million Certified in Cybersecurity (1MCC) initiative, the CC was created to help address the global cybersecurity workforce gap by making a credible, ANAB-accredited certification accessible to a broad audience.

The CC validates foundational knowledge across five core domains: Security Principles, Business Continuity and Incident Response, Access Controls, Network Security, and Security Operations. It is recognized globally and backed by ISC2 — the world's largest cybersecurity professional organization. Holders qualify for entry-level roles including SOC Analyst (Tier 1), Junior Security Analyst, IT Support Specialist with a security focus, Cybersecurity Technician, and Junior Security Consultant. The CC also serves as a natural stepping stone toward advanced ISC2 certifications such as the SSCP and CISSP.

Exam Format (2026)

Testing method: Computerized Adaptive Testing (CAT) at authorized Pearson VUE testing centers worldwide. Moved to CAT format globally in October 2025.

Questions: 100 multiple-choice questions.

Duration: 2 hours (approximately 1.2 minutes per question).

Question types: Multiple-choice with a single correct answer per question. No back-navigation — answers are final once submitted.

Passing score: 700 on a scaled score of 1,000 points.

Exam fee: $199 USD standard; free for eligible candidates through ISC2's One Million Certified in Cybersecurity (1MCC) program.

Eligibility Requirements

Prerequisites: None. The CC has no formal prerequisites and is open to anyone regardless of experience level or educational background.

Work experience: Not required. The CC is specifically designed for individuals without prior cybersecurity work experience.

Free program eligibility: Through ISC2's 1MCC initiative, candidates who are not already ISC2-certified can access free online self-paced training and one free exam attempt. Visit isc2.org/landing/1mcc to enroll.

Certification application: After passing, submit your application and agree to the ISC2 Code of Ethics within 9 months. No endorsement from another ISC2 member is required for the CC.

Renewal: Pay an Annual Maintenance Fee (AMF) of $50 per year to keep the certification active. Note: A new CC exam outline takes effect September 1, 2026 — check the official ISC2 site if your exam is near or after that date.

CC Domain Weights — Current Exam Outline

The CC exam tests knowledge across five entry-level cybersecurity domains. Security Principles carries the most weight at 26%, making it the highest-priority study area along with Network Security (24%) and Access Controls Concepts (22%).

DomainTopicWeight
Domain 1Security Principles26%
Domain 2Business Continuity (BC), Disaster Recovery (DR) & Incident Response Concepts10%
Domain 3Access Controls Concepts22%
Domain 4Network Security24%
Domain 5Security Operations18%

How Our Practice Tests Are Designed

Entry-level scenario style — Every CC practice question is written to match the conceptual and scenario-based style used in the actual ISC2 exam. You are tested on your ability to apply fundamental cybersecurity knowledge to realistic situations — choosing the correct access control model for a scenario, identifying the right network security device, or selecting the appropriate incident response step — rather than simply recalling definitions.

Blueprint-aligned mixed sets — Mixed practice tests distribute questions proportionally across all 5 CC domains per the official ISC2 exam outline. Domain 1 (Security Principles) at 26% and Domain 4 (Network Security) at 24% appear most frequently, reflecting the real exam's weighting so your practice mirrors actual exam conditions.

Proportional timer — The real CC exam allows 2 hours for 100 questions, approximately 1.2 minutes per question. Each 20-question practice test is timed at about 24 minutes to match this pace and build the time discipline needed on exam day.

Domain-specific deep dives — Use the five domain-wise tests to concentrate on areas where your preparation needs the most reinforcement. This targeted approach is especially valuable for candidates who are stronger in one area (such as network security) but need additional work in others (such as access control models or BC/DR concepts).

CC Exam Preparation Tips

Study Strategy

Start with the free ISC2 self-paced training: ISC2 provides free online self-paced training for CC candidates through the 1MCC program. This official course is aligned directly to the exam outline and is the most accurate study resource available. Use it as your primary foundation before supplementing with practice tests.

Prioritize Domains 1, 3, and 4: Security Principles (26%), Access Controls (22%), and Network Security (24%) together make up 72% of the exam. Ensure you have a strong grasp of the CIA triad, access control models, and OSI/TCP-IP concepts before focusing on the lower-weight domains.

Understand concepts, not just definitions: The CC exam tests application of knowledge. Study each concept by asking "How would this apply in a real scenario?" — such as which type of control to implement, or what the first step of the incident response process would be in a given situation.

Test-Taking Strategy

No going back in CAT: The CC moved to Computerized Adaptive Testing in October 2025. Once you submit an answer, you cannot return to it. Read each question carefully, commit to your best answer, and move forward — do not leave any question unanswered hoping to return.

Pace yourself at 1.2 minutes per question: With 100 questions in 2 hours, you have roughly 72 seconds per item. Use our 24-minute timed practice sessions to internalize this rhythm. Candidates who underestimate the pace often find themselves rushing through the final 20 questions under pressure.

Eliminate distractor answers systematically: CC questions often include two clearly wrong answers and two plausible ones. Eliminate the obviously incorrect options first, then choose the response that best fits the principle being tested — favoring answers that align with least privilege, defense-in-depth, or standard security best practices.

Frequently Asked Questions

How many questions are on the real CC exam?+
The CC exam consists of 100 multiple-choice questions. The exam uses Computerized Adaptive Testing (CAT), which adjusts question difficulty based on your performance as you progress. You have 2 hours to complete all 100 questions. Once you submit an answer, you cannot go back and change it — the CAT format does not allow back-navigation.
What is the passing score for the CC exam?+
You need a scaled score of 700 out of 1,000 to pass. ISC2 uses a compensatory scoring model, which means your overall combined performance across all domains determines your result — there is no minimum per-domain score requirement. As long as your total scaled score reaches 700, you pass regardless of how performance is distributed across individual domains.
Is the CC exam really free?+
Through ISC2's One Million Certified in Cybersecurity (1MCC) initiative, eligible candidates can access the official self-paced training and one free exam attempt. To qualify, you must not already hold an ISC2 certification. If you pass, you then pay the $50 Annual Maintenance Fee to activate and maintain the certification each year. Retakes, if needed, are paid at the standard exam fee.
Are these CC practice tests free?+
Yes. All Certified in Cybersecurity practice tests on Security Practice Test are completely free with no account or sign-up required. Select any mixed set or domain-wise test and begin immediately — there are no subscriptions, paywalls, or hidden fees of any kind.
Do I need prior experience to take the CC exam?+
No experience is required. The CC is specifically designed for individuals without prior cybersecurity work experience — including career changers, recent graduates, and complete beginners. It is one of the few globally recognized cybersecurity certifications with zero prerequisites, making it an ideal starting point for anyone entering the field.
How long should I study for the CC exam?+
Most candidates prepare in 2 to 4 weeks. Those with an IT background may be ready in 1 to 2 weeks, while complete beginners to security concepts may benefit from 4 to 6 weeks of study. The free ISC2 online self-paced training course, combined with consistent practice testing and a focus on the higher-weighted domains, is the most efficient preparation path for the majority of candidates.
What happens after I pass the CC exam?+
After passing, you will receive a preliminary pass result at the testing center. Within 9 months, you must log in to your ISC2 account, agree to the ISC2 Code of Professional Ethics, and submit your certification application. Unlike other ISC2 certifications, the CC does not require endorsement from another ISC2-certified professional. Once your application is processed and your Annual Maintenance Fee is paid, you become a fully certified ISC2 CC holder.
What career roles does the CC prepare me for?+
The CC prepares candidates for entry-level and junior cybersecurity roles including SOC Analyst (Tier 1), Junior Security Analyst, IT Support Specialist with a security focus, Cybersecurity Technician, and Junior Security Consultant. It also serves as a recognized credential for employers evaluating candidates for security-adjacent IT roles. Many CC holders use it as a foundation to advance toward the ISC2 SSCP and eventually the CISSP.

Ready to Test Your CC Knowledge?

Start with a mixed set to measure your readiness across all five domains, then use domain-wise tests to sharpen your weakest areas before exam day.

Start CC Practice Test 1 →

Authors

  • Security Practice Test Editorial Team

    Security Practice Test Editorial Team is the expert content team at SecurityPracticeTest.com dedicated to producing authoritative cybersecurity certification exam-prep resources. We create comprehensive practice tests, study materials, and exam-focused content for top security certifications including CompTIA Security+, SecurityX, PenTest+, CISSP, CCSP, SSCP, Certified in Cybersecurity (CC), CGRC, CISM, SC-900, SC-200, AZ-500, AWS Certified Security - Specialty, Professional Cloud Security Engineer, OSCP+, GIAC certifications, CREST certifications, Check Point, Cisco, Fortinet, and Palo Alto Networks exams. Our content is developed through careful review of official exam objectives, cybersecurity knowledge domains, and practical job-relevant concepts to help learners build confidence, strengthen understanding, and prepare effectively for certification success.

  • Sudhanshu Thakur - Reviewer

    Enterprise Technology and Digital Transformation Professional with 18+ years of experience in enterprise software, SaaS, industrial automation, and business consulting. Formerly associated with Rockwell Automation, Tech Mahindra, Emerson, ABB, L&T Infotech, and Hewlett Packard Enterprise.