ISC2 CERTIFIED IN CYBERSECURITY (CC) PRACTICE
EXAM QUESTIONS
A vendor sells a particular operating system (OS). In order to deploy the OS securely on
different platforms, the vendor publishes several sets of instructions on how to install it,
depending on which platform the customer is using. This is an example of ______.
A. Law
B. Procedure
C. Standard
D. Policy - Answers-B. Procedure
The city of Grampon wants to know where all its public vehicles (garbage trucks, police
cars, etc.) are at all times, so the city has GPS transmitters installed in all the vehicles.
What kind of control is this?
A. Administrative
B. Entrenched
C. Physical
D. Technical - Answers-D. Technical
Triffid Corporation has a rule that all employees working with sensitive hardcopy
documents must put the documents into a safe at the end of the workday, where they
are locked up until the following workday. What kind of control is the process of putting
the documents into the safe?
A. Administrative
B. Tangential
C. Physical
D. Technical - Answers-A. Administrative
Grampon municipal code requires that all companies that operate within city limits will
have a set of processes to ensure employees are safe while working with hazardous
materials. Triffid Corporation creates a checklist of activities employees must follow
while working with hazardous materials inside Grampon city limits. The municipal code
is a ______, and the Triffid checklist is a ________.
A. Law, procedure
B. Standard, law
C. Law, standard
D. Policy, standard
E. Policy, law - Answers-A. Law, procedure
Which of the following is an example of a "something you know" authentication factor?
A. User ID
B. Password
C. Fingerprint
D. Iris scan - Answers-B. Password
,Tina is an (ISC)² member and is invited to join an online group of IT security
enthusiasts. After attending a few online sessions, Tina learns that some participants in
the group are sharing malware with each other, in order to use it against other
organizations online. What should Tina do?
A. Nothing
B. Stop participating in the group
C. Report the group to law enforcement
D. Report the group to (ISC)2 - Answers-B. Stop participating
A bollard is a post set securely in the ground in order to prevent a vehicle from entering
an area or driving past a certain point. Bollards are an example of ______ controls.
A. Physical
B. Administrative
C. Drastic
D. Technical - Answers-A. Physical
Triffid Corporation has a policy that all employees must receive security awareness
instruction before using email; the company wants to make employees aware of
potential phishing attempts that the employees might receive via email. What kind of
control is this instruction?
A. Administrative
B. Finite
C. Physical
D. Technical - Answers-A. Administrative
The Triffid Corporation publishes a strategic overview of the company's intent to secure
all the data the company possesses. This document is signed by Triffid senior
management. What kind of document is this?
A. Policy
B. Procedure
C. Standard
D. Law - Answers-A. Policy
Chad is a security practitioner tasked with ensuring that the information on the
organization's public website is not changed by anyone outside the organization. This
task is an example of ensuring _________.
A. Confidentiality
B. Integrity
C. Availability
D. Confirmation - Answers-B. Integrity
The city of Grampon wants to ensure that all of its citizens are protected from malware,
so the city council creates a rule that anyone caught creating and launching malware
within the city limits will receive a fine and go to jail. What kind of rule is this?
A. Policy
B. Procedure
, C. Standard
D. Law - Answers-D. Law
Zarma is an (ISC)² member and a security analyst for Triffid Corporation. One of
Zarma's colleagues is interested in getting an (ISC)2 certification and asks Zarma what
the test questions are like. What should Zarma do?
A. Inform (ISC)2
B. Explain the style and format of the questions, but no detail
C. Inform the colleague's supervisor
D. Nothing - Answers-B. Explain the style and format of the questions, but no detail
Druna is a security practitioner tasked with ensuring that laptops are not stolen from the
organization's offices. Which sort of security control would probably be best for this
purpose?
A. Technical
B. Observe
C. Physical
D. Administrative - Answers-C. Physical
For which of the following assets is integrity probably the most important security
aspect?
A. One frame of a streaming video
B. The file that contains passwords used to authenticate users
C. The color scheme of a marketing website
D. Software that checks the spelling of product descriptions for a retail website -
Answers-B. The file that contains passwords used to authenticate users
Jengi is setting up security for a home network. Jengi decides to configure MAC
address filtering on the router, so that only specific devices will be allowed to join the
network. This is an example of a(n)_______ control.
A. Physical
B. Administrative
C. Substantial
D. Technical - Answers-D. Technical
Siobhan is an (ISC)² member who works for Triffid Corporation as a security analyst.
Yesterday, Siobhan got a parking ticket while shopping after work. What should
Siobhan do?
A. Inform (ISC)2
B. Pay the parking ticket
C. Inform supervisors at Triffid
D. Resign employment from Triffid - Answers-B. Pay the parking ticket
Hoshi is an (ISC)² member who works for the Triffid Corporation as a data manager.
Triffid needs a new firewall solution, and Hoshi is asked to recommend a product for
The benefits of buying summaries with Stuvia:
Guaranteed quality through customer reviews
Stuvia customers have reviewed more than 700,000 summaries. This how you know that you are buying the best documents.
Quick and easy check-out
You can quickly pay through credit card or Stuvia-credit for the summaries. There is no membership needed.
Focus on what matters
Your fellow students write the study notes themselves, which is why the documents are always reliable and up-to-date. This ensures you quickly get to the core!
Frequently asked questions
What do I get when I buy this document?
You get a PDF, available immediately after your purchase. The purchased document is accessible anytime, anywhere and indefinitely through your profile.
Satisfaction guarantee: how does it work?
Our satisfaction guarantee ensures that you always find a study document that suits you well. You fill out a form, and our customer service team takes care of the rest.
Who am I buying these notes from?
Stuvia is a marketplace, so you are not buying this document from us, but from seller GEEKA. Stuvia facilitates payment to the seller.
Will I be stuck with a subscription?
No, you only buy these notes for $12.99. You're not tied to anything after your purchase.