Skip to content

Latest commit

Β 

History

1 Commit

Folders and files

NameName
Last commit message
Last commit date
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 

Repository files navigation

CC Study Guide: ISC2 Certified in Cybersecurity (CC)

A free, open study guide for the ISC2 Certified in Cybersecurity (CC) (CC) exam: revision notes for every domain, side-by-side comparisons of commonly confused services, a glossary, 20 worked sample questions, and the official syllabus as a checklist with a full free lesson for every topic.

Maintained by SaveMyCert, where you can read every lesson free, practice with explained questions and take timed mock exams.

Contents

Exam at a glance

Exam code CC
Level Foundational
Questions 100–125
Time limit 120 min
Passing score 700 / 1000
Format Adaptive (CAT), multiple choice
Exam fee $199
Valid for 3 years

Exam details change. Always confirm them in the official ISC2 Certified in Cybersecurity exam outline from ISC2.

Exam domains

# Domain Weight Topics
1 Security Principles 24% 5
2 Security Governance 17% 4
3 Identity And Access Management (IAM) Concepts 20% 2
4 Networking and Cloud Security Concepts 22% 3
5 Security Operations and Incident Response 17% 5

That is 5 domains and 19 topics. Spend your time in proportion to the weights: the heaviest domain decides more of your score than the lightest.

ISC2 publishes some weights with decimals (for example 17.3%). The figures here are rounded to add up to 100%.

What is in this repo

File What it gives you
Domain 1 notes Security Principles: condensed revision notes per topic
Domain 2 notes Security Governance: condensed revision notes per topic
Domain 3 notes Identity And Access Management (IAM) Concepts: condensed revision notes per topic
Domain 4 notes Networking and Cloud Security Concepts: condensed revision notes per topic
Domain 5 notes Security Operations and Incident Response: condensed revision notes per topic
Commonly confused services Side-by-side tables of the services questions set against each other
Glossary Every in-scope term and service in one sentence
Sample questions 20 worked questions with answers and reasoning
Exam-day guide Booking, testing options, scoring, results and retakes

Syllabus checklist

Tick each topic off once you can explain it without notes. The "Must know" facts are the ones questions turn on. Each lesson link goes to the complete, free lesson.

Domain 1: Security Principles

Weight: 24%. Core cybersecurity concepts, risk management, governance, controls, and professional ethics. Official weighting 24%.

πŸ“ Revision notes: Domain 1: Security Principles

  • Understand cybersecurity concepts
    Confidentiality, integrity, and availability (the CIA triad); Authentication, Authorization, and Accounting (AAA); non-repudiation; and privacy.
    • πŸ“– Lesson: CIA Triad, AAA, and Non-Repudiation: Core ISC2 CC Security Concepts
    • Must know: CIA = Confidentiality (only authorized eyes), Integrity (accurate and unaltered), Availability (usable when needed)
    • Must know: Match controls to properties: encryption protects confidentiality, hashing protects integrity, backups and redundancy protect availability
  • Understand risk management concepts
    The risk management lifecycle and the risk management processes (identification, assessment, treatment, and monitoring).
  • Understand governance concepts
    Regulations and laws; frameworks and guidelines; and policies, standards (e.g., ISO, Center for Internet Security), and procedures.
  • Understand cybersecurity controls
    Technical controls, administrative controls, and physical controls, and how they combine to reduce risk.
  • Maintain professional and ethical conduct
    Professional code of conduct; due care and due diligence; and the ISC2 Code of Ethics.

Domain 2: Security Governance

Weight: 17%. Governance, Risk, and Compliance; redundancy (BC/DR); security awareness; and measuring effectiveness. Official weighting 17.3%.

πŸ“ Revision notes: Domain 2: Security Governance

  • Plan Governance, Risk, and Compliance (GRC)
    The purpose and importance of Governance, Risk, and Compliance (GRC), and GRC frameworks and tools.
    • πŸ“– Lesson: Governance, Risk, and Compliance (GRC) for the ISC2 CC Exam
    • Must know: Governance is leadership setting direction: policy, accountability, and alignment of security with business objectives.
    • Must know: Governance decides what should happen and verifies it did; management executes it day to day.
  • Understand redundancy
    Redundancy through Business Continuity (BC) and Disaster Recovery (DR).
  • Understand security awareness
    Organizational culture (importance of security, security leadership) and awareness concepts (social engineering, password protection, phishing).
    • πŸ“– Lesson: Security Awareness: Social Engineering, Phishing, and Password Hygiene
    • Must know: Security is everyone's responsibility; leadership tone from the top and a blame-free reporting culture make awareness effective
    • Must know: Social engineering manipulates people using authority, urgency, scarcity, familiarity, intimidation, and social proof
  • Measure cybersecurity effectiveness
    Key metrics and Key Risk Indicators (KRIs); and dashboards, scorecards, and reports.

Domain 3: Identity And Access Management (IAM) Concepts

Weight: 20%. Identity lifecycle management and logical access controls. Official weighting 20%.

πŸ“ Revision notes: Domain 3: Identity And Access Management (IAM) Concepts

  • Understand identity life cycle management
    Roles definition, provisioning, review, and deprovisioning; and identity frameworks and tools.
  • Understand logical access controls
    The Principle of Least Privilege (PoLP), Separation of Duties (SoD), and access control models (e.g., DAC, MAC, RBAC).
    • πŸ“– Lesson: Logical Access Controls: Least Privilege, DAC, MAC, and RBAC
    • Must know: Least privilege: grant the minimum access the job requires; need-to-know further restricts specific information.
    • Must know: Separation of Duties splits a sensitive process so no one person can commit and conceal fraud; collusion becomes required.

Domain 4: Networking and Cloud Security Concepts

Weight: 22%. Network security, network security architecture, and cloud security. Official weighting 21.3%.

πŸ“ Revision notes: Domain 4: Networking and Cloud Security Concepts

  • Understand network security
    Networking concepts (OSI and TCP/IP models, IPv4/IPv6, VPN); firewalls (ports, applications); wireless (Wi-Fi, Bluetooth); and embedded systems (Industrial Control Systems) and the Internet of Things (IoT).
    • πŸ“– Lesson: Network Security Basics: OSI Model, TCP/IP, Firewalls, and VPNs
    • Must know: The OSI model has seven layers; the TCP/IP model has four, with the TCP/IP Application layer covering OSI layers 5 to 7.
    • Must know: IP addresses and routing are Layer 3; MAC addresses and switches are Layer 2; TCP and UDP with port numbers are Layer 4.
  • Understand network security architecture
    Network segmentation (firewall zones, VLANs, micro-segmentation); Defense in Depth; and Zero Trust (ZT).
  • Understand cloud security
    Cloud characteristics (broad network access, rapid elasticity, measured service, on-demand self-service, resource pooling); service models; deployment models; and the shared security (responsibility) model.
    • πŸ“– Lesson: Cloud Security: Shared Responsibility, IaaS vs PaaS vs SaaS, Deployment Models
    • Must know: The five essential cloud characteristics: on-demand self-service, broad network access, resource pooling, rapid elasticity, measured service.
    • Must know: IaaS rents infrastructure (you manage the OS up), PaaS rents a managed platform (you bring code and data), SaaS rents a finished application (you bring data and users).

Domain 5: Security Operations and Incident Response

Weight: 17%. Data security, security operations, incident response, asset protection, and security testing. Official weighting 17.3%.

πŸ“ Revision notes: Domain 5: Security Operations and Incident Response

  • Understand data security
    Data handling (classification, labeling, masking, sanitization); and encryption (symmetric, asymmetric, hashing, quantum-resistant cryptography).
    • πŸ“– Lesson: Data Security: Classification, Masking, Sanitization, and Encryption Basics
    • Must know: Classification labels data by sensitivity (for example public, internal, confidential, restricted), and the label determines how strongly the data is protected.
    • Must know: Masking obscures displayed values (showing only the last four digits); the underlying data still exists and there is no key to reverse it.
  • Understand security operations
    Logging and monitoring of security events; security event triage (incident use cases, prioritization, correlation); threat actors (types, motivations); cyber threat intelligence; and threat frameworks.
  • Understand Incident Response (IR)
    Implementing an Incident Response Plan (IRP) with data-handling policy; and Incident Response exercises (testing, tabletop).
    • πŸ“– Lesson: Incident Response: The IR Plan, Phases, CSIRT and Tabletop Exercises
    • Must know: An event is any observable occurrence; an incident is an event that harms or threatens confidentiality, integrity, or availability.
    • Must know: The IRP is written and approved before an incident and defines roles, criteria, escalation paths, and procedures.
  • Understand asset protection
    Asset lifecycle management (End Of Life software and devices); and configuration and change management.
    • πŸ“– Lesson: Asset Lifecycle, Configuration Management, and Change Management
    • Must know: You cannot protect what you do not know you have: the asset inventory is the foundation of asset protection.
    • Must know: The asset lifecycle runs acquisition, deployment, use, maintenance, and secure disposal, with security duties at every stage.
  • Understand security testing
    Security readiness testing (blue, purple, and red teaming); application testing (vulnerability scanning, static and dynamic analysis, threat modeling); and physical penetration testing (phishing, tailgating, impersonation).

How to study for CC

  1. Read the lesson for each topic in the checklist above, starting with the heaviest domain. Every lesson is free on the CC revision notes.
  2. Practice straight after reading. Answer CC practice questions on the topic you just read. Each option comes with an explanation of why it is right or wrong.
  3. Review what you got wrong, re-read that lesson section, and tick the topic off only when you get its questions right.
  4. Take a full-length CC mock exam under the real time limit. Aim to pass mocks comfortably before you book.
  5. On the last day, skim the CC cheat sheet instead of starting anything new.

Sample questions

sample-questions.md has 20 worked CC questions with the answer, why each option is right or wrong, and the reasoning steps.

Free resources

Contributing

Spotted an error or an out-of-date fact? Open an issue with the topic and a link to the official source. See CONTRIBUTING.md.

License and disclaimer

This guide is licensed under CC BY 4.0. You can reuse and adapt it, including commercially, as long as you credit SaveMyCert with a link to https://www.savemycert.com/.

This is an independent study resource. It is not affiliated with or endorsed by ISC2. ISC2 Certified in Cybersecurity (CC) and CC are trademarks of their respective owner. Exam domains and weights are taken from the official exam guide linked above.

About

Free CC study guide: the full ISC2 Certified in Cybersecurity (CC) exam blueprint as a checklist, key facts per topic, and worked sample questions.

Topics

Resources

Contributing

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors