A free, open study guide for the ISC2 Certified in Cybersecurity (CC) (CC) exam: revision notes for every domain, side-by-side comparisons of commonly confused services, a glossary, 20 worked sample questions, and the official syllabus as a checklist with a full free lesson for every topic.
Maintained by SaveMyCert, where you can read every lesson free, practice with explained questions and take timed mock exams.
- Exam at a glance
- Exam domains
- What is in this repo
- Syllabus checklist
- How to study for CC
- Sample questions
- Free resources
| Exam code | CC |
| Level | Foundational |
| Questions | 100β125 |
| Time limit | 120 min |
| Passing score | 700 / 1000 |
| Format | Adaptive (CAT), multiple choice |
| Exam fee | $199 |
| Valid for | 3 years |
Exam details change. Always confirm them in the official ISC2 Certified in Cybersecurity exam outline from ISC2.
| # | Domain | Weight | Topics |
|---|---|---|---|
| 1 | Security Principles | 24% | 5 |
| 2 | Security Governance | 17% | 4 |
| 3 | Identity And Access Management (IAM) Concepts | 20% | 2 |
| 4 | Networking and Cloud Security Concepts | 22% | 3 |
| 5 | Security Operations and Incident Response | 17% | 5 |
That is 5 domains and 19 topics. Spend your time in proportion to the weights: the heaviest domain decides more of your score than the lightest.
ISC2 publishes some weights with decimals (for example 17.3%). The figures here are rounded to add up to 100%.
| File | What it gives you |
|---|---|
| Domain 1 notes | Security Principles: condensed revision notes per topic |
| Domain 2 notes | Security Governance: condensed revision notes per topic |
| Domain 3 notes | Identity And Access Management (IAM) Concepts: condensed revision notes per topic |
| Domain 4 notes | Networking and Cloud Security Concepts: condensed revision notes per topic |
| Domain 5 notes | Security Operations and Incident Response: condensed revision notes per topic |
| Commonly confused services | Side-by-side tables of the services questions set against each other |
| Glossary | Every in-scope term and service in one sentence |
| Sample questions | 20 worked questions with answers and reasoning |
| Exam-day guide | Booking, testing options, scoring, results and retakes |
Tick each topic off once you can explain it without notes. The "Must know" facts are the ones questions turn on. Each lesson link goes to the complete, free lesson.
Weight: 24%. Core cybersecurity concepts, risk management, governance, controls, and professional ethics. Official weighting 24%.
π Revision notes: Domain 1: Security Principles
- Understand cybersecurity concepts
Confidentiality, integrity, and availability (the CIA triad); Authentication, Authorization, and Accounting (AAA); non-repudiation; and privacy.- π Lesson: CIA Triad, AAA, and Non-Repudiation: Core ISC2 CC Security Concepts
- Must know: CIA = Confidentiality (only authorized eyes), Integrity (accurate and unaltered), Availability (usable when needed)
- Must know: Match controls to properties: encryption protects confidentiality, hashing protects integrity, backups and redundancy protect availability
- Understand risk management concepts
The risk management lifecycle and the risk management processes (identification, assessment, treatment, and monitoring).- π Lesson: Risk Management for the ISC2 CC Exam: Lifecycle, Assessment, and Treatment
- Must know: Risk = likelihood x impact; it exists only where a threat can exploit a vulnerability in an asset
- Must know: Threat is the external potential for harm; vulnerability is the internal weakness it exploits - keep them separate
- Understand governance concepts
Regulations and laws; frameworks and guidelines; and policies, standards (e.g., ISO, Center for Internet Security), and procedures.- π Lesson: Security Governance: Laws, Frameworks, Policies, Standards, Procedures
- Must know: Laws and regulations are mandatory, externally imposed, and enforced with penalties
- Must know: GDPR protects EU personal data; HIPAA protects US health information: both are laws, not frameworks
- Understand cybersecurity controls
Technical controls, administrative controls, and physical controls, and how they combine to reduce risk.- π Lesson: Security Controls: Technical, Administrative, and Physical Types
- Must know: Control type describes implementation: technical (logical), administrative (managerial), or physical
- Must know: Technical controls are enforced by hardware and software: firewalls, encryption, ACLs, IDS and IPS, MFA
- Maintain professional and ethical conduct
Professional code of conduct; due care and due diligence; and the ISC2 Code of Ethics.- π Lesson: ISC2 Code of Ethics, Due Care, and Due Diligence for the CC Exam
- Must know: Due care is action: taking the reasonable precautions a prudent person would take.
- Must know: Due diligence is investigation: the ongoing research and verification that informs due care.
Weight: 17%. Governance, Risk, and Compliance; redundancy (BC/DR); security awareness; and measuring effectiveness. Official weighting 17.3%.
π Revision notes: Domain 2: Security Governance
- Plan Governance, Risk, and Compliance (GRC)
The purpose and importance of Governance, Risk, and Compliance (GRC), and GRC frameworks and tools.- π Lesson: Governance, Risk, and Compliance (GRC) for the ISC2 CC Exam
- Must know: Governance is leadership setting direction: policy, accountability, and alignment of security with business objectives.
- Must know: Governance decides what should happen and verifies it did; management executes it day to day.
- Understand redundancy
Redundancy through Business Continuity (BC) and Disaster Recovery (DR).- π Lesson: Business Continuity, Disaster Recovery, and Redundancy Explained
- Must know: BC keeps critical business functions running during a disruption; DR restores IT systems and data after it.
- Must know: DR is a subset of BC: BC covers people, processes, and facilities, while DR focuses only on IT.
- Understand security awareness
Organizational culture (importance of security, security leadership) and awareness concepts (social engineering, password protection, phishing).- π Lesson: Security Awareness: Social Engineering, Phishing, and Password Hygiene
- Must know: Security is everyone's responsibility; leadership tone from the top and a blame-free reporting culture make awareness effective
- Must know: Social engineering manipulates people using authority, urgency, scarcity, familiarity, intimidation, and social proof
- Measure cybersecurity effectiveness
Key metrics and Key Risk Indicators (KRIs); and dashboards, scorecards, and reports.- π Lesson: Measuring Security Effectiveness: Metrics, KPIs, and Key Risk Indicators
- Must know: You cannot manage what you do not measure; metrics turn security from faith into evidence for decisions
- Must know: Good metrics are meaningful and actionable; a number nobody acts on is a vanity metric
Weight: 20%. Identity lifecycle management and logical access controls. Official weighting 20%.
π Revision notes: Domain 3: Identity And Access Management (IAM) Concepts
- Understand identity life cycle management
Roles definition, provisioning, review, and deprovisioning; and identity frameworks and tools.- π Lesson: Identity Life Cycle Management: Provisioning, Review, and Deprovisioning
- Must know: The identity life cycle is roles definition, provisioning, review, and deprovisioning, mapped to Joiner-Mover-Leaver.
- Must know: Define the access a role needs before granting it, and provision only that access: least privilege starts at provisioning.
- Understand logical access controls
The Principle of Least Privilege (PoLP), Separation of Duties (SoD), and access control models (e.g., DAC, MAC, RBAC).- π Lesson: Logical Access Controls: Least Privilege, DAC, MAC, and RBAC
- Must know: Least privilege: grant the minimum access the job requires; need-to-know further restricts specific information.
- Must know: Separation of Duties splits a sensitive process so no one person can commit and conceal fraud; collusion becomes required.
Weight: 22%. Network security, network security architecture, and cloud security. Official weighting 21.3%.
π Revision notes: Domain 4: Networking and Cloud Security Concepts
- Understand network security
Networking concepts (OSI and TCP/IP models, IPv4/IPv6, VPN); firewalls (ports, applications); wireless (Wi-Fi, Bluetooth); and embedded systems (Industrial Control Systems) and the Internet of Things (IoT).- π Lesson: Network Security Basics: OSI Model, TCP/IP, Firewalls, and VPNs
- Must know: The OSI model has seven layers; the TCP/IP model has four, with the TCP/IP Application layer covering OSI layers 5 to 7.
- Must know: IP addresses and routing are Layer 3; MAC addresses and switches are Layer 2; TCP and UDP with port numbers are Layer 4.
- Understand network security architecture
Network segmentation (firewall zones, VLANs, micro-segmentation); Defense in Depth; and Zero Trust (ZT).- π Lesson: Network Security Architecture: Zero Trust, Defense in Depth, Segmentation
- Must know: Segmentation limits lateral movement: an attacker's foothold in one zone cannot freely reach systems in another.
- Must know: The DMZ is a buffer zone between the untrusted internet and the trusted internal network, and it is where public-facing servers belong.
- Understand cloud security
Cloud characteristics (broad network access, rapid elasticity, measured service, on-demand self-service, resource pooling); service models; deployment models; and the shared security (responsibility) model.- π Lesson: Cloud Security: Shared Responsibility, IaaS vs PaaS vs SaaS, Deployment Models
- Must know: The five essential cloud characteristics: on-demand self-service, broad network access, resource pooling, rapid elasticity, measured service.
- Must know: IaaS rents infrastructure (you manage the OS up), PaaS rents a managed platform (you bring code and data), SaaS rents a finished application (you bring data and users).
Weight: 17%. Data security, security operations, incident response, asset protection, and security testing. Official weighting 17.3%.
π Revision notes: Domain 5: Security Operations and Incident Response
- Understand data security
Data handling (classification, labeling, masking, sanitization); and encryption (symmetric, asymmetric, hashing, quantum-resistant cryptography).- π Lesson: Data Security: Classification, Masking, Sanitization, and Encryption Basics
- Must know: Classification labels data by sensitivity (for example public, internal, confidential, restricted), and the label determines how strongly the data is protected.
- Must know: Masking obscures displayed values (showing only the last four digits); the underlying data still exists and there is no key to reverse it.
- Understand security operations
Logging and monitoring of security events; security event triage (incident use cases, prioritization, correlation); threat actors (types, motivations); cyber threat intelligence; and threat frameworks.- π Lesson: Security Operations: Logging, Monitoring, SIEM and Threat Intelligence
- Must know: Logs are the record of system events; monitoring means reviewing them continuously, not just after a breach.
- Must know: A SIEM aggregates, normalizes, and correlates logs from across the environment and raises alerts; the SOC operates it.
- Understand Incident Response (IR)
Implementing an Incident Response Plan (IRP) with data-handling policy; and Incident Response exercises (testing, tabletop).- π Lesson: Incident Response: The IR Plan, Phases, CSIRT and Tabletop Exercises
- Must know: An event is any observable occurrence; an incident is an event that harms or threatens confidentiality, integrity, or availability.
- Must know: The IRP is written and approved before an incident and defines roles, criteria, escalation paths, and procedures.
- Understand asset protection
Asset lifecycle management (End Of Life software and devices); and configuration and change management.- π Lesson: Asset Lifecycle, Configuration Management, and Change Management
- Must know: You cannot protect what you do not know you have: the asset inventory is the foundation of asset protection.
- Must know: The asset lifecycle runs acquisition, deployment, use, maintenance, and secure disposal, with security duties at every stage.
- Understand security testing
Security readiness testing (blue, purple, and red teaming); application testing (vulnerability scanning, static and dynamic analysis, threat modeling); and physical penetration testing (phishing, tailgating, impersonation).- π Lesson: Security Testing: Red, Blue, and Purple Teams, Scanning, SAST, and DAST
- Must know: Red team attacks, blue team defends, purple team is red and blue collaborating to improve both.
- Must know: Vulnerability scanning is automated, broad, and identifies known weaknesses; it does not exploit them.
- Read the lesson for each topic in the checklist above, starting with the heaviest domain. Every lesson is free on the CC revision notes.
- Practice straight after reading. Answer CC practice questions on the topic you just read. Each option comes with an explanation of why it is right or wrong.
- Review what you got wrong, re-read that lesson section, and tick the topic off only when you get its questions right.
- Take a full-length CC mock exam under the real time limit. Aim to pass mocks comfortably before you book.
- On the last day, skim the CC cheat sheet instead of starting anything new.
sample-questions.md has 20 worked CC questions with the answer, why each option is right or wrong, and the reasoning steps.
- ISC2 Certified in Cybersecurity exam outline: the official source (ISC2)
- CC certification overview
- CC revision notes: every lesson, free to read
- CC practice questions: with an explanation on every option
- CC mock exams: full-length and timed
- CC cheat sheet: the key facts on one page
- All certification study guides
Spotted an error or an out-of-date fact? Open an issue with the topic and a link to the official source. See CONTRIBUTING.md.
This guide is licensed under CC BY 4.0. You can reuse and adapt it, including commercially, as long as you credit SaveMyCert with a link to https://www.savemycert.com/.
This is an independent study resource. It is not affiliated with or endorsed by ISC2. ISC2 Certified in Cybersecurity (CC) and CC are trademarks of their respective owner. Exam domains and weights are taken from the official exam guide linked above.