Spring Sale Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: pass65

CC CC - Certified in Cybersecurity Questions and Answers

Questions 4

Exhibit.

IPSec works in which layer of OSI Model

Options:

A.

Layer 2

B.

Layer 5

C.

Layer 3

D.

Layer 7

Buy Now
Questions 5

What is a security token used to authenticate a user to a web application, typically after they log in?

Options:

A.

CAPTCHA

B.

API key

C.

CSRF token

D.

Session token

Buy Now
Questions 6

What is the purpose of the post-incident phase?

Options:

A.

Detection and analysis

B.

Preparation

C.

Lessons learned and improvement

D.

Containment and eradication

Buy Now
Questions 7

Which OSI layer is the primary target of a buffer overflow attack?

Options:

A.

Layer 7

B.

Layer 3

C.

Layer 5

D.

Layer 4

Buy Now
Questions 8

Example of Type 1 authentication:

Options:

A.

Password

B.

Smart card

C.

Fingerprint

D.

RSA token

Buy Now
Questions 9

Which organization defines Internet protocol standards?

Options:

A.

ISO

B.

NIST

C.

IETF

D.

GDPR

Buy Now
Questions 10

Which element of the security policy framework includes recommendations that are NOT binding?

Options:

A.

Procedures

B.

Guidelines

C.

Standards

D.

Policies

Buy Now
Questions 11

What is an IPSec replay attack?

Options:

A.

An attack where an attacker modifies packets in transit

B.

An attack where an attacker eavesdrops on network traffic

C.

An attack where an attacker overloads a network with traffic

D.

An attack where an attacker attempts to inject packets in an existing session

Buy Now
Questions 12

A CISO documents a policy establishing acceptable cloud use for all staff. This is an example of:

Options:

A.

Technical control

B.

Physical control

C.

Cloud control

D.

Management / Administrative control

Buy Now
Questions 13

Is defined as the process of identifying, estimating, and prioritizing risks.

Options:

A.

Risk Assessment

B.

Risk Treatment

C.

Risk Mitigation

D.

Risk Management

Buy Now
Questions 14

Which IR phase involves identifying critical data and systems?

Options:

A.

Detection and analysis

B.

Preparation

C.

Containment

D.

Eradication

Buy Now
Questions 15

A prolonged, targeted cyberattack where an intruder remains undetected for an extended period is called:

Options:

A.

Spoofing

B.

Phishing

C.

DoS

D.

Advanced Persistent Threat

Buy Now
Questions 16

What is the primary factor in the reliability of information and systems?

Options:

A.

Authenticity

B.

Confidentiality

C.

Integrity

D.

Availability

Buy Now
Questions 17

Information should be consistently and readily accessible for authorized parties.

Options:

A.

Confidentiality

B.

Authentication

C.

Availability

D.

Non-repudiation

Buy Now
Questions 18

Which type of attack takes advantage of vulnerabilities in validation?

Options:

A.

ARP spoofing

B.

Pharming attacks

C.

Cross-site scripting (XSS)

D.

DNS poisoning

Buy Now
Questions 19

Risk tolerance is also known as:

Options:

A.

Risk threshold

B.

Risk appetite

C.

Acceptable risk

D.

All

Buy Now
Questions 20

Duke would like to restrict users from accessing a list of prohibited websites while connected to his network. Which control would BEST achieve this objective?

Options:

A.

URL filter

B.

IP address block

C.

DLP solution

D.

IPS solution

Buy Now
Questions 21

Which control identifies that an attack has occurred or is occurring?

Options:

A.

Preventive control

B.

Detective control

C.

Corrective control

D.

Recovery control

Buy Now
Questions 22

The order of controls used in defense in depth:

Options:

A.

Assets → Physical → Administrative → Technical

B.

Assets → Administrative → Physical → Technical

C.

Physical → Administrative → Technical → Assets

D.

Assets → Administrative → Technical → Physical

Buy Now
Questions 23

Which is a component of a Business Continuity (BC) plan?

Options:

A.

Immediate response procedures

B.

Notification systems and call trees

C.

Management authority guidance

D.

All

Buy Now
Questions 24

Which is related to standards?

Options:

A.

NIST

B.

GDPR

C.

HIPAA

D.

All

Buy Now
Questions 25

Which of the following attacks can TLS help mitigate?

Options:

A.

Cross-site Scripting (XSS) attacks

B.

Social engineering attacks

C.

Man-in-the-middle (MITM) attacks

D.

SQL injection attacks

Buy Now
Questions 26

Which of the following properties is NOT guaranteed by digital signatures?

Options:

A.

Authentication

B.

Confidentiality

C.

Non-repudiation

D.

Integrity

Buy Now
Questions 27

Which addresses are reserved for internal network use and are not routable on the Internet?

Options:

A.

ac00:: to adff:ffff:ffff:ffff:ffff:ffff:ffff:ffff

B.

fc00:: to fdff:ffff:ffff:ffff:ffff:ffff:ffff:ffff

C.

bc00:: to bdff:ffff:ffff:ffff:ffff:ffff:ffff:ffff

D.

cc00:: to cdff:ffff:ffff:ffff:ffff:ffff:ffff:ffff

Buy Now
Questions 28

A collection of actions that must be followed to complete a task or process in accordance with a set of rules is known as:

Options:

A.

Policy

B.

Procedure

C.

Law

D.

Standard

Buy Now
Questions 29

Malware that disguises itself as legitimate software is called:

Options:

A.

Worm

B.

Trojan

C.

Virus

D.

Ransomware

Buy Now
Questions 30

Why is the recovery of IT often crucial to the recovery and sustainment of business operations?

Options:

A.

IT is not important to business operations

B.

IT is often the cause of disasters

C.

IT can be easily recovered without impact

D.

Many businesses rely heavily on IT for operations

Buy Now
Questions 31

Events with negative consequences such as crashes, floods, defacement, or malicious code execution are called:

Options:

A.

Breach

B.

Incident

C.

Adverse event

D.

Exploit

Buy Now
Questions 32

A security event in which an intruder gains or attempts unauthorized access to a system is called:

Options:

A.

Intrusion

B.

Exploit

C.

Threat

D.

Attack

Buy Now
Questions 33

Firewalls operate at which OSI layers?

Options:

A.

Layer 3

B.

Layer 4

C.

Layer 7

D.

All

Buy Now
Questions 34

How often should an organization test its BCP?

Options:

A.

Continually

B.

Annually

C.

Routinely

D.

Daily

Buy Now
Questions 35

Which is NOT a possible model for an Incident Response Team (IRT)?

Options:

A.

Leveraged

B.

Dedicated

C.

Hybrid

D.

Outsourced

Buy Now
Questions 36

A company wants employees to access resources from anywhere in the world. Which access control model is best?

Options:

A.

DAC

B.

RBAC

C.

MAC

D.

ABAC

Buy Now
Questions 37

You experienced a power outage that disrupted access to your data center. What type of security concern occurred?

Options:

A.

Availability

B.

Confidentiality

C.

Non-repudiation

D.

Integrity

Buy Now
Questions 38

An attack in which a user authenticated to a server unknowingly invokes unwanted actions after visiting a malicious website is known as:

Options:

A.

XSS

B.

CSRF

C.

Spoofing

D.

ALL

Buy Now
Questions 39

Who should participate in creating a BCP?

Options:

A.

IT only

B.

Management only

C.

Members across the organization

D.

Finance only

Buy Now
Questions 40

A portion of the network exposed to the outside world with additional controls is called:

Options:

A.

VPN

B.

VLAN

C.

Zero Trust

D.

DMZ

Buy Now
Questions 41

When is the Business Continuity Plan (BCP) enacted?

Options:

A.

When there is an event

B.

When there is an incident

C.

When there is a loss of business operations

D.

When there is a natural disaster

Buy Now
Questions 42

Exhibit.

CC Question 42

CC Question 42

What kind of vulnerability is typically not identifiable through a standard vulnerability assessment?

Options:

A.

File permissions

B.

Buffer overflow

C.

Zero-day vulnerability

D.

Cross-site scripting

Buy Now
Questions 43

VLAN hopping belongs to which OSI layer?

Options:

A.

Layer 3

B.

Layer 4

C.

Layer 7

D.

Layer 2

Buy Now
Questions 44

A centralized organizational function that monitors, detects, and analyzes security events to prevent disruptions is called:

Options:

A.

IRP

B.

BCP

C.

SOC

D.

DRP

Buy Now
Questions 45

How do IT professionals differentiate between IT problems and security incidents?

Options:

A.

Medical assistance

B.

Evidence collection only

C.

Specialized incident response training

D.

Lessons learned participation

Buy Now
Questions 46

Modern solutions that detect rootkits, ransomware, and spyware are:

Options:

A.

Antivirus

B.

IDS

C.

IPS

D.

Anti-malware

Buy Now
Questions 47

Which principle aims primarily at fraud detection?

Options:

A.

Defense in depth

B.

Least privilege

C.

Separation of duties

D.

Privileged account

Buy Now
Questions 48

What are registered ports primarily used for?

Options:

A.

Core TCP/IP protocols

B.

Web servers

C.

In-house applications

D.

Vendor and proprietary applications

Buy Now
Questions 49

Which regulation addresses personal privacy?

Options:

A.

HIPAA

B.

GDPR

C.

NIST

D.

ISO

Buy Now
Questions 50

Port forwarding is also known as:

Options:

A.

Port mapping

B.

Tunneling

C.

Punch-through

D.

All

Buy Now
Questions 51

Which type of encryption uses only one shared key to encrypt and decrypt?

Options:

A.

Public key

B.

Asymmetric

C.

Symmetric

D.

TCB key

Buy Now
Questions 52

A system architecture where one instance serves multiple user groups:

Options:

A.

Multithreading

B.

Multiprocessing

C.

Multitenancy

D.

Multi-cloud

Buy Now
Questions 53

According to ISC2 Code of Ethics, to whom does Kristal ultimately report?

Options:

A.

The company

B.

Governments

C.

ISC2

D.

The users

Buy Now
Questions 54

What is the primary goal of incident management?

Options:

A.

To protect life, health, and safety

B.

To reduce the impact of an incident

C.

To prepare for any incident

D.

To resume interrupted operations as soon as possible

Buy Now
Questions 55

What is the primary goal of an incident management team?

Options:

A.

Reduce impact and restore services

B.

Gathering and analyzing information

C.

Conducting lessons learned meetings

D.

Root cause analysis

Buy Now
Questions 56

An approach using software-based controllers and APIs to direct network traffic:

Options:

A.

VLAN

B.

SDN

C.

VPN

D.

SAN

Buy Now
Questions 57

Which protocol is used for secure email?

Options:

A.

POP3S

B.

IMAPS

C.

SMTPS

D.

All

Buy Now
Questions 58

Walmart has a large e-commerce presence worldwide. Which solution would ensure the LOWEST possible latency for customers using their services?

Options:

A.

CDN

B.

SaaS

C.

Load balancing

D.

Decentralized data centers

Buy Now
Questions 59

Scans networks to determine connected devices and services:

Options:

A.

Burp Suite

B.

Wireshark

C.

Fiddler

D.

Zenmap

Buy Now
Questions 60

A company’s governing board decides that only legal services may review third-party contracts. They create a document stating that no other department has permission to do so. This document is a:

Options:

A.

Procedure

B.

Policy

C.

Standard

D.

Law

Buy Now
Questions 61

What is the term used to denote the inherent set of privileges assigned to a user upon the creation of a new account?

Options:

A.

Aggregation

B.

Transitivity

C.

Baseline

D.

Entitlement

Buy Now
Questions 62

Faking the sender address to gain unauthorized access is known as:

Options:

A.

Phishing

B.

ARP

C.

Spoofing

D.

All

Buy Now
Questions 63

Which of the following is a subject?

Options:

A.

File

B.

Fence

C.

Filename

D.

User

Buy Now
Questions 64

What is the main challenge in achieving non-repudiation in electronic transactions?

Options:

A.

Verifying sender and recipient identity

B.

Ensuring message authenticity and integrity

C.

Preventing message tampering

D.

All of the above

Buy Now
Questions 65

What is the purpose of the CIA triad?

Options:

A.

Make security understandable

B.

Describe security concepts

C.

Define the purpose of security

D.

All

Buy Now
Questions 66

Raj wants aphysical deterrent controlto discourage unauthorized entry. Which option best serves this purpose?

Options:

A.

A wall

B.

Razor tape

C.

A sign

D.

A hidden camera

Buy Now
Questions 67

Critical business functions are disrupted due to a system outage. Which plan sustains operations?

Options:

A.

DRP

B.

BCP

C.

IRP

D.

All

Buy Now
Questions 68

Communication between end systems is encrypted using a key, often known as ________?

Options:

A.

Temporary key

B.

Section key

C.

Public key

D.

Session key

Buy Now
Questions 69

Restoring IT and communications after a disruption is the goal of:

Options:

A.

BCP

B.

IRP

C.

DRP

D.

None

Buy Now
Questions 70

A company wants to prevent employees from bringing unauthorized electronic devices into the workspace. Which physical control is best?

Options:

A.

Metal detectors

B.

Security guards

C.

RFID scanners

D.

Baggage X-ray machines

Buy Now
Questions 71

How do you distinguish authentication and identification?

Options:

A.

Both are the same

B.

Authentication verifies identity

C.

Authentication verifies identity; identification claims identity

D.

Identification verifies identity

Buy Now
Questions 72

Which of the following best describes a zero-day vulnerability?

Options:

A.

A vulnerability that has been identified and patched

B.

A vulnerability that has not yet been discovered or publicly disclosed

C.

A vulnerability exploitable only by experts

D.

A vulnerability that affects only legacy systems

Buy Now
Questions 73

Hashing safeguards which CIA triad principle?

Options:

A.

Confidentiality

B.

Availability

C.

Integrity

D.

All

Buy Now
Questions 74

The concept of integrity applies to:

Options:

A.

Organization

B.

Information systems and business processes

C.

People

D.

All

Buy Now
Questions 75

A hacker gains unauthorized access and steals confidential data. What term best describes this?

Options:

A.

Event

B.

Breach

C.

Intrusion

D.

Exploit

Buy Now
Questions 76

Which provides integrity services that allow a recipient to verify that a message has not been altered?

Options:

A.

Hashing

B.

Encryption

C.

Decryption

D.

Encoding

Buy Now
Questions 77

A company analyzes system requirements, functions, and interdependencies to prioritize contingency needs. What is this process called?

Options:

A.

BCP

B.

DRP

C.

IRP

D.

BIA

Buy Now
Questions 78

Which penetration testing technique requires the team to do the MOST work and effort?

Options:

A.

White box

B.

Blue box

C.

Gray box

D.

Black box

Buy Now
Questions 79

A newly enforced BYOD policy represents which control type?

Options:

A.

Physical control

B.

Logical control

C.

Administrative control

D.

Technical control

Buy Now
Questions 80

Which is NOT a function of an Intrusion Prevention System (IPS)?

Options:

A.

Encrypt network traffic

B.

Monitor network traffic

C.

Filter network traffic

D.

Detect and prevent attacks

Buy Now
Questions 81

What is the purpose of defense in depth?

Options:

A.

Implement only technical controls

B.

Provide unrestricted access

C.

Establish multiple layered security controls

D.

Guarantee no cyberattacks

Buy Now
Questions 82

Which ensures maintaining business operations during or after an incident?

Options:

A.

Incident Response

B.

Business Continuity

C.

Disaster Recovery

D.

All

Buy Now
Questions 83

Governments can impose financial penalties as a consequence of breaking a:

Options:

A.

Standard

B.

Regulation

C.

Policy

D.

Procedure

Buy Now
Questions 84

Which type of network is set up similar to the internet but is private to an organization? Select the MOST appropriate answer.

Options:

A.

Extranet

B.

VLAN

C.

Intranet

D.

VPN

Buy Now
Questions 85

Which threat is directly associated with malware?

Options:

A.

APT

B.

Ransomware

C.

Trojan

D.

DDoS

Buy Now
Questions 86

Example of a technical control:

Options:

A.

Security guard

B.

GPS installed in a vehicle to track location

C.

Door lock

D.

None

Buy Now
Questions 87

To avoid bodily injury claims, a company decides not to offer high-risk services. This is an example of:

Options:

A.

Risk Acceptance

B.

Risk Assessment

C.

Risk Avoidance

D.

Risk Control

Buy Now
Questions 88

A DLP solution should be deployed so it can inspect all forms of data leaving the organization, including:

Options:

A.

Posting to websites

B.

Applications and APIs

C.

Copying to portable media

D.

All

Buy Now
Questions 89

A standard that defines wired communication for network devices:

Options:

A.

Switch

B.

Hub

C.

Router

D.

Ethernet

Buy Now
Questions 90

Which OSI layer does a VPN primarily operate at?

Options:

A.

Layer 5

B.

Layer 6

C.

Layer 1

D.

Layer 3

Buy Now
Questions 91

The primary goal of a risk assessment is to:

Options:

A.

Avoid risk

B.

Estimate and prioritize risk

C.

Ignore risk

D.

Evaluate only the impact

Buy Now
Questions 92

Which security control is most commonly used to prevent data breaches?

Options:

A.

Physical control

B.

Logical control

C.

Administrative control

D.

RBAC

Buy Now
Questions 93

A way to prevent unwanted devices from connecting to a network is:

Options:

A.

DMZ

B.

VPN

C.

VLAN

D.

NAC

Buy Now
Questions 94

Which of these components is very likely to be instrumental to any disaster recovery (DR) effort?

Options:

A.

Routers

B.

Laptops

C.

Firewalls

D.

Backups

Buy Now
Questions 95

The process of how an organization is managed and how decisions are made is called:

Options:

A.

Standard

B.

Policy

C.

Procedure

D.

Governance

Buy Now
Questions 96

Which allows extremely granular restrictions down to individual machines or users?

Options:

A.

DMZ

B.

Microsegmentation

C.

VLAN

D.

NAC

Buy Now
Questions 97

An employee launched a privilege escalation attack to gain root access on one of the organization’s database servers. The employee has an authorized user account on the server. What log file would MOST likely contain relevant information?

Options:

A.

Database application log

B.

Firewall log

C.

Operating system log

D.

IDS log

Buy Now
Questions 98

Which fire suppression system is more friendly to electronics?

Options:

A.

Carbon dioxide–based

B.

Chemical-based

C.

Water-based

D.

Foam-based

Buy Now
Questions 99

An event that jeopardizes confidentiality, integrity, or availability is called:

Options:

A.

Breach

B.

Event

C.

Incident

D.

Exploit

Buy Now
Questions 100

A ________ creates an encrypted tunnel to protect your personal data and communications.

Options:

A.

HTTPS

B.

VPN

C.

Anti-virus

D.

IDS

Buy Now
Questions 101

Uses multiple types of access controls in layered fashion to avoid monolithic security:

Options:

A.

DMZ

B.

VLAN

C.

Defense in Depth

D.

VPN

Buy Now
Questions 102

What is the primary goal of network segmentation in cybersecurity?

Options:

A.

To increase network speed

B.

To isolate and protect critical assets

C.

To centralize data storage

D.

To expand network coverage

Buy Now
Questions 103

A power outage disrupts operations. Which plan helps sustain operations?

Options:

A.

DRP

B.

IRP

C.

BCP

D.

All

Buy Now
Questions 104

A previously unknown vulnerability with no public listing is called:

Options:

A.

Malware

B.

Zero-day

C.

Event

D.

Attack

Buy Now
Questions 105

A scam where a malicious website is made to look exactly like a trusted site is called:

Options:

A.

DoS

B.

Virus

C.

Spoofing

D.

Phishing

Buy Now
Questions 106

What does the termbusinessin business continuity planning refer to?

Options:

A.

The financial performance of the organization

B.

The technical systems of the organization

C.

The operational aspects of the organization

D.

The physical infrastructure of the organization

Buy Now
Questions 107

The method of distributing network traffic equally across a pool of resources is called:

Options:

A.

VLAN

B.

DNS

C.

VPN

D.

Load balancing

Buy Now
Questions 108

A DDoS attack affects which OSI layers?

Options:

A.

Network layer

B.

Transport layer

C.

Physical layer

D.

Both A and B

Buy Now
Questions 109

A system crash results in loss of data. What term best describes this?

Options:

A.

Breach

B.

Incident

C.

Event

D.

Adverse event

Buy Now
Questions 110

What is the BEST defense against dumpster diving attacks?

Options:

A.

Anti-malware software

B.

Clean desk policy

C.

Data loss prevention tools

D.

Shredding

Buy Now
Questions 111

What does a breach refer to in the context of cybersecurity?

Options:

A.

An unauthorized access to a system or system resource

B.

Any observable occurrence in a network or system

C.

A deliberate security incident

D.

A previously known system vulnerability

Buy Now
Questions 112

What is the primary purpose of a firewall?

Options:

A.

Encrypt data transmissions

B.

Prevent unauthorized access

C.

Monitor network traffic

D.

Backup critical data

Buy Now
Questions 113

Exhibit.

CC Question 113

What is the PRIMARY purpose of a web application firewall (WAF)?

Options:

A.

To protect the web server from DDoS attacks

B.

To monitor network traffic for intrusions

C.

To filter and block malicious web traffic and requests

D.

To manage SSL certificates

Buy Now
Questions 114

DNS operates at which OSI layer?

Options:

A.

Physical

B.

Network

C.

Application

D.

Data Link

Buy Now
Questions 115

Finance Server and Transaction Server have restored their original facility after a disaster. What should be moved in FIRST?

Options:

A.

Management

B.

Most critical systems

C.

Most critical functions

D.

Least critical functions

Buy Now
Questions 116

Which document identifies the principles and rules governing an organization’s protection of information systems and data?

Options:

A.

Procedure

B.

Guideline

C.

Policy

D.

Standard

Buy Now
Questions 117

What is the first step in incident response planning?

Options:

A.

Develop a management-approved policy

B.

Identify critical systems

C.

Train staff

D.

Form the IR team

Buy Now
Questions 118

Which of the following is often associated with Disaster Recovery planning?

Options:

A.

Checklists

B.

Antivirus

C.

Firewalls

D.

All

Buy Now
Questions 119

A one-way spinning door or barrier that allows only one person at a time to enter a building or area.

Options:

A.

Turnstile

B.

Mantrap

C.

Bollard

D.

Gate

Buy Now
Questions 120

Which is very likely to be used in a Disaster Recovery effort?

Options:

A.

Guard dogs

B.

Contract personnel

C.

Data backups

D.

Anti-malware solutions

Buy Now
Exam Code: CC
Exam Name: CC - Certified in Cybersecurity
Last Update: May 18, 2026
Questions: 403

PDF + Testing Engine

$64.99   $185.69

Testing Engine

$49.99   $142.83

PDF (Q&A)

$54.99   $157.11