CertGrid
Security Study Guide

(ISC)² Certified in Cybersecurity (CC) Study Guide

The (ISC)² Certified in Cybersecurity (CC) is an entry-level credential that validates foundational knowledge across security principles, business continuity and incident response, access control, network security, and security operations. It is aimed at newcomers, career changers, and IT professionals seeking to enter the cybersecurity field with no prior work experience required. The exam is 100-125 questions (multiple choice and advanced item types) over 120 minutes, scored on a 1000-point scale with 700 to pass.

Objective-mapped study guide, aligned to current exam objectives · Reviewed Aug 2026 · Independent practice platform.

Real exam: 100-125 qs · 120 min · Multiple choice and advanced item types.

Domain 1: Security Principles

Key concepts you must know · 241 practice questions

Domain 2: Business Continuity, DR, and Incident Response

Key concepts you must know · 121 practice questions

Domain 3: Access Control Concepts

Key concepts you must know · 205 practice questions

Domain 4: Network Security

Key concepts you must know · 224 practice questions

Domain 5: Security Operations

Key concepts you must know · 194 practice questions

(ISC)² Certified in Cybersecurity (CC) exam tips

Study guide FAQ

How many questions are on the CC exam and what score do I need to pass?

The exam has 100-125 questions (multiple choice and advanced item types) to be completed in 120 minutes. It is scored on a scale of 1 to 1000, and you need a 700 to pass.

Do I need work experience to earn the CC certification?

No. CC is designed as an entry-level credential and requires no prior work experience, making it ideal for students, career changers, and newcomers to cybersecurity. After passing, you complete the (ISC)² endorsement process and agree to the Code of Ethics.

Which domain carries the most weight on the exam?

Security Principles (Domain 1) is the largest at 26%, followed by Network Security (24%), Access Control Concepts (22%), and Security Operations (18%). Business Continuity, DR, and Incident Response (Domain 2) is the smallest at 10%. Study all five, but expect the most questions from Security Principles and Network Security.

Is the CC exam heavily technical or command-line focused?

No. CC tests foundational concepts, terminology, and security principles rather than hands-on configuration. You do not need to memorize commands; focus on understanding what controls and concepts do, when to use them, and how they relate to confidentiality, integrity, and availability.

Related Security resources

What CertGrid is (and is not)

CertGrid is an independent IT certification practice platform for Azure, AWS, Google, Cisco, Security, Linux, Kubernetes, Terraform, and other certification tracks. It provides objective-mapped practice questions, readiness scoring, weak-domain drills, and explanations to help learners understand what to study next.

Independent & original. CertGrid is an independent practice platform and is not affiliated with or endorsed by Security. Questions are original practice items designed to mirror certification concepts and exam style. CertGrid does not provide official exam questions or braindumps.