ISC2 CC Exam Actual Questions
Certified in Cybersecurity (Page 8 )

Updated On: 18-Jul-2026

What federal law requires the use of vulnerability scanning on information systems operated by federal government agencies?

  1. FISMA
  2. HIPAA
  3. GLBA
  4. FERPA

Answer(s): A



What is multi-factor authentication (MFA)?

  1. A type of authentication that uses only one method
  2. A type of authentication that uses only two methods
  3. A type of authentication that uses more than two methods (Correct)
  4. A type of authentication that uses only one factor

Answer(s): C



Duke would like to restrict users from accessing a list of prohibited websites while connected to his network.
Which one of the following controls would BEST achieve his objective?

  1. URL Filter
  2. IP Address Block
  3. DLP Solution
  4. IPS Solution

Answer(s): A



Natalia is concerned that users on her network may be storing sensitive information, such as social security numbers, on their hard drives without proper authorization or security controls.
What 3rd -party security service can she implement to best detect this activity?

  1. IDS - Intrusion Detection System
  2. IPS - Intrusion Prevention System
  3. DLP - Data Loss Protection
  4. TLS - Transport Layer Security

Answer(s): C



Duke would like to restrict users from accessing a list of prohibited websites while connected to his network.
Which one of the following controls would BEST achieve his objective?

  1. URL Filter
  2. IP Address Block
  3. DLP Solution
  4. IPS Solution

Answer(s): A



What is privacy in the context of Information Security?

  1. Protecting data from unauthorized access
  2. Ensuring data is accurate and unchanged
  3. Making sure data is always accessible when needed.
  4. Disclosed without their consent

Answer(s): A



Some Employee of his organization launched a privilege escalation attack to gain root access on one of the organization's database serversiThe employee does have an authorized user account on the server.
What log file would be MOST likely to contain relevant information??

  1. Database application log
  2. Firewall log
  3. Operating system log
  4. IDS log

Answer(s): C



Which of the following best describes a zero-day vulnerability?

  1. A vulnerability that has been identified and patched by software vendors
  2. A vulnerability that has not yet been discovered or publicly disclosed.
  3. A vulnerability that can only be exploited by experienced hackers.
  4. A vulnerability that affects only legacy systems.

Answer(s): B



Viewing page 8 of 52
Viewing questions 57 - 64 out of 407 questions


Post your Comments and Discuss ISC2 CC exam prep with other Community members:

AI Tutor AI Tutor 👋 I’m here to help!