CC Sample Questions

CC Sample Questions & Answers

Security principles lead the outline, followed by network security, physical and logical access control, everyday operations like system hardening and security policy, and the basics of incident response, disaster recovery and continuity planning.

Launch the full CC simulator →

Showing 10 of 20 free samples.

  1. Question 1Advanced

    Security Principles · Information Assurance Concepts

    A healthcare provider sends a digitally signed email to a patient containing medical records. The patient uses the provider's public key to verify the signature. This process primarily ensures which security concept?

    Show answer & explanation

    Correct answer: D

    Digital signatures provide non-repudiation, ensuring that the sender cannot deny having sent the message and that the integrity of the message has not been compromised. While it proves integrity, the specific concept of proving origin to a third party is non-repudiation.

  2. Question 2Advanced

    Security Principles · Risk Management Process

    True or False: In the context of risk management, 'Risk Appetite' refers to the specific amount of loss an organization can objectively endure without failing, whereas 'Risk Tolerance' is the broader strategic level of risk they are willing to take.

    Show answer & explanation

    Correct answer: B

    False. It is the reverse. 'Risk Appetite' is the broad, strategic level of risk an organization is willing to accept in pursuit of its goals. 'Risk Tolerance' is the specific variance from that appetite that is acceptable (e.g., specific metrics or limits).

  3. Question 3Beginner

    Security Principles · Information Assurance Concepts

    Which of the following scenarios best illustrates the 'Integrity' component of the CIA Triad?

    Show answer & explanation

    Correct answer: B

    Integrity ensures data is accurate and has not been tampered with. Hashing is a primary method to verify integrity. Encryption addresses confidentiality, and load balancing addresses availability.

  4. Question 4Intermediate

    Security Principles · Governance Processes

    A multinational corporation must comply with the General Data Protection Regulation (GDPR). They are appointing a specific role responsible for determining the purposes and means of processing personal data. What is this role called?

    Show answer & explanation

    Correct answer: D

    Under GDPR, the Data Controller determines the 'purposes and means' of processing personal data. The Data Processor processes data on behalf of the controller. The DPO is an oversight role.

  5. Question 5Advanced

    Security Principles · Risk Management Process

    An organization is conducting a quantitative risk assessment. They determine that a specific server fails once every 4 years. The replacement cost of the server is $10,000. What is the Annualized Loss Expectancy (ALE)?

    Show answer & explanation

    Correct answer: C

    ALE = Single Loss Expectancy (SLE) x Annualized Rate of Occurrence (ARO). SLE is $10,000. ARO is 1/4 (0.25). ALE = $10,000 x 0.25 = $2,500.

  6. Question 6Intermediate

    Access Controls Concepts · Logical Access Controls

    Case Study: TechSecure Inc.

    TechSecure Inc. is a mid-sized software development company moving its primary operations to a cloud environment. They handle sensitive customer PII. The CISO has mandated a review of all access controls. Currently, developers have full admin access to production servers to 'fix issues quickly', which violates security best practices. The company wants to implement a system where permissions are assigned based on job function rather than individual identity.

    Based on the scenario, which access control model should TechSecure Inc. implement to best address the CISO's requirement for function-based permissions?

    Show answer & explanation

    Correct answer: C

    Role-Based Access Control (RBAC) assigns permissions to specific roles (e.g., 'Developer', 'Admin') rather than directly to users. Users are then assigned to roles. This aligns perfectly with the requirement for 'job function' based permissions and is scalable for a mid-sized company.

  7. Question 7Intermediate

    Access Controls Concepts · Logical Access Controls

    Case Study: TechSecure Inc.

    Referring to the TechSecure scenario: The developers currently having full admin access to production violates which fundamental security principle?

    Show answer & explanation

    Correct answer: A

    The Principle of Least Privilege states that subjects should only be granted the minimum necessary access to perform their job functions. Giving developers full admin access to production when they only need to fix issues (which should be done in dev/test or via controlled processes) violates this principle.

  8. Question 8Intermediate

    Business Continuity, Disaster Recovery & Incident Response Concepts · Incident Response

    Which of the following activities is primarily associated with the 'Containment' phase of the Incident Response Lifecycle?

    Show answer & explanation

    Correct answer: C

    Containment involves limiting the scope and magnitude of an incident. Isolating a server prevents the spread of an attack. Restoring is Recovery; determining the root cause is Analysis; training is Preparation.

  9. Question 9Advanced

    Business Continuity, Disaster Recovery & Incident Response Concepts · Business Continuity Planning

    A business process requires a Recovery Point Objective (RPO) of 10 minutes. Which backup strategy is most appropriate to meet this requirement?

    Show answer & explanation

    Correct answer: B

    RPO of 10 minutes means the business can only lose 10 minutes of data. Tape or daily backups have an RPO of 24 hours. Only continuous replication/mirroring can achieve a near-zero or low-minute RPO.

  10. Question 10IntermediateSelect 2

    Business Continuity, Disaster Recovery & Incident Response Concepts · Disaster Recovery

    Select TWO characteristics that distinguish a 'Hot Site' from a 'Cold Site' in disaster recovery. (Select TWO)

    Show answer & explanation

    Correct answers: C, E

    Hot sites typically have current data loaded, allowing for immediate switchover. Cold sites have no data or hardware installed.

    A hot site is a mirror of the production environment with hardware and software ready to go.

Ready for the real thing?

The full CC simulator has every exam-style question, timed mode, and instant scoring.

Go to the CC simulator →