““A focused practice set that strengthened my grasp of essential security concepts.””
Sophia Rossi
Cybersecurity Analyst
In 2022, ISC2 gave away the CC exam and training to one million people worldwide as part of a workforce initiative to address the cybersecurity staffing gap. That mass giveaway is part of why so many candidates underestimate this exam. Because it was free, marketed as beginner friendly, and requires no prior experience, people walk in expecting a soft knowledge check. What they actually get is an exam that grades against ISC2's own precise vocabulary, the same definitional style used on CISSP, just applied to foundational rather than advanced material.
The CC exam outline is built around five domains, and ISC2 publishes an official weighting for each:
Security Principles (26%): CIA triad, authentication versus authorization, governance concepts, risk management terminology, and the different categories of security controls (administrative, technical, and physical).
Business Continuity (BC), Disaster Recovery (DR) & Incident Response (IR) Concepts (10%): The distinctions between BC, DR, and IR planning, plus specific metrics like Recovery Time Objective, Recovery Point Objective, and Maximum Tolerable Downtime.
Access Controls Concepts (22%): Physical and logical access control models, authentication factors, and the difference between identification, authentication, and authorization.
Network Security (24%): OSI and TCP/IP model layers, common network attacks, network devices, and secure network architecture concepts.
Security Operations (18%): Data handling, logging and monitoring basics, encryption fundamentals, and security awareness concepts.
Security Principles carries the heaviest weighting, and it isn't just an introductory domain you can skim. A lot of terminology introduced there resurfaces in how questions are worded across the other four domains.
This exam pulls in people with genuinely no security background more than almost any other credential in the field. That includes college students trying to land their first help desk or SOC analyst role, career changers coming from teaching, retail management, or the military who are using CC as their entry point into IT security specifically, and existing IT staff, like sysadmins or network technicians, who want a credential proving security knowledge without committing to the years of documented experience CISSP requires. It's also common as a stepping stone credential for people planning to eventually pursue CISSP or CCSP once they've built the required work history.
The official ISC2 (CC) exam consists of 100 multiple choice questions delivered over a two hour window, and it's scored on a scale where 700 out of 1000 is the passing mark. There are no simulations or performance based items like some vendor exams use, every question is straightforward multiple choice, which sounds easier but means the exam leans heavily on precise reading. ISC2 questions are often written with two answers that both sound plausible, where the correct one hinges on a specific definitional distinction, like the difference between a threat and a vulnerability, or between a preventive and a detective control.
Candidates can sit the exam at a Pearson VUE testing center or through OnVUE online proctoring, which matters for practice purposes since the online proctored format has its own environment checks and rules worth getting familiar with before exam day rather than discovering them at check in.
Treat every wrong answer as a vocabulary problem first, not a knowledge gap. If you miss a question about access control types, don't just note the right answer, go back to ISC2's exact phrasing for that concept, because the exam consistently rewards candidates who've internalized ISC2's specific word choices over candidates who understand the concept in a general sense from a different source. Group your practice by domain and track accuracy separately for each one, since the small 10% BC/DR/IR domain is easy to write off as low priority but is dense with acronyms that are simple to mix up under exam pressure, RTO and RPO in particular.
If you're coming from an IT background rather than a security one, spend extra practice time on Network Security even if OSI layers feel familiar, because CC questions test them in a security context, asking which layer a specific attack targets or which layer a given control protects, not just asking you to recite the model.
The most common mistake is treating "entry-level" as synonymous with "easy" and under-preparing as a result. Candidates with IT experience sometimes assume their practical knowledge will carry them through, then get caught by questions that test ISC2's specific governance and risk terminology rather than hands on security skills.
A second frequent mistake is confusing the three BC/DR/IR metrics, RTO, RPO, and MTD, because they sound similar and are frequently tested together in the same question stem asking you to identify which term applies to a given scenario.
Third, candidates often blur the line between authentication and authorization, or between identification and authentication, in the Access Controls domain. These distinctions get tested directly and repeatedly, and missing them tends to cost more points than people expect from what looks like a basic vocabulary issue.
Finally, some candidates skip serious review of the Security Operations domain because it feels like a grab bag of miscellaneous topics compared to the other four. It's only 18% of the exam, but the range of concepts inside it, from data handling to logging to encryption basics, means shallow review there shows up as scattered point loss rather than one obvious weak spot.
Work directly from ISC2's official exam outline document rather than a repackaged study guide, and build your flashcards around the exact phrasing ISC2 uses for each concept, since that phrasing shows up again in question stems. Give Security Principles disproportionate study time relative to its already-large 26% weighting, since its vocabulary is the foundation the other four domains build on. Don't leave the BC/DR/IR domain for a quick last-minute review just because it's the smallest section, its acronyms are exactly the kind of detail that's easy to know in theory and mix up under time pressure. And if you're a hands-on IT person, resist the urge to answer network security questions from technical instinct alone, read for which specific security concept or control the question is actually asking about.
Run through the domain-by-domain practice sets below and pay close attention to whether you're missing questions on concepts you basically understand but phrased the ISC2 way. That gap, understanding the idea but not the specific term ISC2 uses for it, is the single most fixable and most common reason candidates lose points on this exam.
Last updated on Sep, 7 2026