[Jul-2026] CC Exam Dumps Pass with Updated 2026 Certified in Cybersecurity (CC) [Q161-Q180]

Share

[Jul-2026] CC Exam Dumps Pass with Updated 2026 Certified in Cybersecurity (CC)

Free CC Exam Dumps to Pass Exam Easily

NEW QUESTION # 161
Sophia is visiting Las Vegas and decides to put a bet on a particular number on a roulette wheel. This is an example of _________.

  • A. Mitigation
  • B. Acceptance
  • C. Transference
  • D. Avoidance

Answer: B


NEW QUESTION # 162
Which of the following is endpint

  • A. Router
  • B. Firewall
  • C. Switch
  • D. Laptop

Answer: D


NEW QUESTION # 163
A DLP solution should be deployed so it can inspect all forms of data leaving the organization, including:

  • A. All
  • B. Posting to websites
  • C. Applications and APIs
  • D. Copying to portable media

Answer: A

Explanation:
Effective DLP solutions monitor all egress channels to prevent unauthorized data exfiltration, including web uploads, APIs, and removable media.


NEW QUESTION # 164
A prolonged, targeted cyberattack where an intruder remains undetected for an extended period is called:

  • A. Spoofing
  • B. DoS
  • C. Advanced Persistent Threat
  • D. Phishing

Answer: C

Explanation:
An Advanced Persistent Threat (APT) involves stealthy, long-term access to systems for espionage, data theft, or sabotage.


NEW QUESTION # 165
Which of the following is not a Social engineering technique

  • A. Pretexting
  • B. Double Dealing
  • C. Quid pro quo
  • D. Baiting

Answer: B


NEW QUESTION # 166
Which common cloud service model offers the customer the most control of the cloud environment?

  • A. Platform as a service (PaaS)
  • B. Lunch as a service (LaaS)
  • C. Infrastructure as a service (IaaS)
  • D. Software as a service (SaaS)

Answer: C


NEW QUESTION # 167
What federal law requires the use of vulnerability scanning on information systems operated by federal government agencies?

  • A. FERPA
  • B. FISMA
  • C. HIPAA
  • D. GLBA

Answer: B

Explanation:
The Federal Information Security Modernization Act (FISMA) requires federal agencies to implement comprehensive information security programs, including continuous monitoring and vulnerability scanning.
FISMA mandates risk-based security controls aligned with NIST standards, such as NIST SP 800-53 and NIST SP 800-137.
HIPAA applies to healthcare data, GLBA applies to financial institutions, and FERPA protects student education records. None of these broadly mandate vulnerability scanning across federal systems.
FISMA is foundational to federal cybersecurity governance and compliance.


NEW QUESTION # 168
What is sensitivity in the context of confidentiality

  • A. The Health status of the individuals
  • B. The harm caused to externl stakeholders if information is disclosed or modified
  • C. The need for protection assigned to information by its owner
  • D. The ability of information to be accessed only by authorized individuals

Answer: C


NEW QUESTION # 169
Which of the following activities is usually part of the configuration management process, but is also extremely helpful in countering potential attacks?

  • A. Conferences with senior leadership
  • B. The annual shareholders' systems
  • C. Updating and patching systems
  • D. Annual budgeting

Answer: C


NEW QUESTION # 170
An external entity has tried to gain access to your organization's IT environment without authorization. This is an example of a(n):

  • A. Malware
  • B. Intrusion
  • C. Exploit
  • D. Event

Answer: B

Explanation:
Anintrusionis an unauthorized attempt to access systems or networks. It may or may not succeed. Intrusions are more serious than simple events but may not rise to the level of a breach if controls prevent access.


NEW QUESTION # 171
What is the primary factor in the reliability of information and systems?

  • A. Availability
  • B. Integrity
  • C. Authenticity
  • D. Confidentiality

Answer: B

Explanation:
Integrityis the primary factor in system and information reliability. Reliable systems must ensure that data is accurate, complete, and protected from unauthorized modification. If integrity is compromised, decisions based on the data become unreliable-even if systems are available or confidential. NIST and ISO frameworks emphasize integrity as essential to trustworthiness and operational reliability.


NEW QUESTION # 172
What is the main purpose of creating a baseline for system integrity?

  • A. To protect information
  • B. To compare baseline with current system state
  • C. All
  • D. To understand current state

Answer: B

Explanation:
Baselines allow organizations to detect unauthorized changes by comparing known-good configurations against current states.


NEW QUESTION # 173
Ensuring a process cannot be completed by a single person is known as:

  • A. Privileged account
  • B. Least privilege
  • C. Rule-based access control
  • D. Segregation of duties

Answer: D

Explanation:
Segregation of duties reduces fraud and insider threats by requiring multiple individuals to complete critical tasks.


NEW QUESTION # 174
A set of security controls or system settings used to ensure uniformity of configuration through the IT environment?

  • A. Baseline
  • B. Inventory
  • C. Policy
  • D. Patches

Answer: A


NEW QUESTION # 175
During an ISC2 CC exam, you observe another candidate cheating. What should you do?

  • A. Yell at them
  • B. Report the candidate to ISC2
  • C. Call law enforcement
  • D. Do nothing

Answer: B

Explanation:
ISC2's Code of Ethics requires candidates to report violations through proper channels to preserve exam integrity.


NEW QUESTION # 176
Which access control model is best suited for a large organization with many departments and varied access needs?

  • A. DAC
  • B. RuBAC
  • C. MAC
  • D. RBAC

Answer: D

Explanation:
Role-Based Access Control (RBAC) assigns permissions based on job roles, making it scalable and efficient for large organizations. It simplifies access management and supports least privilege.


NEW QUESTION # 177
Which is related to privacy?

  • A. MOU
  • B. All
  • C. FIPS
  • D. GDPR

Answer: B

Explanation:
GDPR directly addresses privacy, while FIPS and MOUs can also relate to privacy controls and data handling requirements.


NEW QUESTION # 178
Which threat is directly associated with malware?

  • A. DDoS
  • B. Trojan
  • C. Ransomware
  • D. APT

Answer: B

Explanation:
ATrojanis a direct form of malware that disguises itself as legitimate software to perform malicious actions.


NEW QUESTION # 179
In risk management concepts, a(n) _________ is something a security practitioner might need to protect.

  • A. Vulnerability
  • B. Asset
  • C. Likelihood
  • D. Threat

Answer: B


NEW QUESTION # 180
......


ISC CC Exam Syllabus Topics:

TopicDetails
Topic 1
  • Security Principles: This section of the exam measures skills of Security Analysts and Information Assurance Specialists and covers fundamental security concepts such as confidentiality, integrity, availability, authentication methods including multi-factor authentication, non-repudiation, and privacy. It also includes understanding the risk management process with emphasis on identifying, assessing, and treating risks based on priorities and tolerance. Candidates are expected to know various security controls, including technical, administrative, and physical, as well as the ISC2 professional code of ethics. Governance processes such as policies, procedures, standards, regulations, and laws are also covered to ensure adherence to organizational and legal requirements.
Topic 2
  • Security Operations: This area targets Security Operations Center (SOC) Analysts and System Administrators. It covers data security with encryption methods, secure handling of data including classification and retention, and the importance of logging and monitoring security events. System hardening through configuration management, baselines, updates, and patching is included. Best practice security policies such as data handling, password, acceptable use, BYOD, change management, and privacy policies are emphasized. Finally, the domain highlights security awareness training addressing social engineering awareness and password protection to foster a security-conscious organizational culture.
Topic 3
  • Access Controls Concepts: This section measures skills of Access Control Specialists and Physical Security Managers in understanding physical and logical access controls. Topics include physical security measures like badge systems, CCTV, monitoring, and managing authorized versus unauthorized personnel. Logical access control concepts such as the principle of least privilege, segregation of duties, discretionary access control, mandatory access control, and role-based access control are essential for controlling information system access.
Topic 4
  • Network Security: This domain assesses the knowledge of Network Security Engineers and Cybersecurity Specialists. It covers foundational computer networking concepts including OSI and TCP
  • IP models, IP addressing, and network ports. Candidates study network threats such as DDoS attacks, malware variants, and man-in-the-middle attacks, along with detection tools like IDS, HIDS, and NIDS. Prevention strategies including firewalls and antivirus software are included. The domain also addresses network security infrastructure encompassing on-premises data centers, design techniques like segmentation and defense in depth, and cloud security models such as SaaS, IaaS, and hybrid deployments.
Topic 5
  • Business Continuity (BC), Disaster Recovery (DR) & Incident Response Concepts: This domain targets Business Continuity Planners and Incident Response Coordinators. It focuses on the purpose, importance, and core components of business continuity, disaster recovery, and incident response. Candidates learn how to prepare for and manage disruptions while maintaining or quickly restoring critical business operations and IT services.

 

CC Exam Dumps, CC Practice Test Questions: https://www.vceengine.com/CC-vce-test-engine.html

Free CC Study Guides Exam Questions and Answer: https://drive.google.com/open?id=1XuNLUOghENIklsMcEPujt7K4qAkZBmh3