ExamDumpster

Free CC sample questions

Real questions from the Certified in Cybersecurity practice bank, with the correct answer and an explanation for each one. No junk, no filler.

Try them in the simulator Same questions, with study, timed and flashcard modes.

Showing 10 of 20 free sample questions.

Question 1Choose one

A global financial institution is implementing a new security framework. The Chief Information Security Officer (CISO) emphasizes that while technical defenses are crucial, the organization must ensure that all employees understand their responsibilities and the consequences of non-compliance. Which governance document should be primarily established to provide this high-level authority and direction?

Question 2Choose one

During a risk assessment meeting, the security team identifies a legacy server that contains non-critical data. The cost to upgrade the server's security controls exceeds the value of the data it processes. The management team decides to continue operating the server without additional controls. Which risk treatment strategy has management adopted?

Question 3Choose one

A security consultant is explaining the concept of defense-in-depth to a client. The client recently installed a biometric scanner (Physical Control) and a firewall (Technical Control). To complete the triad of security control categories, which of the following should be implemented?

Question 4Choose one

An ISC2 member discovers that their employer is unknowingly releasing software that contains a critical safety flaw which could endanger human lives. The employer refuses to delay the release due to financial pressure. According to the ISC2 Code of Ethics, which canon must the member prioritize above all others?

Question 5Choose 2

A user logs into a banking application using a password and a one-time code sent to their mobile phone. Which two authentication factors are being utilized in this scenario? (Select TWO)

Question 6Choose one

A healthcare provider sends a digitally signed email to a patient containing medical records. The patient uses the provider's public key to verify the signature. This process primarily ensures which security concept?

Question 7Choose one

True or False: In the context of risk management, 'Risk Appetite' refers to the specific amount of loss an organization can objectively endure without failing, whereas 'Risk Tolerance' is the broader strategic level of risk they are willing to take.

Question 8Choose one

Which of the following scenarios best illustrates the 'Integrity' component of the CIA Triad?

Question 9Choose one

A multinational corporation must comply with the General Data Protection Regulation (GDPR). They are appointing a specific role responsible for determining the purposes and means of processing personal data. What is this role called?

Question 10Choose one

An organization is conducting a quantitative risk assessment. They determine that a specific server fails once every 4 years. The replacement cost of the server is $10,000. What is the Annualized Loss Expectancy (ALE)?

10 more free samples are waiting

Create a free account to unlock the whole CC sample bank, or get full access to all 220 practice questions in the simulator.

Create account