Pass Your ISC Exam with CC Exam Dumps (Updated 406 Questions) [Q23-Q39]

Share

Pass Your ISC Exam with CC Exam Dumps (Updated 406 Questions)

CC Exam Dumps - ISC Practice Test Questions


ISC CC Exam Syllabus Topics:

TopicDetails
Topic 1
  • Access Controls Concepts: This section measures skills of Access Control Specialists and Physical Security Managers in understanding physical and logical access controls. Topics include physical security measures like badge systems, CCTV, monitoring, and managing authorized versus unauthorized personnel. Logical access control concepts such as the principle of least privilege, segregation of duties, discretionary access control, mandatory access control, and role-based access control are essential for controlling information system access.
Topic 2
  • Business Continuity (BC), Disaster Recovery (DR) & Incident Response Concepts: This domain targets Business Continuity Planners and Incident Response Coordinators. It focuses on the purpose, importance, and core components of business continuity, disaster recovery, and incident response. Candidates learn how to prepare for and manage disruptions while maintaining or quickly restoring critical business operations and IT services.
Topic 3
  • Security Principles: This section of the exam measures skills of Security Analysts and Information Assurance Specialists and covers fundamental security concepts such as confidentiality, integrity, availability, authentication methods including multi-factor authentication, non-repudiation, and privacy. It also includes understanding the risk management process with emphasis on identifying, assessing, and treating risks based on priorities and tolerance. Candidates are expected to know various security controls, including technical, administrative, and physical, as well as the ISC2 professional code of ethics. Governance processes such as policies, procedures, standards, regulations, and laws are also covered to ensure adherence to organizational and legal requirements.
Topic 4
  • Network Security: This domain assesses the knowledge of Network Security Engineers and Cybersecurity Specialists. It covers foundational computer networking concepts including OSI and TCP
  • IP models, IP addressing, and network ports. Candidates study network threats such as DDoS attacks, malware variants, and man-in-the-middle attacks, along with detection tools like IDS, HIDS, and NIDS. Prevention strategies including firewalls and antivirus software are included. The domain also addresses network security infrastructure encompassing on-premises data centers, design techniques like segmentation and defense in depth, and cloud security models such as SaaS, IaaS, and hybrid deployments.
Topic 5
  • Security Operations: This area targets Security Operations Center (SOC) Analysts and System Administrators. It covers data security with encryption methods, secure handling of data including classification and retention, and the importance of logging and monitoring security events. System hardening through configuration management, baselines, updates, and patching is included. Best practice security policies such as data handling, password, acceptable use, BYOD, change management, and privacy policies are emphasized. Finally, the domain highlights security awareness training addressing social engineering awareness and password protection to foster a security-conscious organizational culture.

 

NEW QUESTION # 23
The output of any given hashing algorithm is always _____.

  • A. The same length
  • B. The same language
  • C. Different for the same inputs
  • D. The same characters

Answer: A


NEW QUESTION # 24
An attacker places themselves between two communicating devices is known as:

  • A. On-Path attack
  • B. Phishing
  • C. Spoofing
  • D. All

Answer: A

Explanation:
AnOn-Path (Man-in-the-Middle)attack allows attackers to intercept, modify, or replay communications between two parties without their knowledge.


NEW QUESTION # 25
By far, the most crucial element of any security instruction program.

  • A. Preserve shareholder value
  • B. Preserve health and human safety
  • C. Ensure availability of IT systems
  • D. Protect assets

Answer: B


NEW QUESTION # 26
Faking the sending address of a transmission to gain illegal entry into a secure system.

  • A. ALL
  • B. Spoofing
  • C. Phishing
  • D. ARP

Answer: B


NEW QUESTION # 27
The prevention of authorized access to resources or the delaying of time-critical operations. (Time-critical may be milliseconds or it may be hours, depending upon the service provided.)

  • A. Authetication
  • B. Availablity
  • C. DDOS
  • D. Authentication

Answer: C


NEW QUESTION # 28
What is the main purpose of using multi-factor authentication (MFA) in a security system?

  • A. To add an extra layer of security to user authentication
  • B. To ensure data integrity
  • C. To protect against malware
  • D. To prevent data breaches

Answer: A


NEW QUESTION # 29
Which of the following documents contains elements that are NOT mandatory

  • A. Policies
  • B. Guidelines
  • C. Regulations
  • D. Procedures

Answer: B


NEW QUESTION # 30
Which prevents threats?

  • A. SIEM
  • B. IDS
  • C. HIDS
  • D. Antivirus

Answer: D

Explanation:
Antivirus softwareis apreventive security controldesigned to stop known malware threats before they can execute or spread within a system. Antivirus solutions use signature-based detection, heuristic analysis, and increasingly behavior-based techniques to block malicious code such as viruses, worms, trojans, and ransomware.
In contrast,IDS (Intrusion Detection Systems)andHIDS (Host-based IDS)are primarilydetective controls.
They monitor systems and networks for suspicious activity but do not inherently block threats.SIEMplatforms aggregate and analyze logs for visibility and correlation; they support detection and response but do not directly prevent threats.
According to NIST SP 800-53, preventive controls are designed to stop incidents from occurring, while detective controls identify events after or during occurrence. Therefore, antivirus is the correct choice as it directly prevents threats.


NEW QUESTION # 31
The organization should keep a copy of every signed Acceptable Use Policy (AUP) on file, and issue a copy to _______.

  • A. The Public Relations office
  • B. The regulators overseeing that industry
  • C. Lawmakers
  • D. The user who signed it

Answer: D


NEW QUESTION # 32
Which document serves as specifications for implementing policy and dictates mandatory requirements?

  • A. Policy
  • B. Standard
  • C. Procedure
  • D. Guideline

Answer: B

Explanation:
Standards define mandatory technical or operational requirements that must be followed to comply with policy. Guidelines are optional, and procedures provide step-by-step instructions.


NEW QUESTION # 33
What is a threat in cybersecurity?

  • A. Something to protect
  • B. A person or thing that exploits vulnerabilities
  • C. A system weakness
  • D. A method of attack

Answer: B

Explanation:
Athreatis any actor or condition capable of exploiting a vulnerability to cause harm.


NEW QUESTION # 34
Which access control model can grant access to a given object based on complex rules

  • A. DAC
  • B. MAC
  • C. ABAC
  • D. RBAC

Answer: C


NEW QUESTION # 35
Which of the following is not an appropriate control to add to privileged accounts?

  • A. Increased logging
  • B. Increased auditing
  • C. Multifactor authentication
  • D. Security deposit

Answer: D


NEW QUESTION # 36
Malicious code that acts like a remotely controlled "robot" for an attacker.

  • A. Virus
  • B. Bot
  • C. Rootkit
  • D. Malware

Answer: B

Explanation:
Abotis malware that allows attackers to remotely control infected systems, often forming botnets used for DDoS attacks, spam, or credential theft.


NEW QUESTION # 37
The process of applying secure configurations (to reduce the attack surface)

  • A. Security Benchmark
  • B. Security Evaluation
  • C. Security Hardening
  • D. Security Assessment

Answer: C


NEW QUESTION # 38
After an attack we have suffered a loss of public confidence, which leg of the CIA was compromised?
Response:

  • A. Confidentiality
  • B. Integrity
  • C. Encryption
  • D. Availability

Answer: A


NEW QUESTION # 39
......

Pass Your CC Exam Easily with Accurate PDF Questions: https://passleader.passsureexam.com/CC-pass4sure-exam-dumps.html