ISC2 Certified in Cybersecurity (CC) Study Guide: Current Exam Outline and Plan

Prepare for ISC2 CC with the September 2026 outline: security principles, governance, IAM, network and cloud security, operations, and incident response.

ISC2 Certified in Cybersecurity (CC) is an entry-level certification for people starting in cybersecurity. It has no work experience requirement. The exam checks your understanding of security fundamentals, governance and risk, identity and access controls, network and cloud security, security operations, and incident response.

This guide follows the exam outline effective September 1, 2026. ISC2 revised the domain names, scope, and weights, so use the current official exam outline rather than older CC study materials.

Who is this exam for?

It suits beginners preparing for cybersecurity roles, IT support staff, and learners who want a structured introduction to security terminology and daily practices. ISC2 does not require cybersecurity work experience. Basic computer and networking knowledge will help with technical scenarios.

Exam format and domain weights

The current exam uses Computerized Adaptive Testing (CAT), lasts two hours, and contains 100–125 items. Item types include multiple choice and advanced item types. The passing score is 700 out of 1,000. ISC2 currently lists English, Chinese, Japanese, German, and Spanish; Chinese appointments are available only during select windows, so confirm availability in the official exam information.

Domain Main topics Weight
1. Security Principles CIA, controls, risk, governance, and professional ethics 24%
2. Security Governance GRC, business continuity, disaster recovery, awareness, and metrics 17.3%
3. Identity and Access Management (IAM) Concepts Identity lifecycle, physical and logical access controls 20%
4. Networking and Cloud Security Concepts Networking, segmentation, defense in depth, Zero Trust, cloud responsibility 21.3%
5. Security Operations and Incident Response Data protection, monitoring, incident response, asset management, testing 17.3%

The older CC outline used different domain names and weights. This guide uses the new outline effective September 1, 2026.

How to study the five domains

1. Security Principles

Understand confidentiality, integrity, and availability (CIA), as well as authentication, authorization, accounting (AAA), privacy, and non-repudiation. Learn risk identification, assessment, and treatment; distinguish technical, administrative, and physical controls; and review the ISC2 Code of Ethics.

Common confusion: Authentication answers “Who are you?”, authorization answers “What can you do?”, and accounting records “What did you do?” Security controls should address risks; more controls are not automatically better.

2. Security Governance

Learn why organizations use governance, risk, and compliance (GRC), and how policies, processes, frameworks, and tools support risk management. Business continuity (BC) focuses on maintaining critical operations during disruption; disaster recovery (DR) focuses on restoring systems and data. Also understand awareness training, key risk indicators (KRIs), and effectiveness reporting.

3. Identity and Access Management

Review the identity lifecycle: define roles, provision accounts, review permissions regularly, and remove access when people or responsibilities change. Know least privilege, separation of duties, and access control models such as DAC, MAC, and RBAC. Physical controls include badges, visitor management, monitoring, and environmental security.

Common confusion: Having an account does not mean someone should have access. Grant permissions based on job responsibilities, resource sensitivity, and business need, then review whether access is still appropriate.

4. Networking and Cloud Security

Know OSI/TCP/IP fundamentals, IPv4/IPv6, ports, applications, Wi-Fi, and common network attacks. Understand the purpose of firewalls, IDS/IPS, segmentation, DMZs, VLANs, VPNs, defense in depth, and Zero Trust. For cloud, distinguish SaaS, PaaS, and IaaS and understand how responsibility changes with service and deployment models.

Common confusion: Cloud providers protect cloud infrastructure, while customers generally remain responsible for identity, data, configuration, and how services are used. The exact split depends on the service model; moving to cloud does not transfer all security responsibility.

5. Security Operations and Incident Response

Study data classification, labeling, retention, destruction, and encryption; logging and monitoring; event triage; threat actors; and threat intelligence. Incident response (IR) follows the organization’s plan and should be tested through exercises. Asset lifecycle, configuration and change management, vulnerability scanning, application testing, and red/blue/purple team exercises are also in scope.

The new outline integrates foundational AI-related security concepts across several domains, such as identifying AI assets, protecting data privacy, and recognizing automated threats. Focus on applying security principles to new technologies; CC is not a specialized AI certification.

  1. Learn the terminology and principles first. Explain CIA, AAA, risk, threats, vulnerabilities, and controls with simple examples.
  2. Study governance, BC/DR, and IAM. Use scenarios involving roles, accounts, resources, and business disruption to distinguish concepts.
  3. Build network and cloud security basics. Read simple network diagrams and identify segmentation, firewalls, VPNs, and responsibility boundaries.
  4. Connect the security operations workflow. Detect an event in logs, assess priority, follow and document the response plan, then review lessons learned.
  5. Use the new outline to find gaps. Make sure you can explain each subtopic and apply it to a basic scenario.

Readiness checklist

  • Distinguish CIA, AAA, risk, threats, vulnerabilities, and security controls.
  • Explain the purpose of governance policies, BC, DR, and incident response.
  • Apply least privilege, separation of duties, and common access control models.
  • Explain network segmentation, VPNs, defense in depth, cloud service models, and shared responsibility.
  • Describe the basics of logging, event triage, response plans, asset management, and security testing.
  • Study from the outline effective September 1, 2026.

Keep practicing

Use practice questions to learn the question style and spot weak areas, then revisit the matching topics. Start ISC2 CC practice.

WeChat mini program

IT知习 mini program QR code

Search WeChat for: IT知习