Prepare for Certified in Cybersecurity (CC) by learning the current five-domain outline and applying its concepts to explicit scenarios. The worked permissions exercise shows how to choose access that matches an assigned task, while the preparation guidance helps you check older study materials.
Which CC outline should you use?
Use ISC2’s Certified in Cybersecurity outline effective from 1 September 2026. CC is an entry-level credential and has no work-experience requirement.
The dated English PDF lists the current five domains and their detailed objectives. Some overview text on the website still uses older domain names, so use the dated PDF when building your coverage map.
Foundational AI security topics appear within the domains. Review those listed objectives alongside the other security concepts; they do not form an additional weighted domain.
Official sources: CC official English exam outline — Effective September 1, 2026; v01/2026; Certified in Cybersecurity Exam Outline (ISC2) — Effective September 1, 2026
What should you review in the five domains?
Use the published approximate weights below. They total 99.9% because of rounding; that is not a missing topic or a reason to change the figures.
Allocate study time using both the coverage and your practice gaps. Read the detailed objectives rather than relying only on these summaries.
| Domain | Approximate weight | A useful review task |
|---|---|---|
| Security Principles | 24% | Review core security concepts, ethics and cybersecurity controls, including technical, administrative and physical controls. |
| Security Governance | 17.3% | Review governance, risk and compliance, awareness, business continuity and disaster recovery, and cybersecurity effectiveness measures. |
| Identity and Access Management Concepts | 20% | Review identity lifecycle, roles, provisioning, review and deprovisioning, plus logical access controls such as least privilege and separation of duties. |
| Networking and Cloud Security Concepts | 21.3% | Review network concepts, threats, protections, cloud service models and shared responsibility. |
| Security Operations and Incident Response | 17.3% | Review data handling, monitoring, incident triage and response, and security testing concepts. |
Official sources: CC official English exam outline — Effective September 1, 2026; v01/2026
Practise choosing the minimum permissions
Least privilege means giving the access needed for the assigned task. Compare the actual permissions and authorized work before selecting a role.
This original role matrix supplies all relevant permissions and duties. The role letters are fictional and do not identify permissions in a real product.
Practice exercise
Mira’s only assigned task is reading monthly reports. Role R grants report read access; Role E grants report read and edit; Role A grants report read, edit and account administration. These are the only relevant permissions, no other assignments or controls apply, and no editing or administration is authorized. The fictional policy requires access changes to undergo an approved review of the user’s assigned duties. Which role is sufficient with the least access, why are the others excessive, and what should happen if editing later becomes an authorized duty?
Show answer
Role R provides all the access needed for the current task. Role E adds unneeded editing, and Role A adds both editing and account administration. If editing later becomes an authorized duty, use the policy’s approved review to reassess the permissions; Mira should not grant herself additional rights.
Compare each role’s permission set with the one authorized task. R contains only read, while E and A contain unnecessary permissions under these facts. The approval step follows the explicit fictional policy. No separation-of-duties conflict has been supplied or needs to be invented to justify the decision. This applies NIST’s least-privilege concept without making a universal rule about real role names or job titles.
Official sources: Least privilege — NIST CSRC Glossary — CNSSI 4009-2022 and NIST SP 800-12 Rev. 1 definitions; CC official English exam outline — Effective September 1, 2026; v01/2026
Can older CC study resources still help?
Compare their actual explanations and exercises with the September 2026 outline, then fill the gaps.
Older material may explain useful underlying concepts even when headings differ. Read the relevant content and map it to each current objective; neither an index entry nor a publication date proves full coverage.
After each practice question, state the task, the relevant principle and the evidence supporting your choice. Revisit weak objectives and include mixed practice so familiarity with one topic does not hide another gap.
For adaptive-format practice, commit to each answer before moving on and plan for up to 125 items in 120 minutes. A stopping point, perceived difficulty or practice percentage does not establish the official result.
- Download the current dated PDF and check all five domains.
- Use the worked example to compare the needed and granted permissions explicitly.
- Track the concepts you misread and explain why the other choices fail under the supplied facts.
Official sources: CC official English exam outline — Effective September 1, 2026; v01/2026; Certified in Cybersecurity Exam Outline (ISC2) — Effective September 1, 2026; Computerized Adaptive Testing (ISC2) — CAT FAQ: items, scoring, retakes, results
What happens after you pass CC?
You do not need work experience or an experience endorser for CC, but passing alone does not complete certification.
After official passing notification, complete the certification application within nine months of the exam date. Complete the required agreements, including the ISC2 Code of Ethics, and pay the first annual maintenance fee.
The annual maintenance fee for a member holding only CC is USD 50. Review the current member policy if you later hold other ISC2 certifications.
Official sources: What To Do After Your ISC2 Certification Exam — Results, certification process and retake policy; Endorsement | Online Endorsement Application | ISC2 — Application timeline and CC experience rules; Member Policies (ISC2) — Sections 4.1–4.2: CPE and AMF requirements
What should you expect on the exam?
CC allows 120 minutes for 100–125 items at Pearson VUE testing centers. It uses computerized adaptive testing (CAT), which selects items as you respond.
Once you finalize an answer, you cannot return to review or change it. Content is not presented in separate domain sections. The minimum-length exam includes 25 unscored pretest items, which you cannot identify. Read each item carefully and practise committing to an answer.
The published passing grade is 700 out of 1000; it is not a raw 70% or a fixed correct-answer count. ISC2 does not report numerical scores. Unsuccessful candidates receive domain proficiency information.
An unofficial result is normally provided at checkout, followed by official notification. Results can be delayed, so avoid planning around a guaranteed email turnaround.
Official sources: CC official English exam outline — Effective September 1, 2026; v01/2026; What To Do After Your ISC2 Certification Exam — Results, certification process and retake policy; Computerized Adaptive Testing (ISC2) — CAT FAQ: items, scoring, retakes, results
What should you check before booking?
Use ISC2’s current exam policies and your appointment instructions to check identification, accommodations and testing-center requirements.
Check regional pricing when you book. If a retake is needed, the waiting periods are 30 test-free days after the first attempt, 60 after the second and 90 after the third and subsequent attempts, with no more than four attempts per certification program in 12 months.
- Make sure your registration details match the required identification.
- Arrange any testing accommodations through ISC2 before scheduling.
- Review arrival instructions, permitted items and break rules; allowed breaks count against exam time.
- After passing, keep your exam date and certification application deadline with your records.
Official sources: How to Get Ready, Prepare for Your ISC2 Certification Exam — Exam format, scoring and accommodations; What To Do After Your ISC2 Certification Exam — Results, certification process and retake policy; Computerized Adaptive Testing (ISC2) — CAT FAQ: items, scoring, retakes, results; One Million Certified in Cybersecurity (ISC2) — Program conclusion FAQs and exam fee
Official sources
Facts checked:
- CC official English exam outline
- Certified in Cybersecurity Exam Outline (ISC2)
- How to Get Ready, Prepare for Your ISC2 Certification Exam
- What To Do After Your ISC2 Certification Exam
- Endorsement | Online Endorsement Application | ISC2
- Member Policies (ISC2)
- Computerized Adaptive Testing (ISC2)
- One Million Certified in Cybersecurity (ISC2)
- Least privilege — NIST CSRC Glossary
