Printable reference2026 outline

ISC2 CC cram sheet and exam-day checklist

A compact last-mile reference for the current Certified in Cybersecurity domains and the decision patterns that are easiest to mix up under time pressure.

Independent study resource. Not affiliated with or endorsed by ISC2. No recalled, leaked, copied, or live-exam questions.

Current reviewed CC record

Use the maintained record below for changing logistics and domain weights. The quick-reference content focuses on durable security reasoning while ISC2 remains the final authority for exam changes.

Active

Last verified: 2026-09-28

Next review: 2026-10-28

Official certification page · Official exam objectives

Published domain weighting

Security Principles

Security Governance

IAM Concepts

Networking and Cloud

Operations and Incident Response

Fast distinction drill

Authentication vs authorization: first prove who the identity is; then decide whether that identity may perform the requested action. A successful login does not imply access to every resource.

Business continuity vs disaster recovery: continuity keeps important business functions operating; disaster recovery restores technology and supporting services after disruption. They reinforce each other but answer different questions.

Preventive vs detective vs corrective: preventive controls try to stop an event, detective controls reveal it, and corrective controls help restore or fix conditions afterward. A single technology may support more than one purpose depending on how it is used.

RTO vs RPO: RTO is about how long restoration may take; RPO is about how much recent data loss measured in time the business can accept. Do not swap them.

Alert vs incident: an alert is a signal that warrants evaluation. An incident is a confirmed security event requiring response. Correlation and context matter.

Scenario checklist

Identify the security objective before the tool. Ask what asset or process is at risk, what the organization is trying to preserve, and whether the proposed action directly addresses that objective.

Respect sequence. If the scenario is still establishing facts, choose an evidence-producing action before an irreversible change when practical. During response, distinguish containment, eradication, recovery, and lessons learned rather than treating them as one step.

Respect ownership. Risk acceptance requires an accountable owner. Access changes require authorized approval. Security testing should remain within permission. Technical ability does not override governance or ethics.

Think in layers. A network symptom may be physical, addressing, routing, DNS, transport, or application. A cloud issue may belong to the provider or customer depending on the service model. An IAM issue may be authentication, authorization, provisioning, or review.

Exam-day checklist

Use this after full study, not instead of the current ISC2 outline and hands-on practice.

Last-mile review method

Take ten missed or uncertain practice questions and classify each error. Use four buckets: knowledge gap, terminology confusion, wrong control objective, or sequencing error. Review only the category that caused the miss. This keeps final study efficient and prevents endless rereading.

For every knowledge gap, write a one-sentence definition and one example. For every control-objective miss, explain what the question was actually trying to protect. For sequencing errors, state what evidence or response phase should have come first.

Then practice explaining the same principle in a new scenario. If you learned least privilege from an administrator question, apply it to a service account. If you learned RTO from a data-center outage, apply it to a SaaS dependency. Transferable understanding is the goal.

Finally, verify current exam logistics and objectives with ISC2 before scheduling. Certification programs can change, and owner-published information controls when it conflicts with independent study material.

Concept-to-action drill

Translate memorized terms into the action they justify.

When you see confidentiality, ask what unauthorized disclosure would look like and which control prevents or limits it. When you see integrity, ask what unauthorized change would look like and how the organization could detect or prevent it. When you see availability, ask what dependency or failure could make the service unusable and what resilience control addresses that condition.

For governance questions, identify the document or decision level involved. A policy expresses direction, a standard creates a mandatory implementation requirement, a procedure explains repeatable execution, and a guideline recommends practice. Risk treatment decisions also require ownership: mitigation reduces risk, transfer shifts defined consequences, avoidance stops the risk-producing activity, and acceptance deliberately retains residual risk.

For IAM questions, separate proving identity from granting permission. Authentication answers who the subject is; authorization answers what the subject may do. Least privilege limits access to what is necessary, while separation of duties prevents one identity from controlling every step of a sensitive process. Lifecycle thinking adds provisioning, review, role changes, and deprovisioning around those access decisions.

For network questions, identify the failing layer before choosing a tool. A physical link problem, invalid address, missing route, DNS failure, TLS problem, or application error can all feel like a connection problem to the user. For cloud questions, identify the service model and the shared-responsibility boundary before assigning a control to the provider or customer.

For operations questions, distinguish detection from conclusion. An alert, threat-intelligence match, or unusual event is evidence that may justify investigation; it is not automatically proof of compromise. Correlate identity, endpoint, network, cloud, and application evidence when available. During incident response, choose actions that fit the current phase and verify recovery rather than stopping at symptom removal.