Take a clean first pass
Answer all twenty questions without searching. Mark anything you guessed on even if you get it right. Uncertain correct answers are still useful signals because they show where recall or reasoning is fragile.
Test your understanding of the current Certified in Cybersecurity domains with original scenarios covering principles, governance, IAM, networking and cloud security, and security operations with incident response.
This independent diagnostic does not contain recalled, leaked, copied, or live-exam questions and is not affiliated with or endorsed by ISC2.
Exam timing, item policy, passing score, domain weighting, official links, and review dates are generated from Zeph Tech's maintained registry so older CC domain maps do not silently remain mixed into current study material.
Active
Last verified: 2026-09-28
Next review: 2026-10-28
The strongest use of a small practice set is targeted review. Track missed and uncertain questions, then explain the security principle behind the correct answer in your own words.
Answer all twenty questions without searching. Mark anything you guessed on even if you get it right. Uncertain correct answers are still useful signals because they show where recall or reasoning is fragile.
For each scenario, identify what the organization is trying to protect or accomplish: confidentiality, integrity, availability, least privilege, resilience, containment, evidence quality, or another clear objective.
A miss may mean you do not know a term, or it may mean you chose a valid action at the wrong stage. Classify the miss before reviewing so you do not waste time relearning concepts you already understand.
The quiz engine stores progress locally in your browser and links weak areas to deeper Zeph Tech guides. Use the weakest one or two domains to define your next focused study block.
The scenarios are mapped to the current five-domain outline and include explanations plus source context. Your progress stays in your browser.
Loading the interactive practice test. If it does not load, ensure JavaScript is enabled.
Reconnect controls to CIA, AAA, privacy, risk, governance, and ethics. Ask what property is being protected and whether the proposed action addresses that property directly.
Review ownership, resilience, awareness, metrics, business continuity, and disaster recovery. Focus on the difference between doing security activity and measuring whether risk is actually improving.
Practice identity lifecycle, least privilege, separation of duties, authentication, authorization, and access reviews. Always ask whether access still matches current business need.
Trace connectivity by layer, understand segmentation and zero-trust concepts, and identify customer versus provider responsibility before selecting a cloud security action.
Separate alert from confirmed incident, correlate evidence, choose phase-appropriate response actions, protect data, manage assets, and verify recovery rather than assuming it.
After completing the diagnostic, revisit every wrong or uncertain item. Write one sentence describing why the correct answer fits the stated objective and one sentence explaining why the strongest distractor fails a constraint. This is more useful than memorizing which letter was correct because a different scenario can test the same principle with entirely different wording.
If you repeatedly miss questions because you jump to a technical fix, slow down and identify the control objective first. If you know the objective but choose the wrong stage of incident response, practice sequencing. If cloud questions feel ambiguous, identify the service model and shared-responsibility boundary before deciding who owns the control.
Use current official objectives as the final scope authority. The September 2026 CC outline introduced meaningful changes, so older prep material can contain stale domain names or emphasis even when the underlying concepts remain useful.
Do not interpret a high score on twenty questions as a pass forecast. The diagnostic is intentionally a learning tool rather than a psychometrically validated exam predictor. Continue with fresh questions, hands-on practice, owner-published resources, and weak-domain review.
Identity drill: create a fictional joiner, mover, and leaver workflow. Define who approves access, how it is provisioned, when it is reviewed, and how it is removed. Then identify the risk if each stage fails.
Network and cloud drill: draw a user, a local network, a firewall, a SaaS service, and an administrator. Mark trust boundaries, where authentication occurs, what the customer controls, and which logs would help investigate suspicious access.
Incident drill: take a suspicious-login scenario and write the evidence you would collect, a reasonable containment action, what would constitute eradication, and how you would verify recovery. Keep observed facts separate from conclusions.
For Security Principles, take one business asset and write what confidentiality, integrity, and availability each mean in that specific context. A payroll database, for example, needs confidentiality for employee data, integrity for salary and banking records, and availability for payroll operations. Add authentication, authorization, accounting, privacy, and non-repudiation where they matter. This turns abstract terms into security properties tied to a real system.
For Security Governance, pick a fictional outage and separate continuity from recovery. Identify the business function that must keep operating, the systems that support it, the dependencies that can fail together, the acceptable restoration time, and the acceptable data-loss window. Then define which metric would show whether the plan is improving over repeated exercises. This makes RTO, RPO, resilience, awareness, and reporting part of one operating model instead of isolated definitions.
For IAM, walk an identity through joiner, mover, and leaver events. Record how the account is created, what approvals control initial access, how privileges change when the person's role changes, when access is reviewed, and how the identity is disabled or removed. Add one privileged task and decide whether separation of duties, just-in-time access, MFA, or a dedicated administrative account would reduce risk. The goal is to see access as a lifecycle rather than a one-time login.
For Networking and Cloud Security, draw a user device, local network, firewall, identity provider, SaaS service, and administrator. Trace a normal connection and identify which layer performs addressing, routing, name resolution, encryption, authentication, and authorization. Then mark what the cloud provider operates and what the customer still controls. This simple drawing exposes why a strong network connection does not automatically mean the application, identity, or cloud configuration is secure.
For Security Operations and Incident Response, create a timeline from a suspicious sign-in through investigation, containment, eradication, and recovery. For each phase, record what evidence is available, what remains uncertain, what action is reversible, and how you would prove the organization returned to a trusted state. This exercise trains the distinction between an alert, a confirmed incident, and a complete response.
Finish with one mixed scenario that crosses domains: a new SaaS platform handling sensitive data. Identify the governing policy, account lifecycle, least-privilege roles, network and cloud responsibility, logging requirements, incident contacts, continuity dependency, and data-retention rule. If you can explain how those pieces reinforce one another, you are studying the CC as an operating security model rather than five isolated vocabulary lists.