ISC2 CC: cybersecurity foundations in practice
Five lessons, 25 questions, and five scenarios on principles, governance, access, networks, cloud, and incident response.
Objectives and progression
Initial course with five lessons and 30 original decisions in fictional support and project contexts. Internal assessment of 20 decisions in 45 minutes. Covers all five updated domains, including an AI data-integrity case. Wireless, embedded systems, access models, and cryptography need deeper study; this is not exhaustive preparation. CC outline effective 2026-09-01, PDF v01/2026. Official CAT exam of 100–125 items in 120 minutes; 700/1000 is a scaled score, not 70% correct answers. Published rounded weights sum to 99.9%.
Audience: People entering cybersecurity and support or project professionals needing applied foundations.
Prerequisites: Basic IT knowledge recommended. The official outline requires neither cybersecurity experience nor a degree; studying on dr.pt does not award an ISC2 credential.
225 estimated study minutes
- Distinguish security properties, controls, and operating boundaries.
- Support decisions and continuity with clear metrics and communication.
- Review permissions on joining, changing roles, and ending activities.
- Interpret layers and paths without assuming automatic isolation.
- Triage and protect data with conclusions proportional to evidence.
Modules
- Security principles and conduct
- Governance, continuity, and awareness
- Identity and access lifecycle
- Networks, cloud, and boundaries
- Data, operations, and initial response
Continue learning
References and version
CC examination outline effective 2026-09-01; PDF v01/2026
- CC current examination outline and AI guidance · 2026-09-30
- CC official examination outline PDF · 2026-09-30
- Certified in Cybersecurity credential · 2026-09-30
- ISC2 Code of Ethics · 2026-09-30
- Digital authentication guidelines · 2026-09-30
- Security and privacy controls · 2026-09-30
- Guidelines for media sanitization · 2026-09-30
- Definition of cloud computing · 2026-09-30
- Recognize and avoid phishing scams · 2026-09-30
- IPv6 specification · 2026-09-30
- VPC security groups · 2026-09-30
- Cloud shared responsibility · 2026-09-30
- Static source analysis · 2026-09-30
- Zero trust architecture · 2026-09-30
- Contingency planning, RTO and RPO · 2026-09-30
- Cybersecurity Framework 2.0 · 2026-09-30
- TLS 1.3 replay and early data · 2026-09-30
- Incident response within cybersecurity risk management · 2026-09-30
- Enterprise patch management planning · 2026-09-30
What you will explore
0 / 5Security principles and conduct
Distinguish security properties, controls, and operating boundaries.
Governance, continuity, and awareness
Support decisions and continuity with clear metrics and communication.
Identity and access lifecycle
Review permissions on joining, changing roles, and ending activities.
Networks, cloud, and boundaries
Interpret layers and paths without assuming automatic isolation.
Data, operations, and initial response
Triage and protect data with conclusions proportional to evidence.