Cybersecurity Fundamentals: ISC2 CC Exam Preparation

Categories: Cybersecurity
Wishlist Share

About Course

This self-paced course covers all five domains assessed by the ISC2 Certified in Cybersecurity (CC) exam: security principles; business continuity, disaster recovery and incident response; access controls; network security; and security operations.

It is built for people moving into security from adjacent IT roles, from other careers entirely, or straight from study. CC has no work-experience prerequisite, and this course assumes no prior security background. Basic familiarity with computers and networks will help you move faster through the networking domain, but it isn’t required.

The course is deliberately structured for a compressed timeline. Rather than exhaustive depth, it prioritizes what CC actually tests: recognizing terminology precisely and sorting real examples into the right category. Every module maps to a numbered objective you can check off, and each one flags the specific question types that domain tends to use.

What you’ll learn

  • Explain the core principles of information security and how they relate to one another
  • Tell business continuity, disaster recovery, and incident response apart — what each is for and when each applies
  • Distinguish physical from logical access controls, and identify which access control model a system is using
  • Read a network setup and describe its structure, its exposure, and where the weak points sit
  • Select appropriate preventative measures for a given network design
  • Apply security operations practices; data protection, system hardening, policy, and awareness training, to everyday scenarios
  • Reason through a professional ethics scenario the way a certification exam expects
Show More

Course Content

Domain 1: Security Priniciples
The largest domain on the CC exam at 26%, and the vocabulary every other domain builds on. Covers the CIA triad and the trade-offs between its three legs; identification, authentication, authorisation and accounting; the difference between privacy and confidentiality; risk management from vocabulary through to the four treatments and who may accept a risk; the three categories of security control; the governance hierarchy from laws down to guidelines; and applying the ISC2 Code of Ethics canons in order of precedence. Nine lessons, a 25-question quiz and one hands-on assignment. Allow three days at two to three hours a day. Do not rush lessons 1.1 and 1.2; that terminology reappears throughout the course.

Domain 2: Incident Response, Business Continuity and Disaster Recovery
The availability leg of the triad, applied to systems and to people. Covers incident terminology from event through alert and incident to breach; the goal, four phases and cross-functional team of incident response, including which decisions must escalate to management; business continuity as operating through a crisis rather than preventing it; the business impact analysis and the RPO, RTO and MTD metrics that flow from it; and disaster recovery, backup strategies, recovery site types and the plan testing ladder. Six lessons, a 20-question quiz and one hands-on assignment. Allow one day. At 10% of the exam this is the smallest domain, but the definitional content makes full marks realistic.

Domain 3: Access Control Concepts
The second-largest domain at 22%, and the point where the course shifts from defining terms to selecting controls. Covers the subject-rule-object foundation and why whoever sets the rule defines the model; defence in depth and why layers must differ in kind; least privilege, need-to-know and the extra controls privileged accounts require; separation of duties, two-person control, job rotation and mandatory vacation; physical controls across deterrence, authentication and detection, including access control vestibules and biometric error rates; and the logical models; DAC, MAC, RBAC, ABAC and rule-based. Seven lessons, a 25-question quiz and one hands-on assignment. Allow two days. If you are short of time, protect Lesson 3.6, naming the access control model from a description is the single most reliably tested skill in this domain.

Domain 4: Network Security
The largest domain at 24%, and the most technical. Covers the OSI and TCP/IP reference models and which devices sit at which layer; IPv4 and IPv6 addressing, MAC addresses, NAT, DHCP and DNS; wireless security from WEP to WPA3; common ports and the secure counterpart of each insecure protocol; the TCP handshake; malware families, denial-of-service, on-path and side-channel attacks; firewalls, IDS versus IPS, antimalware and SIEM; data centre power, cooling, fire suppression and redundancy; cloud characteristics, service models and the shared responsibility split; and secure design, defence in depth, zero trust, NAC, DMZ, VLANs, microsegmentation and VPN. Nine lessons, a 30-question quiz and one hands-on assignment. Allow three days. Build the port-number flashcards on day one and drill them daily, no amount of reasoning recovers a forgotten port number, and this domain carries more pure recall than any other.

Domain 5: Security Operations
The final domain at 18%, covering the day-to-day use of the controls the other four domains described. Includes data handling across the full lifecycle — classification, labelling, retention and the three levels of destruction; logging and monitoring, why logs need protecting from the accounts they record, and why clock synchronisation matters; symmetric and asymmetric encryption, hybrid systems, and which key delivers confidentiality versus proof of origin; hashing, salting and how password storage actually works; configuration management, baselines, hardening and configuration drift; change management from request through to documentation; the common security policies; and security awareness training. Eight lessons, a 25-question quiz and one hands-on assignment. Allow two days. Much of this domain re-applies earlier material, so it moves faster than its weight suggests — the exception is encryption and hashing, which is genuinely new and worth the majority of your time here.

Final Assessments – Mock Exams

Student Ratings & Reviews

No Review Yet
No Review Yet

Want to receive push notifications for all major on-site activities?

Navigation