Career Employer

Your FREE ISC2 CC Flashcards 2026 – 200+ Cards

Realistic, ISC2 CC exam-style flashcards across all 5 domains — flip, match, type, and quiz yourself.

How well do you know them?

To find us again, just search “Career Employer ISC2 CC”

By

Click Study Flashcards above to open the flashcard hub — hundreds of ISC2 CC cards you can flip, match, type, or quiz yourself on. Every card is drawn from the five official ISC2 CC domains, so you study exactly what the exam tests.[1] Pair them with our free practice test and study guide.

ISC2 CC is one of the 9 ISC2 certifications — explore our ISC2 flashcards to compare and prep across the whole family.

ISC2 CC Flashcard Study Modes

Flip mode lets you read a term, think, then check the back at your own pace. Match turns terms and definitions into a timed pairing game. Type shows a definition and asks you to produce the term, so a prompt for a decoy network segment has you spell out DMZ. Quiz builds multiple-choice questions from the same 232 cards.

Free ISC2 CC flashcards from Career Employer — active recall for the Certified in Cybersecurity exam

Why Flashcards Work for the ISC2 CC

Security Principles carries the heaviest official weight (24% under the September 2026 outline) and the largest share of the deck with 61 cards. These drill the vocabulary the rest of the exam leans on: the difference between a Threat and an Asset, how Impact is described, and the card written as Risk = ?. Governance terms such as Policy and Standard show up here too, along with Privacy.

The Network Security deck has 56 cards (networking now falls under Networking and Cloud Security Concepts, 21.3%). Expect protocol and device shorthand you must recall cold, including TCP and UDP, the contrast between IDS and IPS, and older wireless protection like WEP. Perimeter and addressing terms round it out, with cards for DMZ, VPN, and NAT.

The Access Controls Concepts deck has 36 cards (the outline now calls this IAM Concepts, 20%), the smallest set relative to its weight, so treat it as high value per card. You get the AAA model, the split between Identification, Authorization, and Accountability, and physical entry problems such as Tailgating and Piggybacking. Principles like Need-to-know and controls like Account lockout are here as well.

The Security Operations deck has 42 cards (Security Operations and Incident Response is 17.3%). Cryptography terms dominate the front half, with AES, RSA, and Hashing alongside the broader idea of Encryption. Monitoring and hardening appear through SIEM and Baseline, and social engineering shows up in Phishing and Whaling.

The BC, DR & Incident Response deck has 37 cards. The distinctions matter most: an Event versus an Incident, and the card on BC vs. DR. Recovery site cards cover Hot site, Warm site, and Cold site, with supporting terms such as Failover and Redundancy.

The ISC2 CC is dense with terminology — control types, security models, networking concepts, and access frameworks.[3] Spaced flashcards are the most efficient way to keep it all fresh. Used alongside our practice test and study guide, they turn review time into measurable progress.

ISC2 CC Flashcards by Domain

The cards are organized by the five ISC2 CC domains of the outline used before September 1, 2026. The current outline renames and reweights them; cover every deck, but lead with the largest, Security Principles:[1]

ISC2 CC flashcard decks and the closest domain in the outline effective Sept 1, 2026
DeckClosest current domain (weight)
Security PrinciplesSecurity Principles (24%)
Network SecurityNetworking and Cloud Security Concepts (21.3%)
Access Controls ConceptsIAM Concepts (20%)
Security OperationsSecurity Operations and Incident Response (17.3%)
BC, DR & Incident ResponseSecurity Operations and Incident Response (17.3%)

How to Get the Most Out of These Flashcards

  • Start with Security Principles. At 24% and 61 cards it is both the heaviest domain and the vocabulary base for everything else, so Flip it end to end before touching other decks.
  • Type-drill the definition-sensitive cards. Risk = ? and Need-to-know reward exact recall, and typing them forces you to produce the wording instead of recognizing it in a list.
  • Use Match for the acronym clusters. Network Security abbreviations such as IDS, IPS, and NAT pair fast under time pressure and expose the ones you only half know.
  • Move to the practice test once Quiz feels easy. When you clear Quiz on all five domains without guessing, switch over to see how the terms behave inside full-length questions.
  • Rotate domains in short sittings. With 232 cards, work one domain per session, then re-Flip the previous day’s misses before starting the next, and keep the study guide open for gaps.

ISC2 CC Flashcards FAQ

Hundreds of free ISC2 CC flashcards, organized across all five domains — Security Principles, Business Continuity/Disaster Recovery & Incident Response, Access Controls Concepts, Network Security, and Security Operations. They're free with no account required.

ISC2 CC flashcard bank

All 232 cards, by topic

A reference copy of every card in this deck. Each answer stays hidden until you choose to show it. To study with Flip, Match, Type and Quiz modes and track what you have mastered, use Study Flashcards at the top of the page.

Security Principles (61)

CIA triad
Show answer

Confidentiality, Integrity, Availability — the three core goals of information security.

Confidentiality
Show answer

Preventing the unauthorized disclosure of data; protected by encryption and access controls.

Integrity
Show answer

Ensuring data is accurate and unaltered except by authorized parties; protected by hashing and change control.

Availability
Show answer

Ensuring authorized users have timely, reliable access to systems and data; protected by redundancy and backups.

DAD triad
Show answer

Disclosure, Alteration, Destruction — the opposite of CIA, naming the threats to each goal.

Authentication
Show answer

Proving a claimed identity with a credential (something you know, have, or are).

Non-repudiation
Show answer

Assurance that a party cannot deny having performed an action; provided by digital signatures and logging.

Privacy
Show answer

The appropriate collection, use, and protection of personal information.

Information assurance concepts (CC)
Show answer

Confidentiality, Integrity, Availability, plus Authentication, Non-repudiation, and Privacy.

Asset
Show answer

Anything of value to the organization that needs protection — data, hardware, software, or people.

Threat
Show answer

Any potential event or actor that could cause harm by exploiting a vulnerability.

Vulnerability
Show answer

A weakness in a system, process, or control that a threat can exploit.

Risk
Show answer

The likelihood that a threat will exploit a vulnerability, and the resulting impact on an asset.

Threat vs. vulnerability vs. risk
Show answer

Threat = potential cause of harm; vulnerability = weakness it exploits; risk = chance and impact of that happening.

Likelihood
Show answer

The probability that a given threat will exploit a given vulnerability.

Impact
Show answer

The magnitude of harm if a risk event occurs.

Risk = ?
Show answer

A function of likelihood × impact, requiring a threat, a vulnerability, and an asset of value.

Risk management process
Show answer

Identify assets/threats/vulnerabilities, assess and prioritize, choose treatment, implement controls, monitor.

Four risk treatment options
Show answer

Avoid, Mitigate (reduce), Transfer, Accept.

Risk avoidance
Show answer

Eliminating a risk by ceasing the activity that creates it.

Risk mitigation
Show answer

Reducing risk to an acceptable level by implementing controls.

Risk transference
Show answer

Shifting the financial impact of a risk to a third party, such as through insurance.

Risk acceptance
Show answer

A documented, management-approved decision to tolerate a risk and its potential impact.

Residual risk
Show answer

The risk that remains after controls are applied; senior management formally accepts it.

Who owns risk?
Show answer

Senior management — they own risk and set the tone; security translates business goals into rules.

Security control
Show answer

A safeguard that reduces risk to assets; categorized by type and by function.

Technical (logical) control
Show answer

A control implemented with technology — firewalls, encryption, antivirus, MFA, access control lists.

Administrative (managerial) control
Show answer

Policies, procedures, standards, and training that direct how people behave.

Physical control
Show answer

A tangible barrier protecting facilities and hardware — locks, fences, guards, badges, CCTV.

Three control TYPES
Show answer

Technical (logical), Administrative (managerial), and Physical.

Preventive control
Show answer

Stops an incident before it happens — a lock, a firewall rule, MFA.

Detective control
Show answer

Identifies an incident in progress or after the fact — CCTV, IDS, logs, audits.

Corrective control
Show answer

Restores systems after an incident — backups, patches, antivirus removal.

Deterrent control
Show answer

Discourages an attacker — warning signs, visible guards, lighting.

Control type vs. function
Show answer

Type = HOW it's built (technical/admin/physical); function = WHAT it does (preventive/detective/corrective/deterrent).

Firewall control classification
Show answer

Technical type, preventive function — it filters traffic by rules before it's allowed in.

CCTV control classification
Show answer

Physical type, detective and deterrent function — it records activity and discourages intruders.

Defense in depth
Show answer

Layering multiple, overlapping controls so that if one fails, others still protect the asset.

Governance document hierarchy
Show answer

Regulation/law → policy → standard → procedure → guideline.

Policy
Show answer

A high-level management statement of intent and goals; mandatory.

Standard
Show answer

A specific mandatory requirement supporting a policy (e.g., 'use AES-256').

Procedure
Show answer

Detailed step-by-step instructions for a task; mandatory.

Guideline
Show answer

Recommended, discretionary best practice; the only non-mandatory document.

Regulation / law
Show answer

A rule imposed by a government or authority that the organization must obey.

ISC2 Code of Ethics — # of canons
Show answer

Four canons, applied in order.

ISC2 Code of Ethics canon 1
Show answer

Protect society, the common good, necessary public trust and confidence, and the infrastructure.

ISC2 Code of Ethics canon 2
Show answer

Act honorably, honestly, justly, responsibly, and legally.

ISC2 Code of Ethics canon 3
Show answer

Provide diligent and competent service to principals.

ISC2 Code of Ethics canon 4
Show answer

Advance and protect the profession.

Conflicting ethics canons — which wins?
Show answer

The earlier (lower-numbered) canon — protecting society outranks advancing the profession.

Due care
Show answer

Acting on due diligence by implementing and maintaining reasonable controls — what a prudent person would do.

Due diligence
Show answer

Doing the research and developing the plans/policies needed to protect the organization.

Defense in depth vs. single control
Show answer

No single control is a silver bullet; layers force an attacker to defeat several independent defenses.

Compensating control
Show answer

An alternative control used when the primary control isn't feasible, providing similar protection.

Qualitative risk analysis
Show answer

Ranking risk subjectively as high/medium/low — fast, but not expressed in dollars.

Quantitative risk analysis
Show answer

Assigning objective monetary values to risk (e.g., expected annual loss) to cost-justify controls.

Threat actor
Show answer

A person or group that carries out a threat — e.g., hacktivists, insiders, nation-states, cybercriminals.

Insider threat
Show answer

A risk posed by people inside the organization, whether malicious or careless.

Asset inventory
Show answer

A catalog of the organization's assets and their value — the starting point of risk management.

Security governance
Show answer

The framework of policies, roles, and oversight by which leadership directs security.

Prudent person rule
Show answer

Acting with the care a reasonable, prudent person would in the same situation (due care + due diligence).

BC, DR & Incident Response (37)

Business continuity (BC)
Show answer

Keeping critical business functions operating during and after a disruption — the organization-wide plan.

Disaster recovery (DR)
Show answer

The IT-focused subset of continuity: restoring systems, data, and infrastructure after a disaster.

BC vs. DR
Show answer

BC keeps the whole business running; DR is the IT subset that restores technology.

Business continuity plan (BCP)
Show answer

A documented plan to keep critical functions running through a disruption.

Disaster recovery plan (DRP)
Show answer

A documented plan to restore IT systems and data after a disruptive event.

Business Impact Analysis (BIA)
Show answer

Identifies critical business functions and sets recovery objectives (MTD, RTO, RPO); the heart of continuity.

Maximum Tolerable Downtime (MTD)
Show answer

The longest a function can be unavailable before unacceptable harm; sets the ceiling for the RTO.

Recovery Time Objective (RTO)
Show answer

The target time to restore a system after a disruption; must be shorter than the MTD.

Recovery Point Objective (RPO)
Show answer

The maximum acceptable amount of data loss measured backward in time; drives backup frequency.

RTO vs. RPO
Show answer

RTO = time to recover; RPO = data you can afford to lose.

RTO and MTD relationship
Show answer

RTO must always be shorter than the MTD.

Hot site
Show answer

A fully equipped recovery site with near-real-time failover; fastest recovery, most expensive.

Warm site
Show answer

A recovery site with hardware and connectivity; data restored on demand. Moderate cost and speed.

Cold site
Show answer

An empty recovery space with power and cooling only; cheapest, slowest to bring online.

Recovery sites by cost/speed
Show answer

Hot (fast, costly) → warm → cold (cheap, slow).

Full backup
Show answer

Backs up all selected data; fastest to restore (one set), slowest to back up.

Incremental backup
Show answer

Backs up changes since the last backup of any type; fast backup, slow restore.

Differential backup
Show answer

Backs up changes since the last full backup; slower backup, faster restore.

3-2-1 backup rule
Show answer

Keep three copies of data, on two different media types, with one copy off-site.

Event
Show answer

Any observable occurrence on a system or network.

Incident
Show answer

An event that actually or potentially harms the confidentiality, integrity, or availability of information.

Event vs. incident
Show answer

Every incident is an event, but only some events harm security and become incidents.

Incident response (IR)
Show answer

The structured process to prepare for, detect, contain, eradicate, recover from, and learn from an incident.

Incident response team
Show answer

A designated group that follows the IR plan to handle security incidents.

NIST incident response lifecycle
Show answer

Preparation; Detection & Analysis; Containment, Eradication & Recovery; Post-Incident Activity.

IR phase: Preparation
Show answer

Build the IR plan, team, tools, and communications, and train staff — before anything happens.

IR phase: Detection & Analysis
Show answer

Recognize and confirm an incident, determine its scope, and prioritize it.

IR phase: Containment, Eradication & Recovery
Show answer

Stop the spread, remove the cause, and restore systems to normal operation.

IR phase: Post-Incident Activity
Show answer

Hold a lessons-learned review and improve the plan and controls.

First step during an active incident
Show answer

Containment — limit the damage before eradicating the cause.

Lessons learned
Show answer

The post-incident review that documents what happened and improves future response.

Tabletop exercise
Show answer

A discussion-based walkthrough of the incident or continuity plan to test it without disrupting operations.

Failover
Show answer

Automatically switching to a standby system or site when the primary fails.

Redundancy
Show answer

Duplicating critical components so a single failure doesn't cause an outage (supports availability).

Why test the BCP/DRP?
Show answer

Untested plans fail in a real disaster; testing finds gaps and trains the team before it matters.

Business continuity vs. incident response
Show answer

BC keeps the business running through disruption; IR handles a specific security incident.

Root cause analysis
Show answer

Determining the underlying cause of an incident so it can be fixed and prevented from recurring.

Access Controls Concepts (36)

Least privilege
Show answer

Granting users and processes only the minimum access needed to do their job, and nothing more.

Need-to-know
Show answer

Limiting access to the specific information required to perform a task.

Segregation (separation) of duties
Show answer

Splitting a sensitive task so no single person can complete it alone, reducing fraud and error.

AAA model
Show answer

Authentication, Authorization, and Accountability.

Access control sequence
Show answer

Identification → Authentication → Authorization → Accountability.

Identification
Show answer

A subject claiming an identity, such as entering a username — the first step of access control.

Authorization
Show answer

Determining what an authenticated identity is permitted to access and do.

Accountability
Show answer

Tying actions back to a specific identity through logging and monitoring.

Multi-factor authentication (MFA)
Show answer

Using two or more factors from different categories — something you know, have, and are.

Something you know
Show answer

A knowledge authentication factor — password, PIN, or passphrase.

Something you have
Show answer

A possession authentication factor — smart card, hardware token, or phone.

Something you are
Show answer

An inherence (biometric) authentication factor — fingerprint, iris, or face.

Is password + security question MFA?
Show answer

No — both are 'something you know,' so it's single-factor. MFA requires different categories.

Discretionary access control (DAC)
Show answer

Access decided by the data owner, e.g., file permissions and ACLs. Flexible but error-prone.

Mandatory access control (MAC)
Show answer

Access enforced by the system from labels and clearances; the most restrictive, used for classified data.

Role-based access control (RBAC)
Show answer

Access granted by job role rather than the individual; scales well in organizations.

DAC vs. MAC vs. RBAC
Show answer

DAC = owner decides; MAC = system enforces from labels; RBAC = by job role.

Most restrictive access model
Show answer

Mandatory Access Control (MAC) — the system, not the owner, decides based on labels and clearances.

Access control model for scalable provisioning
Show answer

RBAC — assign access by role so staff inherit and lose permissions as their role changes.

Physical access control
Show answer

A tangible control protecting facilities and hardware — locks, badges, guards, CCTV.

Mantrap (access control vestibule)
Show answer

A two-door airlock allowing one person per authentication; stops tailgating.

Tailgating
Show answer

Following an authorized person through a secure door without authenticating.

Piggybacking
Show answer

Being let through a secure door by an authorized person (with their awareness).

Biometric authentication
Show answer

Verifying identity from a physical trait — fingerprint, iris, face, or voice.

False acceptance rate (FAR)
Show answer

How often a biometric system wrongly accepts an unauthorized user (a Type II error).

False rejection rate (FRR)
Show answer

How often a biometric system wrongly rejects an authorized user (a Type I error).

Single sign-on (SSO)
Show answer

One authentication that grants access to multiple systems.

Privileged account
Show answer

An account with elevated rights (e.g., administrator) that needs extra protection and monitoring.

Provisioning / deprovisioning
Show answer

Granting access when a user joins or changes roles, and removing it promptly when they leave.

Logical (technical) access control
Show answer

Technology-based control of access to systems and data — passwords, MFA, ACLs, encryption.

Authentication vs. authorization
Show answer

Authentication proves who you are; authorization decides what you're allowed to do.

Token (authentication)
Show answer

A possession factor that generates or stores a credential (e.g., a one-time code).

Type I vs. Type II biometric error
Show answer

Type I = false rejection (authorized user denied); Type II = false acceptance (impostor allowed).

Account lockout
Show answer

Disabling an account after repeated failed logins to slow password-guessing attacks.

Just-in-time access
Show answer

Granting elevated privileges only when needed and for a limited time, reducing standing access.

Physical vs. logical access control
Show answer

Physical protects facilities and hardware; logical protects systems and data via technology.

Network Security (56)

OSI model
Show answer

A seven-layer reference model: Physical, Data Link, Network, Transport, Session, Presentation, Application.

OSI layer 1
Show answer

Physical — cables, signals, and hardware; hubs.

OSI layer 2
Show answer

Data Link — MAC addresses, switches, and frames.

OSI layer 3
Show answer

Network — IP addressing and routing; routers; IPsec.

OSI layer 4
Show answer

Transport — TCP and UDP; port numbers.

OSI layer 5
Show answer

Session — setting up, managing, and tearing down sessions.

OSI layer 6
Show answer

Presentation — encryption, encoding, and formatting.

OSI layer 7
Show answer

Application — the data the user interacts with (HTTP, DNS, SMTP).

OSI mnemonic (Layer 1→7)
Show answer

Please Do Not Throw Sausage Pizza Away.

Switch — OSI layer
Show answer

Layer 2 (Data Link) — forwards frames by MAC address.

Router — OSI layer
Show answer

Layer 3 (Network) — forwards packets by IP address.

TCP/IP model
Show answer

A four-layer practical model: Network Access, Internet, Transport, and Application.

TCP
Show answer

Transmission Control Protocol — connection-oriented, reliable, ordered delivery (Layer 4).

UDP
Show answer

User Datagram Protocol — connectionless, fast, but unreliable (Layer 4).

TCP vs. UDP
Show answer

TCP is reliable and connection-oriented; UDP is fast and connectionless.

IPv4
Show answer

32-bit IP addressing (about 4.3 billion addresses) — running out.

IPv6
Show answer

128-bit IP addressing — vastly more addresses than IPv4.

Port 22
Show answer

SSH — secure remote administration.

Port 53
Show answer

DNS — domain name resolution.

Port 80
Show answer

HTTP — unencrypted web traffic.

Port 443
Show answer

HTTPS (TLS) — encrypted web traffic.

Port 3389
Show answer

RDP — Remote Desktop Protocol.

WPA3
Show answer

The current secure WiFi encryption standard; use it instead of legacy WEP.

WEP
Show answer

An obsolete, insecure WiFi encryption standard that should never be used.

Malware
Show answer

Malicious software — viruses, worms, trojans, ransomware, spyware.

Virus
Show answer

Malware that attaches to a host file and spreads when a user runs it.

Worm
Show answer

Malware that self-replicates across networks with no user action.

Trojan
Show answer

Malware disguised as legitimate software to trick the user into installing it.

Ransomware
Show answer

Malware that encrypts data and demands payment for the decryption key.

Spyware
Show answer

Malware that secretly gathers information about a user or system.

DoS attack
Show answer

A Denial-of-Service attack that floods a system from one source to make it unavailable.

DDoS attack
Show answer

A Distributed Denial-of-Service attack launched from many compromised machines (a botnet) at once.

DoS vs. DDoS
Show answer

DoS floods from one source; DDoS floods from many distributed sources, making it harder to block.

On-path (man-in-the-middle) attack
Show answer

Intercepting and possibly altering traffic between two communicating parties.

Side-channel attack
Show answer

Extracting information through physical signals such as power use, timing, or electromagnetic leaks.

Firewall
Show answer

A control that filters network traffic, allowing or blocking it based on a defined ruleset.

IDS
Show answer

Intrusion Detection System — monitors traffic and alerts on suspicious activity but does not block it.

IPS
Show answer

Intrusion Prevention System — detects and actively blocks malicious traffic.

IDS vs. IPS
Show answer

IDS detects and alerts only; IPS detects and blocks.

VLAN
Show answer

A virtual LAN that logically segments a network to isolate traffic.

Network segmentation
Show answer

Dividing a network into zones to limit the spread of an attack and control traffic.

DMZ
Show answer

A screened subnet that exposes public-facing services while shielding the internal network.

VPN
Show answer

A Virtual Private Network — an encrypted tunnel that secures traffic across an untrusted network.

Zero trust
Show answer

A model that trusts no user or device by default and continuously verifies every access request.

SaaS
Show answer

Software as a Service — the provider delivers ready-to-use applications over the internet.

PaaS
Show answer

Platform as a Service — the provider delivers a platform to build and run applications.

IaaS
Show answer

Infrastructure as a Service — the provider delivers virtualized compute, storage, and networking.

Cloud shared responsibility model
Show answer

The provider secures the cloud itself; the customer secures their data, access, and configuration.

Botnet
Show answer

A network of compromised machines controlled by an attacker, often used for DDoS.

NAT
Show answer

Network Address Translation — maps private internal IPs to a public IP, hiding internal addressing.

Proxy server
Show answer

An intermediary that forwards and can filter or cache traffic between clients and servers.

Network segmentation benefit
Show answer

Limits the blast radius of an attack and contains threats to one zone.

Spoofing
Show answer

Faking a source identity such as an IP or email address to bypass controls or deceive a target.

Sniffing
Show answer

Capturing network traffic to read data, especially when it's unencrypted.

TLS
Show answer

Transport Layer Security — encrypts traffic in transit (the 'S' in HTTPS).

MAC address
Show answer

A hardware address that identifies a device on a local network (used at OSI Layer 2).

Security Operations (42)

Data at rest
Show answer

Data stored on a disk or in a database; protected with full-disk or database encryption.

Data in transit
Show answer

Data moving across a network; protected with TLS, IPsec, or a VPN.

Data in use
Show answer

Data decrypted in memory while being processed — the hardest state to protect.

Three data states
Show answer

At rest (stored), in transit (moving), and in use (being processed).

Encryption
Show answer

Converting data into an unreadable form so only authorized parties with the key can read it.

Symmetric encryption
Show answer

Uses one shared secret key for both encrypting and decrypting (e.g., AES); fast but key distribution is hard.

Asymmetric encryption
Show answer

Uses a public/private key pair (e.g., RSA); slower, but solves key exchange and enables signatures.

Symmetric vs. asymmetric
Show answer

Symmetric = one shared key, fast; asymmetric = key pair, slower, solves key exchange.

AES
Show answer

Advanced Encryption Standard — the widely used symmetric encryption algorithm.

RSA
Show answer

A widely used asymmetric (public-key) encryption and digital-signature algorithm.

Hashing
Show answer

A one-way function producing a fixed-length digest used to verify integrity (e.g., SHA-256).

Encryption vs. hashing
Show answer

Encryption is reversible with a key (confidentiality); hashing is one-way (integrity).

Digital signature
Show answer

A hash encrypted with the sender's private key, giving integrity, authenticity, and non-repudiation.

Public/private key — encrypt vs. sign
Show answer

Encrypt for confidentiality with the recipient's public key; sign for authenticity with your own private key.

Data classification
Show answer

Labeling data by sensitivity (public, internal, confidential, restricted) so the right protection applies.

Logging and monitoring
Show answer

Recording and reviewing system activity to detect, investigate, and respond to problems.

SIEM
Show answer

Security Information and Event Management — centralizes and correlates logs for detection and analysis.

System hardening
Show answer

Reducing a system's attack surface — remove unneeded services, close ports, disable defaults, patch.

Baseline
Show answer

A minimum required level of secure configuration to harden a system toward.

Configuration management
Show answer

Recording, controlling, and approving changes to system settings to keep a known-good state.

Change management
Show answer

A controlled process for evaluating, testing, approving, and documenting changes to systems.

Patch management
Show answer

Applying vendor updates promptly to close known vulnerabilities.

Acceptable use policy (AUP)
Show answer

A policy defining how employees may use organizational systems and data.

BYOD policy
Show answer

Rules governing the use of personal devices for work to protect organizational data.

Password policy
Show answer

Rules for password length, complexity, rotation, and reuse to strengthen authentication.

Data handling policy
Show answer

Rules for how data is stored, transmitted, shared, retained, and destroyed by classification.

Social engineering
Show answer

Manipulating people into divulging information or taking actions that compromise security.

Phishing
Show answer

A social-engineering attack using fraudulent messages to trick users into revealing credentials or installing malware.

Spear phishing
Show answer

A targeted phishing attack aimed at a specific person or organization using personalized details.

Whaling
Show answer

Phishing that targets high-value executives such as a CEO or CFO.

Vishing / smishing
Show answer

Social engineering by voice call (vishing) or SMS text (smishing).

Security awareness training
Show answer

Educating users to recognize and avoid threats such as phishing and social engineering.

Best defense against phishing
Show answer

Security awareness training, backed by email filtering and MFA so stolen credentials alone aren't enough.

Data destruction / sanitization
Show answer

Removing data so it can't be recovered — overwriting, degaussing, or physical destruction.

Principle: least functionality
Show answer

Configure systems to provide only essential capabilities, disabling unneeded ports, services, and software.

Logging — why it matters
Show answer

You can't detect or investigate what you can't see; logs provide accountability and detection.

Default deny
Show answer

Blocking everything by default and allowing only what's explicitly permitted.

Separation of duties (ops)
Show answer

No single person controls a critical operational task end to end, reducing fraud.

Data retention policy
Show answer

Rules for how long data is kept and when it's securely destroyed.

Endpoint protection
Show answer

Security controls on devices — antivirus/EDR, hardening, patching, encryption.

Vulnerability management
Show answer

The ongoing process of identifying, prioritizing, and remediating weaknesses.

Principle of least privilege (ops)
Show answer

Run services and grant accounts only the minimum rights needed, limiting damage from compromise.

References

  1. 1.ISC2. “Certified in Cybersecurity (CC) Exam Outline (effective September 1, 2026).” isc2.org, 2026. ↑
  2. 2.ISC2. “CC — Certified in Cybersecurity.” isc2.org. ↑
  3. 3.National Institute of Standards and Technology. “SP 800-53 Rev. 5: Security and Privacy Controls.” csrc.nist.gov. ↑
Career Employer

Career Employer is the ultimate resource to help you get started working the job of your dreams. We cover topics from general career information, career searching, exam preparation with free study materials, career interviewing, and becoming successful in your career of choice.

Follow Us:

All Posts

Career Employer’s Editorial Process

Here at Career Employer, we focus a lot on providing factually accurate information that is always up to date. We strive to provide correct information using strict editorial processes, article editing, and fact-checking for all of the information found on our website. We only utilize trustworthy and relevant resources. To find out more, make sure to read our full editorial process page here.