Click Study Flashcards above to open the flashcard hub — hundreds of ISC2 CC cards you can flip, match, type, or quiz yourself on. Every card is drawn from the five official ISC2 CC domains, so you study exactly what the exam tests.[1] Pair them with our free practice test and study guide.
ISC2 CC is one of the 9 ISC2 certifications — explore our ISC2 flashcards to compare and prep across the whole family.
ISC2 CC Flashcard Study Modes
Flip mode lets you read a term, think, then check the back at your own pace. Match turns terms and definitions into a timed pairing game. Type shows a definition and asks you to produce the term, so a prompt for a decoy network segment has you spell out DMZ. Quiz builds multiple-choice questions from the same 232 cards.

Why Flashcards Work for the ISC2 CC
Security Principles carries the heaviest official weight (24% under the September 2026 outline) and the largest share of the deck with 61 cards. These drill the vocabulary the rest of the exam leans on: the difference between a Threat and an Asset, how Impact is described, and the card written as Risk = ?. Governance terms such as Policy and Standard show up here too, along with Privacy.
The Network Security deck has 56 cards (networking now falls under Networking and Cloud Security Concepts, 21.3%). Expect protocol and device shorthand you must recall cold, including TCP and UDP, the contrast between IDS and IPS, and older wireless protection like WEP. Perimeter and addressing terms round it out, with cards for DMZ, VPN, and NAT.
The Access Controls Concepts deck has 36 cards (the outline now calls this IAM Concepts, 20%), the smallest set relative to its weight, so treat it as high value per card. You get the AAA model, the split between Identification, Authorization, and Accountability, and physical entry problems such as Tailgating and Piggybacking. Principles like Need-to-know and controls like Account lockout are here as well.
The Security Operations deck has 42 cards (Security Operations and Incident Response is 17.3%). Cryptography terms dominate the front half, with AES, RSA, and Hashing alongside the broader idea of Encryption. Monitoring and hardening appear through SIEM and Baseline, and social engineering shows up in Phishing and Whaling.
The BC, DR & Incident Response deck has 37 cards. The distinctions matter most: an Event versus an Incident, and the card on BC vs. DR. Recovery site cards cover Hot site, Warm site, and Cold site, with supporting terms such as Failover and Redundancy.
The ISC2 CC is dense with terminology — control types, security models, networking concepts, and access frameworks.[3] Spaced flashcards are the most efficient way to keep it all fresh. Used alongside our practice test and study guide, they turn review time into measurable progress.
ISC2 CC Flashcards by Domain
The cards are organized by the five ISC2 CC domains of the outline used before September 1, 2026. The current outline renames and reweights them; cover every deck, but lead with the largest, Security Principles:[1]
| Deck | Closest current domain (weight) |
|---|---|
| Security Principles | Security Principles (24%) |
| Network Security | Networking and Cloud Security Concepts (21.3%) |
| Access Controls Concepts | IAM Concepts (20%) |
| Security Operations | Security Operations and Incident Response (17.3%) |
| BC, DR & Incident Response | Security Operations and Incident Response (17.3%) |
How to Get the Most Out of These Flashcards
- Start with Security Principles. At 24% and 61 cards it is both the heaviest domain and the vocabulary base for everything else, so Flip it end to end before touching other decks.
- Type-drill the definition-sensitive cards. Risk = ? and Need-to-know reward exact recall, and typing them forces you to produce the wording instead of recognizing it in a list.
- Use Match for the acronym clusters. Network Security abbreviations such as IDS, IPS, and NAT pair fast under time pressure and expose the ones you only half know.
- Move to the practice test once Quiz feels easy. When you clear Quiz on all five domains without guessing, switch over to see how the terms behave inside full-length questions.
- Rotate domains in short sittings. With 232 cards, work one domain per session, then re-Flip the previous day’s misses before starting the next, and keep the study guide open for gaps.
ISC2 CC Flashcards FAQ
Hundreds of free ISC2 CC flashcards, organized across all five domains — Security Principles, Business Continuity/Disaster Recovery & Incident Response, Access Controls Concepts, Network Security, and Security Operations. They're free with no account required.
Yes. Flashcards use active recall — retrieving an answer from memory — which research shows is one of the most effective study methods, especially in short, spaced sessions. They're ideal for CC because the exam is heavily definitional: terms, control types, models, and acronyms.
All five ISC2 CC domains: Security Principles (CIA, risk, controls, ethics), BC/DR & Incident Response, Access Controls Concepts (least privilege, DAC/MAC/RBAC, MFA), Network Security (OSI model, threats, firewalls/IDS/IPS), and Security Operations (encryption, hardening, logging, awareness).
Cover all five domains, but lead with the heaviest under the September 2026 outline: Security Principles (24%), Networking and Cloud Security Concepts (21.3%), and Identity and Access Management Concepts (20%). Mix the modes: flip to learn, type to test recall, match for speed, and quiz to check yourself before a full practice test.
Yes — 100% free, all four study modes, no paywall.
Yes. The cards are organized to the current ISC2 CC exam outline effective October 1, 2025, covering all five scored domains in their official proportions.
ISC2 CC flashcard bank
All 232 cards, by topic
A reference copy of every card in this deck. Each answer stays hidden until you choose to show it. To study with Flip, Match, Type and Quiz modes and track what you have mastered, use Study Flashcards at the top of the page.
Security Principles (61)
- CIA triad
Show answerHide answer
Confidentiality, Integrity, Availability — the three core goals of information security.
- Confidentiality
Show answerHide answer
Preventing the unauthorized disclosure of data; protected by encryption and access controls.
- Integrity
Show answerHide answer
Ensuring data is accurate and unaltered except by authorized parties; protected by hashing and change control.
- Availability
Show answerHide answer
Ensuring authorized users have timely, reliable access to systems and data; protected by redundancy and backups.
- DAD triad
Show answerHide answer
Disclosure, Alteration, Destruction — the opposite of CIA, naming the threats to each goal.
- Authentication
Show answerHide answer
Proving a claimed identity with a credential (something you know, have, or are).
- Non-repudiation
Show answerHide answer
Assurance that a party cannot deny having performed an action; provided by digital signatures and logging.
- Privacy
Show answerHide answer
The appropriate collection, use, and protection of personal information.
- Information assurance concepts (CC)
Show answerHide answer
Confidentiality, Integrity, Availability, plus Authentication, Non-repudiation, and Privacy.
- Asset
Show answerHide answer
Anything of value to the organization that needs protection — data, hardware, software, or people.
- Threat
Show answerHide answer
Any potential event or actor that could cause harm by exploiting a vulnerability.
- Vulnerability
Show answerHide answer
A weakness in a system, process, or control that a threat can exploit.
- Risk
Show answerHide answer
The likelihood that a threat will exploit a vulnerability, and the resulting impact on an asset.
- Threat vs. vulnerability vs. risk
Show answerHide answer
Threat = potential cause of harm; vulnerability = weakness it exploits; risk = chance and impact of that happening.
- Likelihood
Show answerHide answer
The probability that a given threat will exploit a given vulnerability.
- Impact
Show answerHide answer
The magnitude of harm if a risk event occurs.
- Risk = ?
Show answerHide answer
A function of likelihood × impact, requiring a threat, a vulnerability, and an asset of value.
- Risk management process
Show answerHide answer
Identify assets/threats/vulnerabilities, assess and prioritize, choose treatment, implement controls, monitor.
- Four risk treatment options
Show answerHide answer
Avoid, Mitigate (reduce), Transfer, Accept.
- Risk avoidance
Show answerHide answer
Eliminating a risk by ceasing the activity that creates it.
- Risk mitigation
Show answerHide answer
Reducing risk to an acceptable level by implementing controls.
- Risk transference
Show answerHide answer
Shifting the financial impact of a risk to a third party, such as through insurance.
- Risk acceptance
Show answerHide answer
A documented, management-approved decision to tolerate a risk and its potential impact.
- Residual risk
Show answerHide answer
The risk that remains after controls are applied; senior management formally accepts it.
- Who owns risk?
Show answerHide answer
Senior management — they own risk and set the tone; security translates business goals into rules.
- Security control
Show answerHide answer
A safeguard that reduces risk to assets; categorized by type and by function.
- Technical (logical) control
Show answerHide answer
A control implemented with technology — firewalls, encryption, antivirus, MFA, access control lists.
- Administrative (managerial) control
Show answerHide answer
Policies, procedures, standards, and training that direct how people behave.
- Physical control
Show answerHide answer
A tangible barrier protecting facilities and hardware — locks, fences, guards, badges, CCTV.
- Three control TYPES
Show answerHide answer
Technical (logical), Administrative (managerial), and Physical.
- Preventive control
Show answerHide answer
Stops an incident before it happens — a lock, a firewall rule, MFA.
- Detective control
Show answerHide answer
Identifies an incident in progress or after the fact — CCTV, IDS, logs, audits.
- Corrective control
Show answerHide answer
Restores systems after an incident — backups, patches, antivirus removal.
- Deterrent control
Show answerHide answer
Discourages an attacker — warning signs, visible guards, lighting.
- Control type vs. function
Show answerHide answer
Type = HOW it's built (technical/admin/physical); function = WHAT it does (preventive/detective/corrective/deterrent).
- Firewall control classification
Show answerHide answer
Technical type, preventive function — it filters traffic by rules before it's allowed in.
- CCTV control classification
Show answerHide answer
Physical type, detective and deterrent function — it records activity and discourages intruders.
- Defense in depth
Show answerHide answer
Layering multiple, overlapping controls so that if one fails, others still protect the asset.
- Governance document hierarchy
Show answerHide answer
Regulation/law → policy → standard → procedure → guideline.
- Policy
Show answerHide answer
A high-level management statement of intent and goals; mandatory.
- Standard
Show answerHide answer
A specific mandatory requirement supporting a policy (e.g., 'use AES-256').
- Procedure
Show answerHide answer
Detailed step-by-step instructions for a task; mandatory.
- Guideline
Show answerHide answer
Recommended, discretionary best practice; the only non-mandatory document.
- Regulation / law
Show answerHide answer
A rule imposed by a government or authority that the organization must obey.
- ISC2 Code of Ethics — # of canons
Show answerHide answer
Four canons, applied in order.
- ISC2 Code of Ethics canon 1
Show answerHide answer
Protect society, the common good, necessary public trust and confidence, and the infrastructure.
- ISC2 Code of Ethics canon 2
Show answerHide answer
Act honorably, honestly, justly, responsibly, and legally.
- ISC2 Code of Ethics canon 3
Show answerHide answer
Provide diligent and competent service to principals.
- ISC2 Code of Ethics canon 4
Show answerHide answer
Advance and protect the profession.
- Conflicting ethics canons — which wins?
Show answerHide answer
The earlier (lower-numbered) canon — protecting society outranks advancing the profession.
- Due care
Show answerHide answer
Acting on due diligence by implementing and maintaining reasonable controls — what a prudent person would do.
- Due diligence
Show answerHide answer
Doing the research and developing the plans/policies needed to protect the organization.
- Defense in depth vs. single control
Show answerHide answer
No single control is a silver bullet; layers force an attacker to defeat several independent defenses.
- Compensating control
Show answerHide answer
An alternative control used when the primary control isn't feasible, providing similar protection.
- Qualitative risk analysis
Show answerHide answer
Ranking risk subjectively as high/medium/low — fast, but not expressed in dollars.
- Quantitative risk analysis
Show answerHide answer
Assigning objective monetary values to risk (e.g., expected annual loss) to cost-justify controls.
- Threat actor
Show answerHide answer
A person or group that carries out a threat — e.g., hacktivists, insiders, nation-states, cybercriminals.
- Insider threat
Show answerHide answer
A risk posed by people inside the organization, whether malicious or careless.
- Asset inventory
Show answerHide answer
A catalog of the organization's assets and their value — the starting point of risk management.
- Security governance
Show answerHide answer
The framework of policies, roles, and oversight by which leadership directs security.
- Prudent person rule
Show answerHide answer
Acting with the care a reasonable, prudent person would in the same situation (due care + due diligence).
BC, DR & Incident Response (37)
- Business continuity (BC)
Show answerHide answer
Keeping critical business functions operating during and after a disruption — the organization-wide plan.
- Disaster recovery (DR)
Show answerHide answer
The IT-focused subset of continuity: restoring systems, data, and infrastructure after a disaster.
- BC vs. DR
Show answerHide answer
BC keeps the whole business running; DR is the IT subset that restores technology.
- Business continuity plan (BCP)
Show answerHide answer
A documented plan to keep critical functions running through a disruption.
- Disaster recovery plan (DRP)
Show answerHide answer
A documented plan to restore IT systems and data after a disruptive event.
- Business Impact Analysis (BIA)
Show answerHide answer
Identifies critical business functions and sets recovery objectives (MTD, RTO, RPO); the heart of continuity.
- Maximum Tolerable Downtime (MTD)
Show answerHide answer
The longest a function can be unavailable before unacceptable harm; sets the ceiling for the RTO.
- Recovery Time Objective (RTO)
Show answerHide answer
The target time to restore a system after a disruption; must be shorter than the MTD.
- Recovery Point Objective (RPO)
Show answerHide answer
The maximum acceptable amount of data loss measured backward in time; drives backup frequency.
- RTO vs. RPO
Show answerHide answer
RTO = time to recover; RPO = data you can afford to lose.
- RTO and MTD relationship
Show answerHide answer
RTO must always be shorter than the MTD.
- Hot site
Show answerHide answer
A fully equipped recovery site with near-real-time failover; fastest recovery, most expensive.
- Warm site
Show answerHide answer
A recovery site with hardware and connectivity; data restored on demand. Moderate cost and speed.
- Cold site
Show answerHide answer
An empty recovery space with power and cooling only; cheapest, slowest to bring online.
- Recovery sites by cost/speed
Show answerHide answer
Hot (fast, costly) → warm → cold (cheap, slow).
- Full backup
Show answerHide answer
Backs up all selected data; fastest to restore (one set), slowest to back up.
- Incremental backup
Show answerHide answer
Backs up changes since the last backup of any type; fast backup, slow restore.
- Differential backup
Show answerHide answer
Backs up changes since the last full backup; slower backup, faster restore.
- 3-2-1 backup rule
Show answerHide answer
Keep three copies of data, on two different media types, with one copy off-site.
- Event
Show answerHide answer
Any observable occurrence on a system or network.
- Incident
Show answerHide answer
An event that actually or potentially harms the confidentiality, integrity, or availability of information.
- Event vs. incident
Show answerHide answer
Every incident is an event, but only some events harm security and become incidents.
- Incident response (IR)
Show answerHide answer
The structured process to prepare for, detect, contain, eradicate, recover from, and learn from an incident.
- Incident response team
Show answerHide answer
A designated group that follows the IR plan to handle security incidents.
- NIST incident response lifecycle
Show answerHide answer
Preparation; Detection & Analysis; Containment, Eradication & Recovery; Post-Incident Activity.
- IR phase: Preparation
Show answerHide answer
Build the IR plan, team, tools, and communications, and train staff — before anything happens.
- IR phase: Detection & Analysis
Show answerHide answer
Recognize and confirm an incident, determine its scope, and prioritize it.
- IR phase: Containment, Eradication & Recovery
Show answerHide answer
Stop the spread, remove the cause, and restore systems to normal operation.
- IR phase: Post-Incident Activity
Show answerHide answer
Hold a lessons-learned review and improve the plan and controls.
- First step during an active incident
Show answerHide answer
Containment — limit the damage before eradicating the cause.
- Lessons learned
Show answerHide answer
The post-incident review that documents what happened and improves future response.
- Tabletop exercise
Show answerHide answer
A discussion-based walkthrough of the incident or continuity plan to test it without disrupting operations.
- Failover
Show answerHide answer
Automatically switching to a standby system or site when the primary fails.
- Redundancy
Show answerHide answer
Duplicating critical components so a single failure doesn't cause an outage (supports availability).
- Why test the BCP/DRP?
Show answerHide answer
Untested plans fail in a real disaster; testing finds gaps and trains the team before it matters.
- Business continuity vs. incident response
Show answerHide answer
BC keeps the business running through disruption; IR handles a specific security incident.
- Root cause analysis
Show answerHide answer
Determining the underlying cause of an incident so it can be fixed and prevented from recurring.
Access Controls Concepts (36)
- Least privilege
Show answerHide answer
Granting users and processes only the minimum access needed to do their job, and nothing more.
- Need-to-know
Show answerHide answer
Limiting access to the specific information required to perform a task.
- Segregation (separation) of duties
Show answerHide answer
Splitting a sensitive task so no single person can complete it alone, reducing fraud and error.
- AAA model
Show answerHide answer
Authentication, Authorization, and Accountability.
- Access control sequence
Show answerHide answer
Identification → Authentication → Authorization → Accountability.
- Identification
Show answerHide answer
A subject claiming an identity, such as entering a username — the first step of access control.
- Authorization
Show answerHide answer
Determining what an authenticated identity is permitted to access and do.
- Accountability
Show answerHide answer
Tying actions back to a specific identity through logging and monitoring.
- Multi-factor authentication (MFA)
Show answerHide answer
Using two or more factors from different categories — something you know, have, and are.
- Something you know
Show answerHide answer
A knowledge authentication factor — password, PIN, or passphrase.
- Something you have
Show answerHide answer
A possession authentication factor — smart card, hardware token, or phone.
- Something you are
Show answerHide answer
An inherence (biometric) authentication factor — fingerprint, iris, or face.
- Is password + security question MFA?
Show answerHide answer
No — both are 'something you know,' so it's single-factor. MFA requires different categories.
- Discretionary access control (DAC)
Show answerHide answer
Access decided by the data owner, e.g., file permissions and ACLs. Flexible but error-prone.
- Mandatory access control (MAC)
Show answerHide answer
Access enforced by the system from labels and clearances; the most restrictive, used for classified data.
- Role-based access control (RBAC)
Show answerHide answer
Access granted by job role rather than the individual; scales well in organizations.
- DAC vs. MAC vs. RBAC
Show answerHide answer
DAC = owner decides; MAC = system enforces from labels; RBAC = by job role.
- Most restrictive access model
Show answerHide answer
Mandatory Access Control (MAC) — the system, not the owner, decides based on labels and clearances.
- Access control model for scalable provisioning
Show answerHide answer
RBAC — assign access by role so staff inherit and lose permissions as their role changes.
- Physical access control
Show answerHide answer
A tangible control protecting facilities and hardware — locks, badges, guards, CCTV.
- Mantrap (access control vestibule)
Show answerHide answer
A two-door airlock allowing one person per authentication; stops tailgating.
- Tailgating
Show answerHide answer
Following an authorized person through a secure door without authenticating.
- Piggybacking
Show answerHide answer
Being let through a secure door by an authorized person (with their awareness).
- Biometric authentication
Show answerHide answer
Verifying identity from a physical trait — fingerprint, iris, face, or voice.
- False acceptance rate (FAR)
Show answerHide answer
How often a biometric system wrongly accepts an unauthorized user (a Type II error).
- False rejection rate (FRR)
Show answerHide answer
How often a biometric system wrongly rejects an authorized user (a Type I error).
- Single sign-on (SSO)
Show answerHide answer
One authentication that grants access to multiple systems.
- Privileged account
Show answerHide answer
An account with elevated rights (e.g., administrator) that needs extra protection and monitoring.
- Provisioning / deprovisioning
Show answerHide answer
Granting access when a user joins or changes roles, and removing it promptly when they leave.
- Logical (technical) access control
Show answerHide answer
Technology-based control of access to systems and data — passwords, MFA, ACLs, encryption.
- Authentication vs. authorization
Show answerHide answer
Authentication proves who you are; authorization decides what you're allowed to do.
- Token (authentication)
Show answerHide answer
A possession factor that generates or stores a credential (e.g., a one-time code).
- Type I vs. Type II biometric error
Show answerHide answer
Type I = false rejection (authorized user denied); Type II = false acceptance (impostor allowed).
- Account lockout
Show answerHide answer
Disabling an account after repeated failed logins to slow password-guessing attacks.
- Just-in-time access
Show answerHide answer
Granting elevated privileges only when needed and for a limited time, reducing standing access.
- Physical vs. logical access control
Show answerHide answer
Physical protects facilities and hardware; logical protects systems and data via technology.
Network Security (56)
- OSI model
Show answerHide answer
A seven-layer reference model: Physical, Data Link, Network, Transport, Session, Presentation, Application.
- OSI layer 1
Show answerHide answer
Physical — cables, signals, and hardware; hubs.
- OSI layer 2
Show answerHide answer
Data Link — MAC addresses, switches, and frames.
- OSI layer 3
Show answerHide answer
Network — IP addressing and routing; routers; IPsec.
- OSI layer 4
Show answerHide answer
Transport — TCP and UDP; port numbers.
- OSI layer 5
Show answerHide answer
Session — setting up, managing, and tearing down sessions.
- OSI layer 6
Show answerHide answer
Presentation — encryption, encoding, and formatting.
- OSI layer 7
Show answerHide answer
Application — the data the user interacts with (HTTP, DNS, SMTP).
- OSI mnemonic (Layer 1→7)
Show answerHide answer
Please Do Not Throw Sausage Pizza Away.
- Switch — OSI layer
Show answerHide answer
Layer 2 (Data Link) — forwards frames by MAC address.
- Router — OSI layer
Show answerHide answer
Layer 3 (Network) — forwards packets by IP address.
- TCP/IP model
Show answerHide answer
A four-layer practical model: Network Access, Internet, Transport, and Application.
- TCP
Show answerHide answer
Transmission Control Protocol — connection-oriented, reliable, ordered delivery (Layer 4).
- UDP
Show answerHide answer
User Datagram Protocol — connectionless, fast, but unreliable (Layer 4).
- TCP vs. UDP
Show answerHide answer
TCP is reliable and connection-oriented; UDP is fast and connectionless.
- IPv4
Show answerHide answer
32-bit IP addressing (about 4.3 billion addresses) — running out.
- IPv6
Show answerHide answer
128-bit IP addressing — vastly more addresses than IPv4.
- Port 22
Show answerHide answer
SSH — secure remote administration.
- Port 53
Show answerHide answer
DNS — domain name resolution.
- Port 80
Show answerHide answer
HTTP — unencrypted web traffic.
- Port 443
Show answerHide answer
HTTPS (TLS) — encrypted web traffic.
- Port 3389
Show answerHide answer
RDP — Remote Desktop Protocol.
- WPA3
Show answerHide answer
The current secure WiFi encryption standard; use it instead of legacy WEP.
- WEP
Show answerHide answer
An obsolete, insecure WiFi encryption standard that should never be used.
- Malware
Show answerHide answer
Malicious software — viruses, worms, trojans, ransomware, spyware.
- Virus
Show answerHide answer
Malware that attaches to a host file and spreads when a user runs it.
- Worm
Show answerHide answer
Malware that self-replicates across networks with no user action.
- Trojan
Show answerHide answer
Malware disguised as legitimate software to trick the user into installing it.
- Ransomware
Show answerHide answer
Malware that encrypts data and demands payment for the decryption key.
- Spyware
Show answerHide answer
Malware that secretly gathers information about a user or system.
- DoS attack
Show answerHide answer
A Denial-of-Service attack that floods a system from one source to make it unavailable.
- DDoS attack
Show answerHide answer
A Distributed Denial-of-Service attack launched from many compromised machines (a botnet) at once.
- DoS vs. DDoS
Show answerHide answer
DoS floods from one source; DDoS floods from many distributed sources, making it harder to block.
- On-path (man-in-the-middle) attack
Show answerHide answer
Intercepting and possibly altering traffic between two communicating parties.
- Side-channel attack
Show answerHide answer
Extracting information through physical signals such as power use, timing, or electromagnetic leaks.
- Firewall
Show answerHide answer
A control that filters network traffic, allowing or blocking it based on a defined ruleset.
- IDS
Show answerHide answer
Intrusion Detection System — monitors traffic and alerts on suspicious activity but does not block it.
- IPS
Show answerHide answer
Intrusion Prevention System — detects and actively blocks malicious traffic.
- IDS vs. IPS
Show answerHide answer
IDS detects and alerts only; IPS detects and blocks.
- VLAN
Show answerHide answer
A virtual LAN that logically segments a network to isolate traffic.
- Network segmentation
Show answerHide answer
Dividing a network into zones to limit the spread of an attack and control traffic.
- DMZ
Show answerHide answer
A screened subnet that exposes public-facing services while shielding the internal network.
- VPN
Show answerHide answer
A Virtual Private Network — an encrypted tunnel that secures traffic across an untrusted network.
- Zero trust
Show answerHide answer
A model that trusts no user or device by default and continuously verifies every access request.
- SaaS
Show answerHide answer
Software as a Service — the provider delivers ready-to-use applications over the internet.
- PaaS
Show answerHide answer
Platform as a Service — the provider delivers a platform to build and run applications.
- IaaS
Show answerHide answer
Infrastructure as a Service — the provider delivers virtualized compute, storage, and networking.
- Cloud shared responsibility model
Show answerHide answer
The provider secures the cloud itself; the customer secures their data, access, and configuration.
- Botnet
Show answerHide answer
A network of compromised machines controlled by an attacker, often used for DDoS.
- NAT
Show answerHide answer
Network Address Translation — maps private internal IPs to a public IP, hiding internal addressing.
- Proxy server
Show answerHide answer
An intermediary that forwards and can filter or cache traffic between clients and servers.
- Network segmentation benefit
Show answerHide answer
Limits the blast radius of an attack and contains threats to one zone.
- Spoofing
Show answerHide answer
Faking a source identity such as an IP or email address to bypass controls or deceive a target.
- Sniffing
Show answerHide answer
Capturing network traffic to read data, especially when it's unencrypted.
- TLS
Show answerHide answer
Transport Layer Security — encrypts traffic in transit (the 'S' in HTTPS).
- MAC address
Show answerHide answer
A hardware address that identifies a device on a local network (used at OSI Layer 2).
Security Operations (42)
- Data at rest
Show answerHide answer
Data stored on a disk or in a database; protected with full-disk or database encryption.
- Data in transit
Show answerHide answer
Data moving across a network; protected with TLS, IPsec, or a VPN.
- Data in use
Show answerHide answer
Data decrypted in memory while being processed — the hardest state to protect.
- Three data states
Show answerHide answer
At rest (stored), in transit (moving), and in use (being processed).
- Encryption
Show answerHide answer
Converting data into an unreadable form so only authorized parties with the key can read it.
- Symmetric encryption
Show answerHide answer
Uses one shared secret key for both encrypting and decrypting (e.g., AES); fast but key distribution is hard.
- Asymmetric encryption
Show answerHide answer
Uses a public/private key pair (e.g., RSA); slower, but solves key exchange and enables signatures.
- Symmetric vs. asymmetric
Show answerHide answer
Symmetric = one shared key, fast; asymmetric = key pair, slower, solves key exchange.
- AES
Show answerHide answer
Advanced Encryption Standard — the widely used symmetric encryption algorithm.
- RSA
Show answerHide answer
A widely used asymmetric (public-key) encryption and digital-signature algorithm.
- Hashing
Show answerHide answer
A one-way function producing a fixed-length digest used to verify integrity (e.g., SHA-256).
- Encryption vs. hashing
Show answerHide answer
Encryption is reversible with a key (confidentiality); hashing is one-way (integrity).
- Digital signature
Show answerHide answer
A hash encrypted with the sender's private key, giving integrity, authenticity, and non-repudiation.
- Public/private key — encrypt vs. sign
Show answerHide answer
Encrypt for confidentiality with the recipient's public key; sign for authenticity with your own private key.
- Data classification
Show answerHide answer
Labeling data by sensitivity (public, internal, confidential, restricted) so the right protection applies.
- Logging and monitoring
Show answerHide answer
Recording and reviewing system activity to detect, investigate, and respond to problems.
- SIEM
Show answerHide answer
Security Information and Event Management — centralizes and correlates logs for detection and analysis.
- System hardening
Show answerHide answer
Reducing a system's attack surface — remove unneeded services, close ports, disable defaults, patch.
- Baseline
Show answerHide answer
A minimum required level of secure configuration to harden a system toward.
- Configuration management
Show answerHide answer
Recording, controlling, and approving changes to system settings to keep a known-good state.
- Change management
Show answerHide answer
A controlled process for evaluating, testing, approving, and documenting changes to systems.
- Patch management
Show answerHide answer
Applying vendor updates promptly to close known vulnerabilities.
- Acceptable use policy (AUP)
Show answerHide answer
A policy defining how employees may use organizational systems and data.
- BYOD policy
Show answerHide answer
Rules governing the use of personal devices for work to protect organizational data.
- Password policy
Show answerHide answer
Rules for password length, complexity, rotation, and reuse to strengthen authentication.
- Data handling policy
Show answerHide answer
Rules for how data is stored, transmitted, shared, retained, and destroyed by classification.
- Social engineering
Show answerHide answer
Manipulating people into divulging information or taking actions that compromise security.
- Phishing
Show answerHide answer
A social-engineering attack using fraudulent messages to trick users into revealing credentials or installing malware.
- Spear phishing
Show answerHide answer
A targeted phishing attack aimed at a specific person or organization using personalized details.
- Whaling
Show answerHide answer
Phishing that targets high-value executives such as a CEO or CFO.
- Vishing / smishing
Show answerHide answer
Social engineering by voice call (vishing) or SMS text (smishing).
- Security awareness training
Show answerHide answer
Educating users to recognize and avoid threats such as phishing and social engineering.
- Best defense against phishing
Show answerHide answer
Security awareness training, backed by email filtering and MFA so stolen credentials alone aren't enough.
- Data destruction / sanitization
Show answerHide answer
Removing data so it can't be recovered — overwriting, degaussing, or physical destruction.
- Principle: least functionality
Show answerHide answer
Configure systems to provide only essential capabilities, disabling unneeded ports, services, and software.
- Logging — why it matters
Show answerHide answer
You can't detect or investigate what you can't see; logs provide accountability and detection.
- Default deny
Show answerHide answer
Blocking everything by default and allowing only what's explicitly permitted.
- Separation of duties (ops)
Show answerHide answer
No single person controls a critical operational task end to end, reducing fraud.
- Data retention policy
Show answerHide answer
Rules for how long data is kept and when it's securely destroyed.
- Endpoint protection
Show answerHide answer
Security controls on devices — antivirus/EDR, hardening, patching, encryption.
- Vulnerability management
Show answerHide answer
The ongoing process of identifying, prioritizing, and remediating weaknesses.
- Principle of least privilege (ops)
Show answerHide answer
Run services and grant accounts only the minimum rights needed, limiting damage from compromise.
References
- 1.ISC2. “Certified in Cybersecurity (CC) Exam Outline (effective September 1, 2026).” isc2.org, 2026. ↑
- 2.ISC2. “CC — Certified in Cybersecurity.” isc2.org. ↑
- 3.National Institute of Standards and Technology. “SP 800-53 Rev. 5: Security and Privacy Controls.” csrc.nist.gov. ↑

Career Employer
Career Employer is the ultimate resource to help you get started working the job of your dreams. We cover topics from general career information, career searching, exam preparation with free study materials, career interviewing, and becoming successful in your career of choice.
All PostsCareer Employer’s Editorial Process
Here at Career Employer, we focus a lot on providing factually accurate information that is always up to date. We strive to provide correct information using strict editorial processes, article editing, and fact-checking for all of the information found on our website. We only utilize trustworthy and relevant resources. To find out more, make sure to read our full editorial process page here.
