Skip to content
Oluma Cyber Security Awareness
🔒
OLUMA CERTIFICATION ZONE

CCPractice Range

100 original scenarios across the five CC domains — security principles, business continuity, access controls, network security and security operations. ISC2’s entry-level credential, and the perfect first step into cybersecurity. Pick your range and get started.

START HERE
How do you want us to call you?
Enter a name to unlock the practice range — we’ll keep it friendly from here on.
🔒 Practice range locked — enter a name above to begin
✔ You’re in, learner — scroll on when you’re ready
About the Certification

What is ISC2 CC?

Certified in Cybersecurity (CC) is ISC2’s entry-level credential — built from scratch to help newcomers, students, and career changers prove they understand core cybersecurity concepts well enough to be trusted in a real role. It’s the rare certification with no work-experience requirement, and through its “One Million Certified in Cybersecurity” initiative, ISC2 has offered free training and exam vouchers to over a million people.

It’s an ideal first certification if you’re breaking into cybersecurity (like much of the Oluma community), moving over from general IT, or building toward larger ISC2 credentials like the SSCP and CISSP down the line.

🖥️SOC Analyst (Tier 1)Monitor alerts and triage security events.
🔎Junior Security AnalystLearn to investigate and support defenses.
🧰IT Support (Security)Bring security into everyday IT work.
🛠️Cybersecurity TechnicianHands-on with the fundamentals of defense.
ProviderISC2
Format100–125 items
Time120 minutes
Passing Score700 / 1000
Exam Objectives

The five domains

CC covers five entry-level domains. Security Principles is the heavyweight at 26%, with Network Security (24%) and Access Controls (22%) close behind — those three are nearly three-quarters of the exam. These practice questions are grouped by the same five areas.

1 · Security Principles
CIA triad, AAA, risk, controls, governance docs and the ISC2 Code of Ethics.
26%
2 · BC, DR & Incident Response
Business continuity, disaster recovery, and the incident response lifecycle.
10%
3 · Access Controls Concepts
Identification, authentication factors, access models, and physical access.
22%
4 · Network Security
Firewalls, VPNs, ports, protocols, common attacks and network defenses.
24%
5 · Security Operations
Data handling, encryption, hardening, patching, and everyday operations.
18%
Official Resources

Go straight to the source

Bookmark the official ISC2 pages for authoritative details on the exam, free training, and the full domain blueprint. These open in a new tab.

Before You Start

Set yourself up to pass

CC is entry-level, but it rewards clear fundamentals over memorized trivia. A few habits make it click.

1Weight your study

Security Principles (26%), Network Security (24%) and Access Controls (22%) are nearly three-quarters of the exam. Start there.

2Learn the CIA triad

Confidentiality, Integrity and Availability underpin everything. Know each one and how controls protect it.

3Know your access terms

Identification, authentication, authorization, accountability — plus the three factors (know, have, are). CC leans hard on these.

4Get governance straight

Policy, standard, procedure and guideline — CC asks many short scenarios testing the difference.

5Think in scenarios

Most questions describe a situation and ask the BEST answer. Reason from the concept, not a memorized line.

6Don’t fear the CAT

The exam is adaptive now — questions adjust to your answers and you can’t go back. Pace steadily, commit, and move on.

Security PrinciplesBC / DR / IRAccess ControlsNetwork SecuritySecurity Operations
SELECT YOUR RANGE
1/100 Security Principles

Keeping sensitive data from being disclosed to unauthorized people protects which part of the CIA triad?

✔ ACCESS GRANTED

That’s foundation-solid — clean and correct.

Confidentiality ensures information is disclosed only to authorized parties.

✖ ACCESS DENIED

No stress — here’s the fix:

Confidentiality ensures information is disclosed only to authorized parties.

✖ ACCESS DENIED

No stress — here’s the fix:

Confidentiality ensures information is disclosed only to authorized parties.

✖ ACCESS DENIED

No stress — here’s the fix:

Confidentiality ensures information is disclosed only to authorized parties.

2/100 Security Principles

Ensuring that data has not been altered or tampered with protects which principle?

✖ THREAT DETECTED

Every miss is a lesson. Takeaway:

Integrity ensures data remains accurate and unaltered.

✖ THREAT DETECTED

Every miss is a lesson. Takeaway:

Integrity ensures data remains accurate and unaltered.

✖ THREAT DETECTED

Every miss is a lesson. Takeaway:

Integrity ensures data remains accurate and unaltered.

✔ THREAT NEUTRALIZED

Sharp. You’re thinking like a defender.

Integrity ensures data remains accurate and unaltered.

3/100 Security Principles

A ransomware attack that locks users out of critical files most directly harms which principle?

✖ ALERT RAISED

Reset and lock it in with this:

Availability ensures authorized users can access systems and data when they need them.

✖ ALERT RAISED

Reset and lock it in with this:

Availability ensures authorized users can access systems and data when they need them.

✔ IDENTITY VERIFIED

You’ve got the principle down. Textbook.

Availability ensures authorized users can access systems and data when they need them.

✖ ALERT RAISED

Reset and lock it in with this:

Availability ensures authorized users can access systems and data when they need them.

4/100 Security Principles

A user proves who they are by entering a password. This step is:

✖ CHECK FAILED

Patch your thinking with this:

Authentication verifies identity; authorization then decides what that identity may do.

✔ CONTROL VALIDATED

Locked in — that’s the CC mindset.

Authentication verifies identity; authorization then decides what that identity may do.

✖ CHECK FAILED

Patch your thinking with this:

Authentication verifies identity; authorization then decides what that identity may do.

✖ CHECK FAILED

Patch your thinking with this:

Authentication verifies identity; authorization then decides what that identity may do.

5/100 Security Principles

After logging in, the system checks whether the user is allowed to open a payroll file. This step is:

✔ RISK MITIGATED

Verified. Oluma loves to see it.

Authorization determines what an authenticated identity is permitted to access or do.

✖ FLAGGED FOR REVIEW

No stress — here’s the fix:

Authorization determines what an authenticated identity is permitted to access or do.

✖ FLAGGED FOR REVIEW

No stress — here’s the fix:

Authorization determines what an authenticated identity is permitted to access or do.

✖ FLAGGED FOR REVIEW

No stress — here’s the fix:

Authorization determines what an authenticated identity is permitted to access or do.

6/100 Security Principles

A digital signature ensures a sender cannot later deny sending a message. This property is:

✖ ACCESS DENIED

Every miss is a lesson. Takeaway:

Non-repudiation prevents a party from credibly denying an action they took.

✖ ACCESS DENIED

Every miss is a lesson. Takeaway:

Non-repudiation prevents a party from credibly denying an action they took.

✖ ACCESS DENIED

Every miss is a lesson. Takeaway:

Non-repudiation prevents a party from credibly denying an action they took.

✔ POLICY ENFORCED

Nicely done — that’s a keeper.

Non-repudiation prevents a party from credibly denying an action they took.

7/100 Security Principles

An unpatched flaw in software that could be exploited is best described as a:

✖ THREAT DETECTED

Reset and lock it in with this:

A vulnerability is a weakness; a threat is something that could exploit it.

✖ THREAT DETECTED

Reset and lock it in with this:

A vulnerability is a weakness; a threat is something that could exploit it.

✔ INTEGRITY CONFIRMED

That’s foundation-solid — clean and correct.

A vulnerability is a weakness; a threat is something that could exploit it.

✖ THREAT DETECTED

Reset and lock it in with this:

A vulnerability is a weakness; a threat is something that could exploit it.

8/100 Security Principles

A hacker who wants to steal an organization’s data is an example of a:

✖ ALERT RAISED

Patch your thinking with this:

A threat is a potential danger or actor that could exploit a vulnerability.

✔ SECURED

Sharp. You’re thinking like a defender.

A threat is a potential danger or actor that could exploit a vulnerability.

✖ ALERT RAISED

Patch your thinking with this:

A threat is a potential danger or actor that could exploit a vulnerability.

✖ ALERT RAISED

Patch your thinking with this:

A threat is a potential danger or actor that could exploit a vulnerability.

9/100 Security Principles

Risk is best described as the combination of:

✔ VERIFIED

You’ve got the principle down. Textbook.

Risk combines the likelihood and the impact of a threat exploiting a vulnerability.

✖ CHECK FAILED

No stress — here’s the fix:

Risk combines the likelihood and the impact of a threat exploiting a vulnerability.

✖ CHECK FAILED

No stress — here’s the fix:

Risk combines the likelihood and the impact of a threat exploiting a vulnerability.

✖ CHECK FAILED

No stress — here’s the fix:

Risk combines the likelihood and the impact of a threat exploiting a vulnerability.

10/100 Security Principles

Management decides a small risk isn’t worth the cost to fix and formally takes no action. This is risk:

✖ FLAGGED FOR REVIEW

Every miss is a lesson. Takeaway:

Risk acceptance means acknowledging a risk and choosing to take no further action on it.

✖ FLAGGED FOR REVIEW

Every miss is a lesson. Takeaway:

Risk acceptance means acknowledging a risk and choosing to take no further action on it.

✖ FLAGGED FOR REVIEW

Every miss is a lesson. Takeaway:

Risk acceptance means acknowledging a risk and choosing to take no further action on it.

✔ DEFENSE HELD

Locked in — that’s the CC mindset.

Risk acceptance means acknowledging a risk and choosing to take no further action on it.

CHECKPOINT — 10 DOWN, STAY SHARP
11/100 Security Principles

Buying cyber insurance to cover the cost of a possible breach is risk:

✖ ACCESS DENIED

Reset and lock it in with this:

Transference shifts the financial impact of a risk to a third party, such as an insurer.

✖ ACCESS DENIED

Reset and lock it in with this:

Transference shifts the financial impact of a risk to a third party, such as an insurer.

✔ ACCESS GRANTED

Verified. Oluma loves to see it.

Transference shifts the financial impact of a risk to a third party, such as an insurer.

✖ ACCESS DENIED

Reset and lock it in with this:

Transference shifts the financial impact of a risk to a third party, such as an insurer.

12/100 Security Principles

Installing a firewall to reduce the chance an attack succeeds is risk:

✖ THREAT DETECTED

Patch your thinking with this:

Mitigation reduces the likelihood or impact of a risk by applying controls.

✔ THREAT NEUTRALIZED

Nicely done — that’s a keeper.

Mitigation reduces the likelihood or impact of a risk by applying controls.

✖ THREAT DETECTED

Patch your thinking with this:

Mitigation reduces the likelihood or impact of a risk by applying controls.

✖ THREAT DETECTED

Patch your thinking with this:

Mitigation reduces the likelihood or impact of a risk by applying controls.

13/100 Security Principles

A company decides not to launch a risky new feature at all, eliminating its risk. This is risk:

✔ IDENTITY VERIFIED

That’s foundation-solid — clean and correct.

Avoidance eliminates a risk by choosing not to engage in the activity that creates it.

✖ ALERT RAISED

No stress — here’s the fix:

Avoidance eliminates a risk by choosing not to engage in the activity that creates it.

✖ ALERT RAISED

No stress — here’s the fix:

Avoidance eliminates a risk by choosing not to engage in the activity that creates it.

✖ ALERT RAISED

No stress — here’s the fix:

Avoidance eliminates a risk by choosing not to engage in the activity that creates it.

14/100 Security Principles

A locked door and a security guard are examples of which type of control?

✖ CHECK FAILED

Every miss is a lesson. Takeaway:

Physical controls protect facilities and hardware — locks, guards, fences, and the like.

✖ CHECK FAILED

Every miss is a lesson. Takeaway:

Physical controls protect facilities and hardware — locks, guards, fences, and the like.

✖ CHECK FAILED

Every miss is a lesson. Takeaway:

Physical controls protect facilities and hardware — locks, guards, fences, and the like.

✔ CONTROL VALIDATED

Sharp. You’re thinking like a defender.

Physical controls protect facilities and hardware — locks, guards, fences, and the like.

15/100 Security Principles

A firewall and antivirus software are examples of which type of control?

✖ FLAGGED FOR REVIEW

Reset and lock it in with this:

Technical/logical controls are implemented through technology.

✖ FLAGGED FOR REVIEW

Reset and lock it in with this:

Technical/logical controls are implemented through technology.

✔ RISK MITIGATED

You’ve got the principle down. Textbook.

Technical/logical controls are implemented through technology.

✖ FLAGGED FOR REVIEW

Reset and lock it in with this:

Technical/logical controls are implemented through technology.

16/100 Security Principles

A security awareness training requirement written into company policy is which type of control?

✖ ACCESS DENIED

Patch your thinking with this:

Administrative controls are the policies, procedures, and training that direct behavior.

✔ POLICY ENFORCED

Locked in — that’s the CC mindset.

Administrative controls are the policies, procedures, and training that direct behavior.

✖ ACCESS DENIED

Patch your thinking with this:

Administrative controls are the policies, procedures, and training that direct behavior.

✖ ACCESS DENIED

Patch your thinking with this:

Administrative controls are the policies, procedures, and training that direct behavior.

17/100 Security Principles

Layering multiple security controls so that one failure doesn’t expose everything is called:

✔ INTEGRITY CONFIRMED

Verified. Oluma loves to see it.

Defense in depth uses multiple overlapping layers of controls.

✖ THREAT DETECTED

No stress — here’s the fix:

Defense in depth uses multiple overlapping layers of controls.

✖ THREAT DETECTED

No stress — here’s the fix:

Defense in depth uses multiple overlapping layers of controls.

✖ THREAT DETECTED

No stress — here’s the fix:

Defense in depth uses multiple overlapping layers of controls.

18/100 Security Principles

Giving a user only the access they need to do their job — and no more — is the principle of:

✖ ALERT RAISED

Every miss is a lesson. Takeaway:

Least privilege limits access to the minimum necessary for the role or task.

✖ ALERT RAISED

Every miss is a lesson. Takeaway:

Least privilege limits access to the minimum necessary for the role or task.

✖ ALERT RAISED

Every miss is a lesson. Takeaway:

Least privilege limits access to the minimum necessary for the role or task.

✔ SECURED

Nicely done — that’s a keeper.

Least privilege limits access to the minimum necessary for the role or task.

19/100 Security Principles

As an ISC2 member, the Code of Ethics primarily obligates you to:

✖ CHECK FAILED

Reset and lock it in with this:

The ISC2 Code of Ethics requires acting honestly and honorably and protecting society, the common good, and the profession.

✖ CHECK FAILED

Reset and lock it in with this:

The ISC2 Code of Ethics requires acting honestly and honorably and protecting society, the common good, and the profession.

✔ VERIFIED

That’s foundation-solid — clean and correct.

The ISC2 Code of Ethics requires acting honestly and honorably and protecting society, the common good, and the profession.

✖ CHECK FAILED

Reset and lock it in with this:

The ISC2 Code of Ethics requires acting honestly and honorably and protecting society, the common good, and the profession.

20/100 Security Principles

A step-by-step set of instructions for resetting a password is best classified as a:

✖ FLAGGED FOR REVIEW

Patch your thinking with this:

A procedure gives detailed steps; a policy states intent, a standard sets mandatory rules, and a guideline recommends.

✔ DEFENSE HELD

Sharp. You’re thinking like a defender.

A procedure gives detailed steps; a policy states intent, a standard sets mandatory rules, and a guideline recommends.

✖ FLAGGED FOR REVIEW

Patch your thinking with this:

A procedure gives detailed steps; a policy states intent, a standard sets mandatory rules, and a guideline recommends.

✖ FLAGGED FOR REVIEW

Patch your thinking with this:

A procedure gives detailed steps; a policy states intent, a standard sets mandatory rules, and a guideline recommends.

CHECKPOINT — 20 DOWN, STAY SHARP
21/100 Security Principles

A mandatory rule that all company passwords must be at least 12 characters is a:

✔ ACCESS GRANTED

You’ve got the principle down. Textbook.

A standard is a mandatory, specific requirement that supports a policy.

✖ ACCESS DENIED

No stress — here’s the fix:

A standard is a mandatory, specific requirement that supports a policy.

✖ ACCESS DENIED

No stress — here’s the fix:

A standard is a mandatory, specific requirement that supports a policy.

✖ ACCESS DENIED

No stress — here’s the fix:

A standard is a mandatory, specific requirement that supports a policy.

22/100 Security Principles

A recommended but optional suggestion to use a password manager is a:

✖ THREAT DETECTED

Every miss is a lesson. Takeaway:

A guideline is a recommendation, not a mandatory rule.

✖ THREAT DETECTED

Every miss is a lesson. Takeaway:

A guideline is a recommendation, not a mandatory rule.

✖ THREAT DETECTED

Every miss is a lesson. Takeaway:

A guideline is a recommendation, not a mandatory rule.

✔ THREAT NEUTRALIZED

Locked in — that’s the CC mindset.

A guideline is a recommendation, not a mandatory rule.

23/100 Security Principles

Requiring both a password and a one-time code from a phone app to log in is an example of:

✖ ALERT RAISED

Reset and lock it in with this:

MFA combines two or more different types of authentication factors.

✖ ALERT RAISED

Reset and lock it in with this:

MFA combines two or more different types of authentication factors.

✔ IDENTITY VERIFIED

Verified. Oluma loves to see it.

MFA combines two or more different types of authentication factors.

✖ ALERT RAISED

Reset and lock it in with this:

MFA combines two or more different types of authentication factors.

24/100 Security Principles

To verify a downloaded file wasn’t altered, you compare its hash to the original’s. Hashing primarily supports:

✖ CHECK FAILED

Patch your thinking with this:

Hashing detects any change to data, which supports integrity.

✔ CONTROL VALIDATED

Nicely done — that’s a keeper.

Hashing detects any change to data, which supports integrity.

✖ CHECK FAILED

Patch your thinking with this:

Hashing detects any change to data, which supports integrity.

✖ CHECK FAILED

Patch your thinking with this:

Hashing detects any change to data, which supports integrity.

25/100 Security Principles

A person’s name combined with their Social Security number is an example of:

✔ RISK MITIGATED

That’s foundation-solid — clean and correct.

PII is information that can identify a specific individual.

✖ FLAGGED FOR REVIEW

No stress — here’s the fix:

PII is information that can identify a specific individual.

✖ FLAGGED FOR REVIEW

No stress — here’s the fix:

PII is information that can identify a specific individual.

✖ FLAGGED FOR REVIEW

No stress — here’s the fix:

PII is information that can identify a specific individual.

26/100 Security Principles

Regularly patching systems and monitoring for threats — doing what a reasonable organization would — demonstrates:

✖ ACCESS DENIED

Every miss is a lesson. Takeaway:

Due care is taking reasonable steps to protect assets; due diligence is the ongoing effort to ensure they work.

✖ ACCESS DENIED

Every miss is a lesson. Takeaway:

Due care is taking reasonable steps to protect assets; due diligence is the ongoing effort to ensure they work.

✖ ACCESS DENIED

Every miss is a lesson. Takeaway:

Due care is taking reasonable steps to protect assets; due diligence is the ongoing effort to ensure they work.

✔ POLICY ENFORCED

Sharp. You’re thinking like a defender.

Due care is taking reasonable steps to protect assets; due diligence is the ongoing effort to ensure they work.

27/100 BC / DR / IR

A plan that keeps critical business functions running during and after a disruption is a:

✖ THREAT DETECTED

Reset and lock it in with this:

A BCP keeps essential business operations running through a disruption.

✖ THREAT DETECTED

Reset and lock it in with this:

A BCP keeps essential business operations running through a disruption.

✔ INTEGRITY CONFIRMED

You’ve got the principle down. Textbook.

A BCP keeps essential business operations running through a disruption.

✖ THREAT DETECTED

Reset and lock it in with this:

A BCP keeps essential business operations running through a disruption.

28/100 BC / DR / IR

A plan focused specifically on restoring IT systems and data after a disaster is a:

✖ ALERT RAISED

Patch your thinking with this:

A DRP focuses on recovering IT systems and data after a disaster.

✔ SECURED

Locked in — that’s the CC mindset.

A DRP focuses on recovering IT systems and data after a disaster.

✖ ALERT RAISED

Patch your thinking with this:

A DRP focuses on recovering IT systems and data after a disaster.

✖ ALERT RAISED

Patch your thinking with this:

A DRP focuses on recovering IT systems and data after a disaster.

29/100 BC / DR / IR

In incident response, isolating an infected computer from the network to stop the spread is part of which phase?

✔ VERIFIED

Verified. Oluma loves to see it.

Containment limits the damage and stops an incident from spreading further.

✖ CHECK FAILED

No stress — here’s the fix:

Containment limits the damage and stops an incident from spreading further.

✖ CHECK FAILED

No stress — here’s the fix:

Containment limits the damage and stops an incident from spreading further.

✖ CHECK FAILED

No stress — here’s the fix:

Containment limits the damage and stops an incident from spreading further.

30/100 BC / DR / IR

A security incident is best described as:

✖ FLAGGED FOR REVIEW

Every miss is a lesson. Takeaway:

An incident actually or potentially harms security; not every event is an incident.

✖ FLAGGED FOR REVIEW

Every miss is a lesson. Takeaway:

An incident actually or potentially harms security; not every event is an incident.

✖ FLAGGED FOR REVIEW

Every miss is a lesson. Takeaway:

An incident actually or potentially harms security; not every event is an incident.

✔ DEFENSE HELD

Nicely done — that’s a keeper.

An incident actually or potentially harms security; not every event is an incident.

CHECKPOINT — 30 DOWN, STAY SHARP
31/100 BC / DR / IR

The maximum acceptable time a system can be down before it seriously hurts the business is the:

✖ ACCESS DENIED

Reset and lock it in with this:

RTO is the target time to restore a system; RPO is the acceptable amount of data loss.

✖ ACCESS DENIED

Reset and lock it in with this:

RTO is the target time to restore a system; RPO is the acceptable amount of data loss.

✔ ACCESS GRANTED

That’s foundation-solid — clean and correct.

RTO is the target time to restore a system; RPO is the acceptable amount of data loss.

✖ ACCESS DENIED

Reset and lock it in with this:

RTO is the target time to restore a system; RPO is the acceptable amount of data loss.

32/100 BC / DR / IR

The maximum amount of data, measured in time, that a business can afford to lose sets the:

✖ THREAT DETECTED

Patch your thinking with this:

RPO is the acceptable data-loss window, which drives how often backups must run.

✔ THREAT NEUTRALIZED

Sharp. You’re thinking like a defender.

RPO is the acceptable data-loss window, which drives how often backups must run.

✖ THREAT DETECTED

Patch your thinking with this:

RPO is the acceptable data-loss window, which drives how often backups must run.

✖ THREAT DETECTED

Patch your thinking with this:

RPO is the acceptable data-loss window, which drives how often backups must run.

33/100 BC / DR / IR

The main reason to keep regular, tested backups of important data is to support:

✔ IDENTITY VERIFIED

You’ve got the principle down. Textbook.

Backups enable recovery and availability after loss, corruption, or ransomware.

✖ ALERT RAISED

No stress — here’s the fix:

Backups enable recovery and availability after loss, corruption, or ransomware.

✖ ALERT RAISED

No stress — here’s the fix:

Backups enable recovery and availability after loss, corruption, or ransomware.

✖ ALERT RAISED

No stress — here’s the fix:

Backups enable recovery and availability after loss, corruption, or ransomware.

34/100 BC / DR / IR

Having a second power supply so a server keeps running if one fails is an example of:

✖ CHECK FAILED

Every miss is a lesson. Takeaway:

Redundancy provides backup components to maintain availability if one fails.

✖ CHECK FAILED

Every miss is a lesson. Takeaway:

Redundancy provides backup components to maintain availability if one fails.

✖ CHECK FAILED

Every miss is a lesson. Takeaway:

Redundancy provides backup components to maintain availability if one fails.

✔ CONTROL VALIDATED

Locked in — that’s the CC mindset.

Redundancy provides backup components to maintain availability if one fails.

35/100 BC / DR / IR

Writing the incident response plan, training the team, and setting up tools before anything happens is which phase?

✖ FLAGGED FOR REVIEW

Reset and lock it in with this:

Preparation readies the people, plans, and tools before an incident ever occurs.

✖ FLAGGED FOR REVIEW

Reset and lock it in with this:

Preparation readies the people, plans, and tools before an incident ever occurs.

✔ RISK MITIGATED

Verified. Oluma loves to see it.

Preparation readies the people, plans, and tools before an incident ever occurs.

✖ FLAGGED FOR REVIEW

Reset and lock it in with this:

Preparation readies the people, plans, and tools before an incident ever occurs.

36/100 BC / DR / IR

After an incident is resolved, the team meets to review what happened and improve. This is the:

✖ ACCESS DENIED

Patch your thinking with this:

The lessons-learned phase reviews the incident to strengthen future response.

✔ POLICY ENFORCED

Nicely done — that’s a keeper.

The lessons-learned phase reviews the incident to strengthen future response.

✖ ACCESS DENIED

Patch your thinking with this:

The lessons-learned phase reviews the incident to strengthen future response.

✖ ACCESS DENIED

Patch your thinking with this:

The lessons-learned phase reviews the incident to strengthen future response.

37/100 Access Controls

Typing your username to claim an identity, before proving it, is:

✔ INTEGRITY CONFIRMED

That’s foundation-solid — clean and correct.

Identification is claiming an identity; authentication then proves it.

✖ THREAT DETECTED

No stress — here’s the fix:

Identification is claiming an identity; authentication then proves it.

✖ THREAT DETECTED

No stress — here’s the fix:

Identification is claiming an identity; authentication then proves it.

✖ THREAT DETECTED

No stress — here’s the fix:

Identification is claiming an identity; authentication then proves it.

38/100 Access Controls

System logs that tie a specific action back to a specific user provide:

✖ ALERT RAISED

Every miss is a lesson. Takeaway:

Accountability links actions to identities, usually through logging.

✖ ALERT RAISED

Every miss is a lesson. Takeaway:

Accountability links actions to identities, usually through logging.

✖ ALERT RAISED

Every miss is a lesson. Takeaway:

Accountability links actions to identities, usually through logging.

✔ SECURED

Sharp. You’re thinking like a defender.

Accountability links actions to identities, usually through logging.

39/100 Access Controls

A password or PIN is which type of authentication factor?

✖ CHECK FAILED

Reset and lock it in with this:

‘Something you know’ is knowledge-based, like a password or PIN.

✖ CHECK FAILED

Reset and lock it in with this:

‘Something you know’ is knowledge-based, like a password or PIN.

✔ VERIFIED

You’ve got the principle down. Textbook.

‘Something you know’ is knowledge-based, like a password or PIN.

✖ CHECK FAILED

Reset and lock it in with this:

‘Something you know’ is knowledge-based, like a password or PIN.

40/100 Access Controls

A smart card or hardware token is which authentication factor?

✖ FLAGGED FOR REVIEW

Patch your thinking with this:

‘Something you have’ is possession-based, like a token, smart card, or phone.

✔ DEFENSE HELD

Locked in — that’s the CC mindset.

‘Something you have’ is possession-based, like a token, smart card, or phone.

✖ FLAGGED FOR REVIEW

Patch your thinking with this:

‘Something you have’ is possession-based, like a token, smart card, or phone.

✖ FLAGGED FOR REVIEW

Patch your thinking with this:

‘Something you have’ is possession-based, like a token, smart card, or phone.

CHECKPOINT — 40 DOWN, STAY SHARP
41/100 Access Controls

A fingerprint or facial scan is which authentication factor?

✔ ACCESS GRANTED

Verified. Oluma loves to see it.

‘Something you are’ is biometric — fingerprint, face, or iris, for example.

✖ ACCESS DENIED

No stress — here’s the fix:

‘Something you are’ is biometric — fingerprint, face, or iris, for example.

✖ ACCESS DENIED

No stress — here’s the fix:

‘Something you are’ is biometric — fingerprint, face, or iris, for example.

✖ ACCESS DENIED

No stress — here’s the fix:

‘Something you are’ is biometric — fingerprint, face, or iris, for example.

42/100 Access Controls

Which combination is true multi-factor authentication?

✖ THREAT DETECTED

Every miss is a lesson. Takeaway:

True MFA combines factors of different types (know + are), not two of the same type.

✖ THREAT DETECTED

Every miss is a lesson. Takeaway:

True MFA combines factors of different types (know + are), not two of the same type.

✖ THREAT DETECTED

Every miss is a lesson. Takeaway:

True MFA combines factors of different types (know + are), not two of the same type.

✔ THREAT NEUTRALIZED

Nicely done — that’s a keeper.

True MFA combines factors of different types (know + are), not two of the same type.

43/100 Access Controls

An access model where the data owner decides who may access their files is:

✖ ALERT RAISED

Reset and lock it in with this:

In DAC, the owner has discretion to grant or deny access to their resources.

✖ ALERT RAISED

Reset and lock it in with this:

In DAC, the owner has discretion to grant or deny access to their resources.

✔ IDENTITY VERIFIED

That’s foundation-solid — clean and correct.

In DAC, the owner has discretion to grant or deny access to their resources.

✖ ALERT RAISED

Reset and lock it in with this:

In DAC, the owner has discretion to grant or deny access to their resources.

44/100 Access Controls

An access model where the system enforces access using classification labels and clearances is:

✖ CHECK FAILED

Patch your thinking with this:

MAC enforces access based on labels and clearances set by the system, not by owners.

✔ CONTROL VALIDATED

Sharp. You’re thinking like a defender.

MAC enforces access based on labels and clearances set by the system, not by owners.

✖ CHECK FAILED

Patch your thinking with this:

MAC enforces access based on labels and clearances set by the system, not by owners.

✖ CHECK FAILED

Patch your thinking with this:

MAC enforces access based on labels and clearances set by the system, not by owners.

45/100 Access Controls

Assigning permissions to job roles, so users gain access based on their role, is:

✔ RISK MITIGATED

You’ve got the principle down. Textbook.

RBAC grants access based on a user’s role within the organization.

✖ FLAGGED FOR REVIEW

No stress — here’s the fix:

RBAC grants access based on a user’s role within the organization.

✖ FLAGGED FOR REVIEW

No stress — here’s the fix:

RBAC grants access based on a user’s role within the organization.

✖ FLAGGED FOR REVIEW

No stress — here’s the fix:

RBAC grants access based on a user’s role within the organization.

46/100 Access Controls

Even with a Secret clearance, an analyst may only see the specific documents required for their task. This enforces:

✖ ACCESS DENIED

Every miss is a lesson. Takeaway:

Need-to-know limits access to only the information required for a task, even among the cleared.

✖ ACCESS DENIED

Every miss is a lesson. Takeaway:

Need-to-know limits access to only the information required for a task, even among the cleared.

✖ ACCESS DENIED

Every miss is a lesson. Takeaway:

Need-to-know limits access to only the information required for a task, even among the cleared.

✔ POLICY ENFORCED

Locked in — that’s the CC mindset.

Need-to-know limits access to only the information required for a task, even among the cleared.

47/100 Access Controls

Requiring two different people to approve a large payment reduces fraud through:

✖ THREAT DETECTED

Reset and lock it in with this:

Separation of duties splits a sensitive task so no single person controls it entirely.

✖ THREAT DETECTED

Reset and lock it in with this:

Separation of duties splits a sensitive task so no single person controls it entirely.

✔ INTEGRITY CONFIRMED

Verified. Oluma loves to see it.

Separation of duties splits a sensitive task so no single person controls it entirely.

✖ THREAT DETECTED

Reset and lock it in with this:

Separation of duties splits a sensitive task so no single person controls it entirely.

48/100 Access Controls

Creating a new employee’s accounts and granting appropriate access on their first day is:

✖ ALERT RAISED

Patch your thinking with this:

Provisioning sets up identities and access when a user joins or changes roles.

✔ SECURED

Nicely done — that’s a keeper.

Provisioning sets up identities and access when a user joins or changes roles.

✖ ALERT RAISED

Patch your thinking with this:

Provisioning sets up identities and access when a user joins or changes roles.

✖ ALERT RAISED

Patch your thinking with this:

Provisioning sets up identities and access when a user joins or changes roles.

49/100 Access Controls

Disabling accounts and removing access the moment an employee is terminated is:

✔ VERIFIED

That’s foundation-solid — clean and correct.

Deprovisioning promptly removes access when it’s no longer needed, closing a common security gap.

✖ CHECK FAILED

No stress — here’s the fix:

Deprovisioning promptly removes access when it’s no longer needed, closing a common security gap.

✖ CHECK FAILED

No stress — here’s the fix:

Deprovisioning promptly removes access when it’s no longer needed, closing a common security gap.

✖ CHECK FAILED

No stress — here’s the fix:

Deprovisioning promptly removes access when it’s no longer needed, closing a common security gap.

50/100 Access Controls

An administrator account with broad system rights should be:

✖ FLAGGED FOR REVIEW

Every miss is a lesson. Takeaway:

Privileged accounts are high-value targets and must be limited, monitored, and used sparingly.

✖ FLAGGED FOR REVIEW

Every miss is a lesson. Takeaway:

Privileged accounts are high-value targets and must be limited, monitored, and used sparingly.

✖ FLAGGED FOR REVIEW

Every miss is a lesson. Takeaway:

Privileged accounts are high-value targets and must be limited, monitored, and used sparingly.

✔ DEFENSE HELD

Sharp. You’re thinking like a defender.

Privileged accounts are high-value targets and must be limited, monitored, and used sparingly.

CHECKPOINT — 50 DOWN, STAY SHARP
51/100 Access Controls

A small room with two interlocking doors that lets only one person through at a time is a:

✖ ACCESS DENIED

Reset and lock it in with this:

A mantrap/access control vestibule prevents tailgating by allowing one person through at a time.

✖ ACCESS DENIED

Reset and lock it in with this:

A mantrap/access control vestibule prevents tailgating by allowing one person through at a time.

✔ ACCESS GRANTED

You’ve got the principle down. Textbook.

A mantrap/access control vestibule prevents tailgating by allowing one person through at a time.

✖ ACCESS DENIED

Reset and lock it in with this:

A mantrap/access control vestibule prevents tailgating by allowing one person through at a time.

52/100 Access Controls

An employee taps an ID badge to open a secure door. This is a:

✖ THREAT DETECTED

Patch your thinking with this:

Badge readers on doors are physical access controls.

✔ THREAT NEUTRALIZED

Locked in — that’s the CC mindset.

Badge readers on doors are physical access controls.

✖ THREAT DETECTED

Patch your thinking with this:

Badge readers on doors are physical access controls.

✖ THREAT DETECTED

Patch your thinking with this:

Badge readers on doors are physical access controls.

53/100 Access Controls

An unauthorized person slips through a secure door right behind an employee. This is:

✔ IDENTITY VERIFIED

Verified. Oluma loves to see it.

Tailgating is following an authorized person through a controlled entry without authenticating.

✖ ALERT RAISED

No stress — here’s the fix:

Tailgating is following an authorized person through a controlled entry without authenticating.

✖ ALERT RAISED

No stress — here’s the fix:

Tailgating is following an authorized person through a controlled entry without authenticating.

✖ ALERT RAISED

No stress — here’s the fix:

Tailgating is following an authorized person through a controlled entry without authenticating.

54/100 Access Controls

The best default when assigning a new user’s permissions is to start with:

✖ CHECK FAILED

Every miss is a lesson. Takeaway:

Least privilege starts minimal and grants more access only as it’s justified.

✖ CHECK FAILED

Every miss is a lesson. Takeaway:

Least privilege starts minimal and grants more access only as it’s justified.

✖ CHECK FAILED

Every miss is a lesson. Takeaway:

Least privilege starts minimal and grants more access only as it’s justified.

✔ CONTROL VALIDATED

Nicely done — that’s a keeper.

Least privilege starts minimal and grants more access only as it’s justified.

55/100 Access Controls

A fingerprint reader occasionally admits the wrong person. This error is a:

✖ FLAGGED FOR REVIEW

Reset and lock it in with this:

False acceptance wrongly admits an unauthorized user; false rejection wrongly denies a valid one.

✖ FLAGGED FOR REVIEW

Reset and lock it in with this:

False acceptance wrongly admits an unauthorized user; false rejection wrongly denies a valid one.

✔ RISK MITIGATED

That’s foundation-solid — clean and correct.

False acceptance wrongly admits an unauthorized user; false rejection wrongly denies a valid one.

✖ FLAGGED FOR REVIEW

Reset and lock it in with this:

False acceptance wrongly admits an unauthorized user; false rejection wrongly denies a valid one.

56/100 Access Controls

Logging in once to reach many applications without re-entering credentials is:

✖ ACCESS DENIED

Patch your thinking with this:

SSO lets a user authenticate once for access to multiple systems.

✔ POLICY ENFORCED

Sharp. You’re thinking like a defender.

SSO lets a user authenticate once for access to multiple systems.

✖ ACCESS DENIED

Patch your thinking with this:

SSO lets a user authenticate once for access to multiple systems.

✖ ACCESS DENIED

Patch your thinking with this:

SSO lets a user authenticate once for access to multiple systems.

57/100 Access Controls

Periodically checking that users still need the access they have, and removing stale rights, is an access:

✔ INTEGRITY CONFIRMED

You’ve got the principle down. Textbook.

Access reviews/recertification catch excessive or outdated permissions over time.

✖ THREAT DETECTED

No stress — here’s the fix:

Access reviews/recertification catch excessive or outdated permissions over time.

✖ THREAT DETECTED

No stress — here’s the fix:

Access reviews/recertification catch excessive or outdated permissions over time.

✖ THREAT DETECTED

No stress — here’s the fix:

Access reviews/recertification catch excessive or outdated permissions over time.

58/100 Access Controls

Security cameras recording a data center entrance primarily serve as a:

✖ ALERT RAISED

Every miss is a lesson. Takeaway:

CCTV records activity for later review and deters wrongdoers — detective and deterrent.

✖ ALERT RAISED

Every miss is a lesson. Takeaway:

CCTV records activity for later review and deters wrongdoers — detective and deterrent.

✖ ALERT RAISED

Every miss is a lesson. Takeaway:

CCTV records activity for later review and deters wrongdoers — detective and deterrent.

✔ SECURED

Locked in — that’s the CC mindset.

CCTV records activity for later review and deters wrongdoers — detective and deterrent.

59/100 Network Security

A device or software that filters network traffic based on rules, allowing or blocking it, is a:

✖ CHECK FAILED

Reset and lock it in with this:

A firewall enforces rules on what traffic may pass between networks.

✖ CHECK FAILED

Reset and lock it in with this:

A firewall enforces rules on what traffic may pass between networks.

✔ VERIFIED

Verified. Oluma loves to see it.

A firewall enforces rules on what traffic may pass between networks.

✖ CHECK FAILED

Reset and lock it in with this:

A firewall enforces rules on what traffic may pass between networks.

60/100 Network Security

A system that monitors network traffic and alerts on suspicious activity but does not block it is an:

✖ FLAGGED FOR REVIEW

Patch your thinking with this:

An IDS detects and alerts; an IPS can also actively block.

✔ DEFENSE HELD

Nicely done — that’s a keeper.

An IDS detects and alerts; an IPS can also actively block.

✖ FLAGGED FOR REVIEW

Patch your thinking with this:

An IDS detects and alerts; an IPS can also actively block.

✖ FLAGGED FOR REVIEW

Patch your thinking with this:

An IDS detects and alerts; an IPS can also actively block.

CHECKPOINT — 60 DOWN, STAY SHARP
61/100 Network Security

A system that detects malicious traffic and actively blocks it in real time is an:

✔ ACCESS GRANTED

That’s foundation-solid — clean and correct.

An IPS both detects and prevents by blocking malicious traffic inline.

✖ ACCESS DENIED

No stress — here’s the fix:

An IPS both detects and prevents by blocking malicious traffic inline.

✖ ACCESS DENIED

No stress — here’s the fix:

An IPS both detects and prevents by blocking malicious traffic inline.

✖ ACCESS DENIED

No stress — here’s the fix:

An IPS both detects and prevents by blocking malicious traffic inline.

62/100 Network Security

Remote employees use an encrypted tunnel to connect securely to the office network. This is a:

✖ THREAT DETECTED

Every miss is a lesson. Takeaway:

A VPN creates an encrypted tunnel over an untrusted network like the internet.

✖ THREAT DETECTED

Every miss is a lesson. Takeaway:

A VPN creates an encrypted tunnel over an untrusted network like the internet.

✖ THREAT DETECTED

Every miss is a lesson. Takeaway:

A VPN creates an encrypted tunnel over an untrusted network like the internet.

✔ THREAT NEUTRALIZED

Sharp. You’re thinking like a defender.

A VPN creates an encrypted tunnel over an untrusted network like the internet.

63/100 Network Security

Splitting a network into separate zones so a breach in one can’t easily reach the others is:

✖ ALERT RAISED

Reset and lock it in with this:

Segmentation limits how far an attacker can move within a network.

✖ ALERT RAISED

Reset and lock it in with this:

Segmentation limits how far an attacker can move within a network.

✔ IDENTITY VERIFIED

You’ve got the principle down. Textbook.

Segmentation limits how far an attacker can move within a network.

✖ ALERT RAISED

Reset and lock it in with this:

Segmentation limits how far an attacker can move within a network.

64/100 Network Security

A network zone that hosts public-facing servers, separated from the internal network, is a:

✖ CHECK FAILED

Patch your thinking with this:

A DMZ/screened subnet isolates internet-facing services from the internal network.

✔ CONTROL VALIDATED

Locked in — that’s the CC mindset.

A DMZ/screened subnet isolates internet-facing services from the internal network.

✖ CHECK FAILED

Patch your thinking with this:

A DMZ/screened subnet isolates internet-facing services from the internal network.

✖ CHECK FAILED

Patch your thinking with this:

A DMZ/screened subnet isolates internet-facing services from the internal network.

65/100 Network Security

Secure web traffic (HTTPS) uses which well-known port?

✔ RISK MITIGATED

Verified. Oluma loves to see it.

HTTPS uses port 443; unencrypted HTTP uses port 80.

✖ FLAGGED FOR REVIEW

No stress — here’s the fix:

HTTPS uses port 443; unencrypted HTTP uses port 80.

✖ FLAGGED FOR REVIEW

No stress — here’s the fix:

HTTPS uses port 443; unencrypted HTTP uses port 80.

✖ FLAGGED FOR REVIEW

No stress — here’s the fix:

HTTPS uses port 443; unencrypted HTTP uses port 80.

66/100 Network Security

Unencrypted web traffic (HTTP) uses which well-known port?

✖ ACCESS DENIED

Every miss is a lesson. Takeaway:

HTTP uses port 80; the secure version, HTTPS, uses 443.

✖ ACCESS DENIED

Every miss is a lesson. Takeaway:

HTTP uses port 80; the secure version, HTTPS, uses 443.

✖ ACCESS DENIED

Every miss is a lesson. Takeaway:

HTTP uses port 80; the secure version, HTTPS, uses 443.

✔ POLICY ENFORCED

Nicely done — that’s a keeper.

HTTP uses port 80; the secure version, HTTPS, uses 443.

67/100 Network Security

An administrator needs to securely manage a remote server over an encrypted command line. Which protocol?

✖ THREAT DETECTED

Reset and lock it in with this:

SSH provides encrypted remote administration; Telnet sends everything in cleartext.

✖ THREAT DETECTED

Reset and lock it in with this:

SSH provides encrypted remote administration; Telnet sends everything in cleartext.

✔ INTEGRITY CONFIRMED

That’s foundation-solid — clean and correct.

SSH provides encrypted remote administration; Telnet sends everything in cleartext.

✖ THREAT DETECTED

Reset and lock it in with this:

SSH provides encrypted remote administration; Telnet sends everything in cleartext.

68/100 Network Security

Which service translates a domain name like example.com into an IP address?

✖ ALERT RAISED

Patch your thinking with this:

DNS resolves human-friendly names to IP addresses.

✔ SECURED

Sharp. You’re thinking like a defender.

DNS resolves human-friendly names to IP addresses.

✖ ALERT RAISED

Patch your thinking with this:

DNS resolves human-friendly names to IP addresses.

✖ ALERT RAISED

Patch your thinking with this:

DNS resolves human-friendly names to IP addresses.

69/100 Network Security

Which service automatically assigns IP addresses to devices joining a network?

✔ VERIFIED

You’ve got the principle down. Textbook.

DHCP automatically hands out IP configuration to devices.

✖ CHECK FAILED

No stress — here’s the fix:

DHCP automatically hands out IP configuration to devices.

✖ CHECK FAILED

No stress — here’s the fix:

DHCP automatically hands out IP configuration to devices.

✖ CHECK FAILED

No stress — here’s the fix:

DHCP automatically hands out IP configuration to devices.

70/100 Network Security

An attacker floods a website with traffic until it can’t serve real users. This attack targets:

✖ FLAGGED FOR REVIEW

Every miss is a lesson. Takeaway:

A DoS/DDoS attack overwhelms a resource, harming its availability.

✖ FLAGGED FOR REVIEW

Every miss is a lesson. Takeaway:

A DoS/DDoS attack overwhelms a resource, harming its availability.

✖ FLAGGED FOR REVIEW

Every miss is a lesson. Takeaway:

A DoS/DDoS attack overwhelms a resource, harming its availability.

✔ DEFENSE HELD

Locked in — that’s the CC mindset.

A DoS/DDoS attack overwhelms a resource, harming its availability.

CHECKPOINT — 70 DOWN, STAY SHARP
71/100 Network Security

An attacker secretly sits between two parties and intercepts their communication. This is a:

✖ ACCESS DENIED

Reset and lock it in with this:

A man-in-the-middle/on-path attacker intercepts or alters traffic between two parties.

✖ ACCESS DENIED

Reset and lock it in with this:

A man-in-the-middle/on-path attacker intercepts or alters traffic between two parties.

✔ ACCESS GRANTED

Verified. Oluma loves to see it.

A man-in-the-middle/on-path attacker intercepts or alters traffic between two parties.

✖ ACCESS DENIED

Reset and lock it in with this:

A man-in-the-middle/on-path attacker intercepts or alters traffic between two parties.

72/100 Network Security

Malicious code that attaches to a file and needs a user to run it in order to spread is a:

✖ THREAT DETECTED

Patch your thinking with this:

A virus needs a host file and user action to execute; a worm spreads on its own.

✔ THREAT NEUTRALIZED

Nicely done — that’s a keeper.

A virus needs a host file and user action to execute; a worm spreads on its own.

✖ THREAT DETECTED

Patch your thinking with this:

A virus needs a host file and user action to execute; a worm spreads on its own.

✖ THREAT DETECTED

Patch your thinking with this:

A virus needs a host file and user action to execute; a worm spreads on its own.

73/100 Network Security

Self-replicating malware that spreads across a network on its own, without user action, is a:

✔ IDENTITY VERIFIED

That’s foundation-solid — clean and correct.

A worm self-propagates across networks without needing a host file or user action.

✖ ALERT RAISED

No stress — here’s the fix:

A worm self-propagates across networks without needing a host file or user action.

✖ ALERT RAISED

No stress — here’s the fix:

A worm self-propagates across networks without needing a host file or user action.

✖ ALERT RAISED

No stress — here’s the fix:

A worm self-propagates across networks without needing a host file or user action.

74/100 Network Security

Malware disguised as a legitimate program to trick a user into installing it is a:

✖ CHECK FAILED

Every miss is a lesson. Takeaway:

A trojan hides malicious functionality inside something that looks legitimate.

✖ CHECK FAILED

Every miss is a lesson. Takeaway:

A trojan hides malicious functionality inside something that looks legitimate.

✖ CHECK FAILED

Every miss is a lesson. Takeaway:

A trojan hides malicious functionality inside something that looks legitimate.

✔ CONTROL VALIDATED

Sharp. You’re thinking like a defender.

A trojan hides malicious functionality inside something that looks legitimate.

75/100 Network Security

To secure a home or office Wi-Fi network, you should enable:

✖ FLAGGED FOR REVIEW

Reset and lock it in with this:

WPA2/WPA3 provide strong Wi-Fi encryption; WEP is outdated and easily broken.

✖ FLAGGED FOR REVIEW

Reset and lock it in with this:

WPA2/WPA3 provide strong Wi-Fi encryption; WEP is outdated and easily broken.

✔ RISK MITIGATED

You’ve got the principle down. Textbook.

WPA2/WPA3 provide strong Wi-Fi encryption; WEP is outdated and easily broken.

✖ FLAGGED FOR REVIEW

Reset and lock it in with this:

WPA2/WPA3 provide strong Wi-Fi encryption; WEP is outdated and easily broken.

76/100 Network Security

A technique that lets many internal devices share one public IP address is:

✖ ACCESS DENIED

Patch your thinking with this:

NAT maps multiple private addresses to public ones, conserving addresses and hiding internal IPs.

✔ POLICY ENFORCED

Locked in — that’s the CC mindset.

NAT maps multiple private addresses to public ones, conserving addresses and hiding internal IPs.

✖ ACCESS DENIED

Patch your thinking with this:

NAT maps multiple private addresses to public ones, conserving addresses and hiding internal IPs.

✖ ACCESS DENIED

Patch your thinking with this:

NAT maps multiple private addresses to public ones, conserving addresses and hiding internal IPs.

77/100 Network Security

A device that forwards data between different networks, such as your LAN and the internet, is a:

✔ INTEGRITY CONFIRMED

Verified. Oluma loves to see it.

A router connects and routes between different networks; a switch connects devices within one.

✖ THREAT DETECTED

No stress — here’s the fix:

A router connects and routes between different networks; a switch connects devices within one.

✖ THREAT DETECTED

No stress — here’s the fix:

A router connects and routes between different networks; a switch connects devices within one.

✖ THREAT DETECTED

No stress — here’s the fix:

A router connects and routes between different networks; a switch connects devices within one.

78/100 Network Security

An attacker probes a server to discover which ports are open and what services are running. This is:

✖ ALERT RAISED

Every miss is a lesson. Takeaway:

Port scanning discovers open ports and services as a precursor to an attack.

✖ ALERT RAISED

Every miss is a lesson. Takeaway:

Port scanning discovers open ports and services as a precursor to an attack.

✖ ALERT RAISED

Every miss is a lesson. Takeaway:

Port scanning discovers open ports and services as a precursor to an attack.

✔ SECURED

Nicely done — that’s a keeper.

Port scanning discovers open ports and services as a precursor to an attack.

79/100 Network Security

Which protocol encrypts data in transit for secure websites, email, and more?

✖ CHECK FAILED

Reset and lock it in with this:

TLS encrypts data in transit and underpins HTTPS and other secure communications.

✖ CHECK FAILED

Reset and lock it in with this:

TLS encrypts data in transit and underpins HTTPS and other secure communications.

✔ VERIFIED

That’s foundation-solid — clean and correct.

TLS encrypts data in transit and underpins HTTPS and other secure communications.

✖ CHECK FAILED

Reset and lock it in with this:

TLS encrypts data in transit and underpins HTTPS and other secure communications.

80/100 Network Security

A model that never automatically trusts a user or device, even inside the network, and verifies every request is:

✖ FLAGGED FOR REVIEW

Patch your thinking with this:

Zero trust assumes no implicit trust and continuously verifies every access request.

✔ DEFENSE HELD

Sharp. You’re thinking like a defender.

Zero trust assumes no implicit trust and continuously verifies every access request.

✖ FLAGGED FOR REVIEW

Patch your thinking with this:

Zero trust assumes no implicit trust and continuously verifies every access request.

✖ FLAGGED FOR REVIEW

Patch your thinking with this:

Zero trust assumes no implicit trust and continuously verifies every access request.

CHECKPOINT — 80 DOWN, STAY SHARP
81/100 Network Security

An email pretending to be from your bank asks you to click a link and enter your password. This is:

✔ ACCESS GRANTED

You’ve got the principle down. Textbook.

Phishing uses deceptive messages to trick users into revealing credentials or clicking malicious links.

✖ ACCESS DENIED

No stress — here’s the fix:

Phishing uses deceptive messages to trick users into revealing credentials or clicking malicious links.

✖ ACCESS DENIED

No stress — here’s the fix:

Phishing uses deceptive messages to trick users into revealing credentials or clicking malicious links.

✖ ACCESS DENIED

No stress — here’s the fix:

Phishing uses deceptive messages to trick users into revealing credentials or clicking malicious links.

82/100 Network Security

The most secure default rule for a firewall is to:

✖ THREAT DETECTED

Every miss is a lesson. Takeaway:

A default-deny (implicit deny) posture blocks everything not explicitly permitted.

✖ THREAT DETECTED

Every miss is a lesson. Takeaway:

A default-deny (implicit deny) posture blocks everything not explicitly permitted.

✖ THREAT DETECTED

Every miss is a lesson. Takeaway:

A default-deny (implicit deny) posture blocks everything not explicitly permitted.

✔ THREAT NEUTRALIZED

Locked in — that’s the CC mindset.

A default-deny (implicit deny) posture blocks everything not explicitly permitted.

83/100 Security Operations

Labeling data as Public, Internal, or Confidential so it is handled appropriately is:

✖ ALERT RAISED

Reset and lock it in with this:

Classification labels data by sensitivity to drive how it is protected and handled.

✖ ALERT RAISED

Reset and lock it in with this:

Classification labels data by sensitivity to drive how it is protected and handled.

✔ IDENTITY VERIFIED

Verified. Oluma loves to see it.

Classification labels data by sensitivity to drive how it is protected and handled.

✖ ALERT RAISED

Reset and lock it in with this:

Classification labels data by sensitivity to drive how it is protected and handled.

84/100 Security Operations

Encrypting the files stored on a laptop’s hard drive protects data:

✖ CHECK FAILED

Patch your thinking with this:

Encryption at rest protects stored data; encryption in transit protects data that is moving.

✔ CONTROL VALIDATED

Nicely done — that’s a keeper.

Encryption at rest protects stored data; encryption in transit protects data that is moving.

✖ CHECK FAILED

Patch your thinking with this:

Encryption at rest protects stored data; encryption in transit protects data that is moving.

✖ CHECK FAILED

Patch your thinking with this:

Encryption at rest protects stored data; encryption in transit protects data that is moving.

85/100 Security Operations

Using HTTPS to protect data as it travels between a browser and a server protects data:

✔ RISK MITIGATED

That’s foundation-solid — clean and correct.

Encryption in transit protects data while it moves across a network.

✖ FLAGGED FOR REVIEW

No stress — here’s the fix:

Encryption in transit protects data while it moves across a network.

✖ FLAGGED FOR REVIEW

No stress — here’s the fix:

Encryption in transit protects data while it moves across a network.

✖ FLAGGED FOR REVIEW

No stress — here’s the fix:

Encryption in transit protects data while it moves across a network.

86/100 Security Operations

Regularly applying vendor updates to fix known vulnerabilities is:

✖ ACCESS DENIED

Every miss is a lesson. Takeaway:

Patch management keeps systems updated to close known security holes.

✖ ACCESS DENIED

Every miss is a lesson. Takeaway:

Patch management keeps systems updated to close known security holes.

✖ ACCESS DENIED

Every miss is a lesson. Takeaway:

Patch management keeps systems updated to close known security holes.

✔ POLICY ENFORCED

Sharp. You’re thinking like a defender.

Patch management keeps systems updated to close known security holes.

87/100 Security Operations

Removing unnecessary software, closing unused ports, and disabling default accounts on a server is:

✖ THREAT DETECTED

Reset and lock it in with this:

Hardening reduces a system’s attack surface by removing what isn’t needed.

✖ THREAT DETECTED

Reset and lock it in with this:

Hardening reduces a system’s attack surface by removing what isn’t needed.

✔ INTEGRITY CONFIRMED

You’ve got the principle down. Textbook.

Hardening reduces a system’s attack surface by removing what isn’t needed.

✖ THREAT DETECTED

Reset and lock it in with this:

Hardening reduces a system’s attack surface by removing what isn’t needed.

88/100 Security Operations

Collecting and reviewing system and security logs to spot suspicious activity supports:

✖ ALERT RAISED

Patch your thinking with this:

Logging and monitoring provide the visibility needed to detect and investigate incidents.

✔ SECURED

Locked in — that’s the CC mindset.

Logging and monitoring provide the visibility needed to detect and investigate incidents.

✖ ALERT RAISED

Patch your thinking with this:

Logging and monitoring provide the visibility needed to detect and investigate incidents.

✖ ALERT RAISED

Patch your thinking with this:

Logging and monitoring provide the visibility needed to detect and investigate incidents.

89/100 Security Operations

Teaching employees to recognize phishing and follow good security habits is:

✔ VERIFIED

Verified. Oluma loves to see it.

Awareness training strengthens the human layer, one of the most common attack targets.

✖ CHECK FAILED

No stress — here’s the fix:

Awareness training strengthens the human layer, one of the most common attack targets.

✖ CHECK FAILED

No stress — here’s the fix:

Awareness training strengthens the human layer, one of the most common attack targets.

✖ CHECK FAILED

No stress — here’s the fix:

Awareness training strengthens the human layer, one of the most common attack targets.

90/100 Security Operations

A document employees sign describing acceptable use of company systems and the internet is an:

✖ FLAGGED FOR REVIEW

Every miss is a lesson. Takeaway:

An AUP defines what users may and may not do with company resources.

✖ FLAGGED FOR REVIEW

Every miss is a lesson. Takeaway:

An AUP defines what users may and may not do with company resources.

✖ FLAGGED FOR REVIEW

Every miss is a lesson. Takeaway:

An AUP defines what users may and may not do with company resources.

✔ DEFENSE HELD

Nicely done — that’s a keeper.

An AUP defines what users may and may not do with company resources.

CHECKPOINT — 90 DOWN, STAY SHARP
91/100 Security Operations

Reviewing and approving a proposed system change before it’s made, to avoid unintended problems, is:

✖ ACCESS DENIED

Reset and lock it in with this:

Change management controls how changes are proposed, reviewed, approved, and applied.

✖ ACCESS DENIED

Reset and lock it in with this:

Change management controls how changes are proposed, reviewed, approved, and applied.

✔ ACCESS GRANTED

That’s foundation-solid — clean and correct.

Change management controls how changes are proposed, reviewed, approved, and applied.

✖ ACCESS DENIED

Reset and lock it in with this:

Change management controls how changes are proposed, reviewed, approved, and applied.

92/100 Security Operations

Before donating old computers, the drives are wiped or destroyed so no data can be recovered. This is:

✖ THREAT DETECTED

Patch your thinking with this:

Sanitization/secure disposal ensures data cannot be recovered from retired media.

✔ THREAT NEUTRALIZED

Sharp. You’re thinking like a defender.

Sanitization/secure disposal ensures data cannot be recovered from retired media.

✖ THREAT DETECTED

Patch your thinking with this:

Sanitization/secure disposal ensures data cannot be recovered from retired media.

✖ THREAT DETECTED

Patch your thinking with this:

Sanitization/secure disposal ensures data cannot be recovered from retired media.

93/100 Security Operations

A policy stating how long records must be kept before deletion addresses data:

✔ IDENTITY VERIFIED

You’ve got the principle down. Textbook.

Retention policies define how long data is kept and when it is disposed of.

✖ ALERT RAISED

No stress — here’s the fix:

Retention policies define how long data is kept and when it is disposed of.

✖ ALERT RAISED

No stress — here’s the fix:

Retention policies define how long data is kept and when it is disposed of.

✖ ALERT RAISED

No stress — here’s the fix:

Retention policies define how long data is kept and when it is disposed of.

94/100 Security Operations

An attacker phones the help desk pretending to be a locked-out executive to get a password reset. This is:

✖ CHECK FAILED

Every miss is a lesson. Takeaway:

Social engineering manipulates people, rather than technology, to gain access.

✖ CHECK FAILED

Every miss is a lesson. Takeaway:

Social engineering manipulates people, rather than technology, to gain access.

✖ CHECK FAILED

Every miss is a lesson. Takeaway:

Social engineering manipulates people, rather than technology, to gain access.

✔ CONTROL VALIDATED

Locked in — that’s the CC mindset.

Social engineering manipulates people, rather than technology, to gain access.

95/100 Security Operations

Requiring strong, unique passwords and enabling MFA is part of good:

✖ FLAGGED FOR REVIEW

Reset and lock it in with this:

Strong password practices and MFA protect accounts from compromise.

✖ FLAGGED FOR REVIEW

Reset and lock it in with this:

Strong password practices and MFA protect accounts from compromise.

✔ RISK MITIGATED

Verified. Oluma loves to see it.

Strong password practices and MFA protect accounts from compromise.

✖ FLAGGED FOR REVIEW

Reset and lock it in with this:

Strong password practices and MFA protect accounts from compromise.

96/100 Security Operations

An analyst uses a standard account for daily work and a separate admin account only when needed. This applies:

✖ ACCESS DENIED

Patch your thinking with this:

Using elevated rights only when required limits the damage if a session is compromised.

✔ POLICY ENFORCED

Nicely done — that’s a keeper.

Using elevated rights only when required limits the damage if a session is compromised.

✖ ACCESS DENIED

Patch your thinking with this:

Using elevated rights only when required limits the damage if a session is compromised.

✖ ACCESS DENIED

Patch your thinking with this:

Using elevated rights only when required limits the damage if a session is compromised.

97/100 Security Operations

Backups are only truly reliable if the team also:

✔ INTEGRITY CONFIRMED

That’s foundation-solid — clean and correct.

Untested backups may fail when needed; restore testing verifies they actually work.

✖ THREAT DETECTED

No stress — here’s the fix:

Untested backups may fail when needed; restore testing verifies they actually work.

✖ THREAT DETECTED

No stress — here’s the fix:

Untested backups may fail when needed; restore testing verifies they actually work.

✖ THREAT DETECTED

No stress — here’s the fix:

Untested backups may fail when needed; restore testing verifies they actually work.

98/100 Security Operations

A clean-desk policy requiring sensitive documents to be locked away when unattended supports:

✖ ALERT RAISED

Every miss is a lesson. Takeaway:

A clean-desk policy prevents unauthorized viewing of sensitive information, supporting confidentiality.

✖ ALERT RAISED

Every miss is a lesson. Takeaway:

A clean-desk policy prevents unauthorized viewing of sensitive information, supporting confidentiality.

✖ ALERT RAISED

Every miss is a lesson. Takeaway:

A clean-desk policy prevents unauthorized viewing of sensitive information, supporting confidentiality.

✔ SECURED

Sharp. You’re thinking like a defender.

A clean-desk policy prevents unauthorized viewing of sensitive information, supporting confidentiality.

99/100 Security Operations

Defining an approved standard configuration for all workstations, so unauthorized changes can be spotted, creates a:

✖ CHECK FAILED

Reset and lock it in with this:

A configuration baseline is the approved standard build that later changes are measured against.

✖ CHECK FAILED

Reset and lock it in with this:

A configuration baseline is the approved standard build that later changes are measured against.

✔ VERIFIED

You’ve got the principle down. Textbook.

A configuration baseline is the approved standard build that later changes are measured against.

✖ CHECK FAILED

Reset and lock it in with this:

A configuration baseline is the approved standard build that later changes are measured against.

100/100 Security Operations

You receive an unexpected email attachment from an unknown sender at work. The BEST action is to:

✖ FLAGGED FOR REVIEW

Patch your thinking with this:

Unexpected attachments may be malware; the safe move is to avoid opening it and report it to security.

✔ DEFENSE HELD

Locked in — that’s the CC mindset.

Unexpected attachments may be malware; the safe move is to avoid opening it and report it to security.

✖ FLAGGED FOR REVIEW

Patch your thinking with this:

Unexpected attachments may be malware; the safe move is to avoid opening it and report it to security.

✖ FLAGGED FOR REVIEW

Patch your thinking with this:

Unexpected attachments may be malware; the safe move is to avoid opening it and report it to security.

FOUNDATIONS LOCKED IN — WELL DONE

Nice work, learner. You just drilled the fundamentals every cybersecurity career is built on — and every rep, right or wrong, is how it sticks.

Your live score is on the board below. Whatever the number, you showed up and put in the work today — that’s the part that compounds.

Gold means a strong area to lock in; the dashed tag means a domain worth another pass. Keep circling back — you’ve got this, friend.

CORRECT ANSWERED

These are original practice scenarios written for the Oluma community. CC® and ISC2® are trademarks or registered trademarks of ISC2, Inc. Oluma is not affiliated with or endorsed by ISC2. No official exam content is reproduced here — learn the concepts, not the dumps.