Certified in Cybersecurity Exam Outline Aug22
Certified in Cybersecurity Exam Outline Aug22
Certified in Cybersecurity Exam Outline Aug22
• Security Principles
• Business Continuity (BC), Disaster Recovery (DR) & Incident Response Concepts
• Access Controls Concepts
• Network Security
• Security Operations
Experience Requirements
There are no specific prerequisites to take the exam. It is recommended that candidates have basic
information technology (IT) knowledge. No work experience in cybersecurity or any formal educational
diploma/degree is required. The next step in the candidate’s career would drive to earning (ISC)2 expert-level
certifications, which require experience in the field.
CC Examination Weights
Domains Average Weight
Total 100%
» Technical controls
» Administrative controls
» Physical controls
» Policies
» Procedures
» Standards
» Regulations and laws
» Purpose » Purpose
» Importance » Importance
» Components » Components
» Purpose
» Importance
» Components
Domain 3:
Access Controls Concepts
3.1 Understand physical access controls
» Physical security controls (e.g., badge systems, gate entry, environmental design)
» Monitoring (e.g., security guards, closed-circuit television (CCTV), alarm systems, logs)
» Authorized versus unauthorized personnel
» Networks (e.g., Open Systems Interconnection (OSI) model, Transmission Control Protocol/Internet Protocol
(TCP/IP) model, Internet Protocol version 4 (IPv4), Internet Protocol version 6 (IPv6), WiFi)
» Ports
» Applications
» Types of threats (e.g., distributed denial-of-service (DDoS), virus, worm, Trojan, man-in-the-middle (MITM),
side-channel)
» Identification (e.g., intrusion detection system (IDS), host-based intrusion detection system (HIDS), network
intrusion detection system (NIDS))
» Prevention (e.g., antivirus, scans, firewalls, intrusion prevention system (IPS))
» On-premises (e.g., power, data center/closets, Heating, Ventilation, and Air Conditioning (HVAC),
environmental, fire suppression, redundancy, memorandum of understanding (MOU)/memorandum of
agreement (MOA))
» Design (e.g., network segmentation (demilitarized zone (DMZ), virtual local area network (VLAN), virtual
private network (VPN), micro-segmentation), defense in depth, Network Access Control (NAC) (segmentation
for embedded systems, Internet of Things (IoT))
» Cloud (e.g., service-level agreement (SLA), managed service provider (MSP), Software as a Service (SaaS),
Infrastructure as a Service (IaaS), Platform as a Service (PaaS), hybrid)
Legal Information
For any questions related to (ISC)²’s legal policies, please contact
the (ISC)² Legal Department at legal@isc2.org.
Any Questions?
Contact (ISC)² Candidate Services in your region:
Americas
Phone: +1-866-331-ISC2 (4722)
Email: info@isc2.org
Asia Pacific
Phone: +852-5803-5662
Email: isc2asia@isc2.org