Exam objectivesCC

ISC2 Certified in Cybersecurity exam objectives

The published blueprint is the contract: the exam can only test what is on this list. Domains carry their official weightings, and objectives with a practice page link straight to questions written for that objective.

Titles and weightings from the official objectives. ISC2 exam page

Security Principles

26% of exam
  • 1.1 1.1 Understand the security concepts of information assurance.

  • 1.2 1.2 Understand the risk management process.

  • 1.3 1.3 Understand security controls.

  • 1.4 1.4 Understand (ISC)2 Code of Ethics.

  • 1.5 1.5 Understand governance processes.

Business Continuity, DR, and Incident Response

10% of exam
  • 2.1 2.1 Understand business continuity (BC).

  • 2.2 2.2 Understand disaster recovery (DR).

  • 2.3 2.3 Understand incident response.

Access Control Concepts

22% of exam
  • 3.1 3.1 Understand physical access controls.

  • 3.2 3.2 Understand logical access controls.

Network Security

24% of exam
  • 4.1 4.1 Understand computer networking.

  • 4.2 4.2 Understand network threats and attacks.

  • 4.3 4.3 Understand network security infrastructure.

Security Operations

18% of exam
  • 5.1 5.1 Understand data security.

  • 5.2 5.2 Understand system hardening.

  • 5.3 5.3 Understand best practice security policies.

  • 5.4 5.4 Understand security awareness training.

Keep reading

Every guide and cost breakdown, by vendor