ISC2 Certified in Cybersecurity (CC) Cert Prep
4h 57mBeginner2026-08-27
Authors

Mike Chapple
Teaching Professor at the University of Notre Dame
Course details
The ISC2 Certified in Cybersecurity (CC) certification is one of the most accessible entry points into the field. It requires no work experience and no formal degree, only basic IT knowledge. Instructor Mike Chapple covers every topic on the exam, one domain at a time. He starts with security principles: the CIA triad, authentication, non-repudiation, and how privacy fits into security work. He then moves into security governance, including risk management, regulatory frameworks, business continuity, disaster recovery, and security awareness. Mike explores identity and access management (IAM), from the identity lifecycle to access control models, and covers the essentials of networking and cloud security. He finishes the course with security operations and incident response, including cryptography, logging, threat intelligence, IR programs, asset protection, and how AI is reshaping the field.
Concepts
Introduction
- Cybersecurity
- What you should know
- Study resources
The CC Certification
- The Certified in Cybersecurity (CC) exam
- Computerized adaptive testing
- Careers in information security
- The value of certification
Domain 1 - Security Principles
- Overview of the Security Principles domain
Cybersecurity Concepts
- Confidentiality
- Integrity
- Availability
- Authentication, authorization, and accounting (AAA)
- Password security
- Multifactor authentication
- Non-repudiation
- Privacy
Risk Management
- Understanding risks
- Risk assessment
- Risk treatment
Governance Concepts
- Regulations and laws
- Frameworks and guidelines
- Security policy framework
- Best-practice security policies
Cybersecurity Controls
- Security control categories
Professional and Ethical Conduct
- Professional conduct, due care, and due diligence
- ISC2 Code of Ethics
Domain 2 - Security Governance
- Overview of the Security Governance domain
Governance, Risk, and Compliance (GRC)
- Introducing governance, risk, and compliance
- GRC frameworks and tools
Business Continuity
- Business continuity planning
- Business continuity controls
- High availability and fault tolerance
Disaster Recovery
- Disaster recovery planning
- Backups
- Disaster recovery sites
- Testing BC DR plans
Security Awareness
- Building a security awareness program
- Social engineering
- Phishing and impersonation attacks
Measuring Cybersecurity Effectiveness
- Cybersecurity metrics and key risk indicators
- Dashboards, scorecards, and reports
Domain 3 - Identity and Access Management (IAM) Concepts
- Overview of the Identity and Access Management Concepts domain
Identity Life Cycle Management
- The identity lifecycle
- Account and privilege management
- Account monitoring
- Provisioning and deprovisioning
- IAM Frameworks and Tools
Logical Access Controls
- Least privilege and separation of duties
- Access Control Models
Domain 4 - Networking and Cloud Security Concepts
- Overview of the Networking and Cloud Security Concepts Domain
Network Security
- Network types
- Introducing TCP IP
- IP Addresses and DHCP
- Network ports
- Firewalls
- Virtual private networks (VPNs)
- Securing wireless networks
- Wireless Encryption
- Industrial control systems (ICS)
- Internet of Things (IoT)
Network Security Architecture
- Defense in depth
- Zero Trust
- Network segmentation and firewall zones
- VLANs
- Microsegmentation
Cloud Security
- What is the cloud
- Cloud service models
- Cloud deployment models
- Shared responsibility model
Domain 5 - Security Operations and Incident Response
- Overview of the Security Operations and Incident Response domain
Data Security
- Data classification
- Data handling
- The data lifecycle
- Understanding encryption
- Symmetric and Asymmetric Cryptography
- Hash functions
- Quantum-resistant cryptography
Security Operations
- Logging and monitoring
- Intrusion detection and prevention
- Security event triage
- Malware and malicious code
- Threat actors
- Cyber threat intelligence
- Threat frameworks
Incident Response
- Building an incident response program
- Creating an incident response team
- Incident communications plan
- Incident identification
- Incident response exercises
Asset Protection
- Asset lifecycle management
- Configuration management
- Change management
Security Testing
- Security readiness testing
- Vulnerability Scanning
- Application testing
- Physical penetration testing
AI and Cybersecurity
- AI fundamentals for cybersecurity
- AI threats and risks
- AI as a Defensive Tool
- Governing AI systems
Continuing Your Studies
- Get ready for the exam