ISC2 Certified in Cybersecurity (CC) Cert Prep

ISC2 Certified in Cybersecurity (CC) Cert Prep

4h 57mBeginner2026-08-27

Authors

Mike Chapple

Mike Chapple

Teaching Professor at the University of Notre Dame

Course details

The ISC2 Certified in Cybersecurity (CC) certification is one of the most accessible entry points into the field. It requires no work experience and no formal degree, only basic IT knowledge. Instructor Mike Chapple covers every topic on the exam, one domain at a time. He starts with security principles: the CIA triad, authentication, non-repudiation, and how privacy fits into security work. He then moves into security governance, including risk management, regulatory frameworks, business continuity, disaster recovery, and security awareness. Mike explores identity and access management (IAM), from the identity lifecycle to access control models, and covers the essentials of networking and cloud security. He finishes the course with security operations and incident response, including cryptography, logging, threat intelligence, IR programs, asset protection, and how AI is reshaping the field.

Concepts

Introduction

  • Cybersecurity
  • What you should know
  • Study resources

The CC Certification

  • The Certified in Cybersecurity (CC) exam
  • Computerized adaptive testing
  • Careers in information security
  • The value of certification

Domain 1 - Security Principles

  • Overview of the Security Principles domain

Cybersecurity Concepts

  • Confidentiality
  • Integrity
  • Availability
  • Authentication, authorization, and accounting (AAA)
  • Password security
  • Multifactor authentication
  • Non-repudiation
  • Privacy

Risk Management

  • Understanding risks
  • Risk assessment
  • Risk treatment

Governance Concepts

  • Regulations and laws
  • Frameworks and guidelines
  • Security policy framework
  • Best-practice security policies

Cybersecurity Controls

  • Security control categories

Professional and Ethical Conduct

  • Professional conduct, due care, and due diligence
  • ISC2 Code of Ethics

Domain 2 - Security Governance

  • Overview of the Security Governance domain

Governance, Risk, and Compliance (GRC)

  • Introducing governance, risk, and compliance
  • GRC frameworks and tools

Business Continuity

  • Business continuity planning
  • Business continuity controls
  • High availability and fault tolerance

Disaster Recovery

  • Disaster recovery planning
  • Backups
  • Disaster recovery sites
  • Testing BC DR plans

Security Awareness

  • Building a security awareness program
  • Social engineering
  • Phishing and impersonation attacks

Measuring Cybersecurity Effectiveness

  • Cybersecurity metrics and key risk indicators
  • Dashboards, scorecards, and reports

Domain 3 - Identity and Access Management (IAM) Concepts

  • Overview of the Identity and Access Management Concepts domain

Identity Life Cycle Management

  • The identity lifecycle
  • Account and privilege management
  • Account monitoring
  • Provisioning and deprovisioning
  • IAM Frameworks and Tools

Logical Access Controls

  • Least privilege and separation of duties
  • Access Control Models

Domain 4 - Networking and Cloud Security Concepts

  • Overview of the Networking and Cloud Security Concepts Domain

Network Security

  • Network types
  • Introducing TCP IP
  • IP Addresses and DHCP
  • Network ports
  • Firewalls
  • Virtual private networks (VPNs)
  • Securing wireless networks
  • Wireless Encryption
  • Industrial control systems (ICS)
  • Internet of Things (IoT)

Network Security Architecture

  • Defense in depth
  • Zero Trust
  • Network segmentation and firewall zones
  • VLANs
  • Microsegmentation

Cloud Security

  • What is the cloud
  • Cloud service models
  • Cloud deployment models
  • Shared responsibility model

Domain 5 - Security Operations and Incident Response

  • Overview of the Security Operations and Incident Response domain

Data Security

  • Data classification
  • Data handling
  • The data lifecycle
  • Understanding encryption
  • Symmetric and Asymmetric Cryptography
  • Hash functions
  • Quantum-resistant cryptography

Security Operations

  • Logging and monitoring
  • Intrusion detection and prevention
  • Security event triage
  • Malware and malicious code
  • Threat actors
  • Cyber threat intelligence
  • Threat frameworks

Incident Response

  • Building an incident response program
  • Creating an incident response team
  • Incident communications plan
  • Incident identification
  • Incident response exercises

Asset Protection

  • Asset lifecycle management
  • Configuration management
  • Change management

Security Testing

  • Security readiness testing
  • Vulnerability Scanning
  • Application testing
  • Physical penetration testing

AI and Cybersecurity

  • AI fundamentals for cybersecurity
  • AI threats and risks
  • AI as a Defensive Tool
  • Governing AI systems

Continuing Your Studies

  • Get ready for the exam
100,000 Toman