Critical transition notice: Publication date is August 21, 2026. This package aligns to the upcoming official outline effective September 1, 2026. If the booked exam is before September 1, use the current outline effective October 1, 2025 instead. Always verify the outline attached to the booked appointment with ISC2; do not assume a study page determines the delivered form.
Upcoming ISC2 CC snapshot — effective September 1, 2026
The official upcoming outline lists a two-hour exam, 100–125 items, multiple-choice and advanced item types, a 700/1000 passing grade, Pearson VUE delivery, and CAT for listed languages. It states no specific prerequisites, cybersecurity work experience, or formal degree are required; basic IT knowledge is recommended. PrepKloud's 50-item distribution is an integer approximation of the official weights, not an official form.
24% · Bank 12Security Principles
17.3% · Bank 9Security Governance
20% · Bank 10Identity and Access Management Concepts
21.3% · Bank 11Networking and Cloud Security Concepts
17.3% · Bank 8Security Operations and Incident Response
1
Security principles, risk, controls, and ethics
Week 1Build the vocabulary used to make every later decision.
- Apply confidentiality, integrity, availability, authentication, authorization, accounting, non-repudiation, and privacy to simple scenarios.
- Trace risk from context and identification through assessment, treatment, monitoring, and communication.
- Separate regulations and laws from frameworks, policies, standards, procedures, and guidelines.
- Classify technical, administrative, and physical controls and explain why layered controls are needed.
- Practice due care, due diligence, professional conduct, evidence integrity, authorized disclosure, and the ISC2 Code of Ethics.
- Reject any study method based on live, recalled, leaked, copied, or dump questions.
2
Governance, resilience, awareness, and measurement
Week 2Connect security activity to leadership, obligations, and organizational resilience.
- Explain the purpose and importance of Governance, Risk, and Compliance and how frameworks and tools support—not replace—accountability.
- Distinguish business continuity, which sustains critical operations, from disaster recovery, which restores technology and data.
- Build awareness around social engineering, phishing, password protection, reporting, and leadership-supported culture.
- Define meaningful metrics and Key Risk Indicators with owners, sources, thresholds, quality checks, and decisions.
- Use dashboards, scorecards, and reports to communicate effectiveness without hiding missing data or gaming measures.
- Run discussion-only tabletop exercises in fictional scenarios with no production impact.
3
Identity lifecycle and logical access control
Week 3Treat access as a lifecycle, not a one-time login.
- Define roles and execute provisioning, review, role change, and deprovisioning.
- Use frameworks and tools to automate approved policy while preserving review, exception handling, and audit.
- Apply least privilege to people, administrators, contractors, applications, and service identities.
- Apply separation of duties to sensitive approval and transaction paths.
- Differentiate role-based access control, discretionary access control, mandatory access control, and other models by who sets policy and how access is decided.
- Test successful and denied access and remove orphaned or accumulated privileges.
4
Networking, segmentation, Zero Trust, and cloud
Weeks 4–5Reason from communication requirements and trust boundaries.
- Review OSI and TCP/IP concepts, IPv4, IPv6, VPNs, ports, protocols, applications, and firewall decisions.
- Identify wireless risks involving Wi-Fi and Bluetooth and the security needs of industrial, embedded, and IoT systems.
- Use firewall zones, VLANs, and micro-segmentation to constrain paths and lateral movement.
- Apply defense in depth so one control failure does not expose the entire environment.
- Apply Zero Trust by evaluating identity, device, context, and least privilege instead of trusting internal location.
- Learn cloud characteristics, IaaS/PaaS/SaaS, deployment models, and the shared security model.
5
Security operations, incident response, assets, and testing
Week 6+Turn data and controls into defensible daily operations.
- Classify and label data; distinguish masking and sanitization; compare symmetric, asymmetric, hashing, and planning for quantum-resistant cryptography.
- Collect and protect logs, create event use cases, prioritize and correlate alerts, and avoid treating every alert as proof.
- Use threat-actor context, cyber threat intelligence, and threat frameworks with explicit confidence and relevance.
- Follow and exercise an incident response plan, including data-handling requirements and tabletop or simulation exercises.
- Manage asset lifecycle, end-of-life technology, configuration baselines, approved changes, validation, and rollback.
- Differentiate blue, purple, and red teaming; vulnerability scanning; static and dynamic analysis; threat modeling; and physical testing. Perform technical or human testing only with explicit authorization.
- Complete three projects, review 40 cards, and answer the exact 12/9/10/11/8 approximation.
Three substantial defensive projects
Governance and resilience program
Create an invented risk register, policy hierarchy, control map, BC/DR priorities, awareness campaign, KRIs, dashboard, and ransomware tabletop.
Open projectsLeast-privilege segmented cloud lab
Exercise identity lifecycle, roles, access models, zones, firewall flows, VPN or private administration, Zero Trust, shared responsibility, logs, and teardown.
Open projectsDefensive operations and response
Protect synthetic data, centralize logs, triage events, exercise incident response, manage EOL and changes, and compare testing methods on owned targets only.
Open projects
Use every learning surface
50 original questions
Two 25-item files with zero-based answers, detailed reasoning, and official HTTPS references.40 unique flashcards
Recall the five September 2026 domains and their operational distinctions.3 defensive projects
Practice governance, IAM, segmentation, cloud, logs, response, testing, safety, and cleanup.Complete transition guide
Study the upcoming outline and verify the blueprint for the booked exam date.
Official sources
Live outline pageCurrent exam information, current outline, and the notice and link for the September 1, 2026 transition.
ISC2 CC exam outline page Code of EthicsProfessional obligations that inform responsible study and cybersecurity conduct.
ISC2 Code of Ethics
Frequently asked questions
Which outline does this package use?
The upcoming official ISC2 CC outline effective September 1, 2026.
What if the exam is booked before September 1?
Use the current October 1, 2025 outline and verify the blueprint attached to the appointment with ISC2. The current outline has different domain names and weights.
What is the upcoming exam format?
Two hours, 100–125 items, multiple-choice and advanced item types, and CAT as specified in the upcoming outline.
How is the 50-question bank allocated?
Exactly 12 Security Principles, 9 Security Governance, 10 IAM Concepts, 11 Networking and Cloud Security Concepts, and 8 Security Operations and Incident Response questions.
Is work experience required?
The upcoming outline states no specific prerequisites, cybersecurity work experience, or formal degree is required. Basic IT knowledge is recommended.
Do practice scores guarantee a pass?
No. The independent original practice bank is not the official 100–125-item CAT exam and cannot predict or guarantee a result.
Independence, transition, and safety disclaimer: ISC2 and CC names belong to ISC2. PrepKloud is independent and not affiliated with or endorsed by ISC2. This content targets the official outline effective September 1, 2026. Candidates testing earlier must use the current outline and verify their booked date. No dumps, recalled items, pass guarantee, job promise, or authorization to test real people or systems is provided.
Prepare with ethics, evidence, and safe practice
Combine official scope, original scenarios, spaced recall, and three defensive synthetic projects.