Candidates are encouraged to supplement their education and experience by reviewing relevant resources that pertain to the CC Exam Outline and identifying areas of study that may need additional attention.
View the full list of supplementary references at www.isc2.org/certifications/references.
ISC2 recommends that CC candidates review exam policies and procedures prior to registering for the examination. Read the comprehensive breakdown of this important information at www.isc2.org/Register-for-Exam.
View and download the latest PDF version of the Certified in Cybersecurity Exam Outline in the following languages:
CC – English | CC – Chinese | CC – Japanese | CC – German | CC – Spanish
ISC2 developed the Certified in Cybersecurity (CC) credential for newcomers to the field, to recognize the growing trend of people entering the cybersecurity workforce without direct IT experience. Getting Certified in Cybersecurity provides employers with the confidence that you have a solid grasp of the right technical concepts, and a demonstrated aptitude to learn on the job. As an ISC2 certification, those who hold the CC are backed by the world’s largest network of certified cybersecurity professionals helping them continue their professional development and earn new achievements and qualifications throughout their career.
The topics on the CC exam include:
The CC exam uses Computerized Adaptive Testing (CAT) for all exams.
| Length of exam | 2 hours |
| Number of items | 100-125 |
| Item format | Multiple choice and advanced item types |
| Passing grade | 700 out of 1000 points |
| Exam language availability | English, Chinese, Japanese, German, Spanish |
| Testing center | Pearson VUE Testing Center |
Notice: Chinese language CC exams are only available during select appointment windows.
| Domains | Average Weight |
|---|---|
| 1. Security Principles | 24% |
| 2. Security Governance | 17.3% |
| 3. Identity And Access Management (IAM) Concepts | 20% |
| 4. Networking and Cloud Security Concepts | 21.3% |
| 5. Security Operations and Incident Response | 17.3% |
| Total | 100% |
The Certified in Cybersecurity (CC) certification is the global gateway for individuals entering the cybersecurity workforce. As AI becomes a standard component of corporate technology, it is essential that even entry level professionals understand its security implications. For the CC Exam Outline, we have integrated foundational AI concepts across all five domains. This approach ensures that new practitioners can identify AI assets, recognize automated threats and support the governance frameworks that keep these emerging technologies secure.
At the foundational level, the CC Exam Outline introduces how AI impacts the core pillars of information security: Confidentiality, Integrity and Availability. Entry-level professionals understand how to apply the fundamental security principles to AI systems, specifically focusing on how data integrity is vital for preventing model poisoning and how privacy must be protected when handling AI training data. The integration also emphasizes Authentication, Authorization, and Accounting (AAA) alongside non-repudiation, ensuring that AI-generated actions and access remain traceable and secure.
Furthermore, this domain establishes the role of AI within the broader governance, risk and compliance (GRC) landscape. Candidates are aware that AI tools require a blend of technical, administrative, and physical controls, and are subject to the same organizational policies and legal requirements as traditional software. By understanding these high-level principles, new practitioners can support senior leadership in exercising due care and due diligence when adopting AI. Ultimately, this promotes a comprehensive security culture that aligns with the organization’s risk appetite, demands transparency and non-bias, and upholds the ISC2 Code of Ethics.
In this domain, the CC Exam Outline Incorporates how AI both complicates and enhances the resilience of an organization. From a response perspective, candidates understand the basics of how AI-driven tools can assist in the early identification and reporting of security incidents. The CC Exam Outline emphasizes the role of the entry-level practitioner in fostering a strong security awareness culture and completing updated security training to recognize how AI escalates social engineering and phishing attacks. Practitioners are expected to follow established playbooks that now account for these automated threats, ensuring they can provide valuable support during the initial triage of a suspected breach.
Regarding recovery and continuity, the integration focuses on the necessity of backing up not just traditional data, but the specific configurations and datasets that power AI services. The CC Exam Outline includes the concept of “Model Drift” as a potential Business Continuity (BC) and Disaster Recovery (DR) risk, where an AI’s declining performance could impact critical operations. Furthermore, candidates learn to support GRC planning by utilizing frameworks and tools to measure cybersecurity effectiveness. By tracking AI-specific Key Risk Indicators (KRI) through dashboards and reports, CC holders are prepared to assist in maintaining the availability of intelligent systems during and after a disruptive event.
Access control is the first line of defense. Candidates understand that just like human users, AI “bots” and automated service accounts must be managed through formal identity life cycle management. Using standard frameworks and tools, practitioners manage this entire process—from initial roles definition and provisioning, through regular access reviews, to final deprovisioning. The integration emphasizes logical access controls, specifically the Principle of Least Privilege and Separation of Duties (SoD). This ensures staff can verify that automated systems operate strictly within established access control models, holding only the permissions necessary to perform their designated tasks.
Additionally, the CC Exam Outline includes how AI is used to strengthen authentication through behavioral analysis. Candidates understand the foundational concepts of Multi- Factor Authentication (MFA) and how AI can help detect “impossible travel” or anomalous login patterns. This ensures that new professionals understand both how to secure the AI’s access and how AI serves as a silent partner in protecting user identities across the enterprise.
For network security, the CC Exam Outline incorporates the basics of how AI influences traffic monitoring and threat prevention. Entry-level practitioners must understand foundational concepts—including the Open Systems Interconnection (OSI) and Transmission Control Protocol/Internet Protocol (TCP/IP) models, Internet Protocol (IPv4/IPv6), and Virtual Private Networks (VPN) —to secure the pathways AI data travels. Candidates understand how AI-powered firewalls and Intrusion Detection Systems (IDS) go beyond simple signature matching, and how AI impacts the security of wireless networks and embedded systems. By understanding how these tools use machine learning to identify unusual network behavior, candidates are better equipped to monitor dashboards and report potential anomalies.
The integration also addresses network security architecture. The CC Exam Outline describes the importance of network segmentation (e.g., VLANs, micro-segmentation) to keep AI development environments isolated from sensitive production data. This foundational knowledge allows CC professionals to support a Defense in Depth strategy and the implementation of Zero Trust (ZT) principles, ensuring that the network remains a secure environment for high-value AI training data. ISC2 Exam Guidance for Artificial Intelligence 4Finally, because AI workloads heavily rely on scalable infrastructure, candidates must understand foundational cloud security. Practitioners are expected to recognize key cloud characteristics (such as rapid elasticity and resource pooling) and differentiate between various service and deployment models. Most importantly, candidates must understand the shared security model, ensuring they can accurately identify the security roles and responsibilities shared between the organization and the cloud service provider when hosting AI solutions.
In the final domain, the CC Exam Outline focuses on the day-to-day tasks of a security professional working alongside AI in security operations. This includes the foundational understanding of how Security Information and Event Management (SIEM) tools use AI for logging and monitoring, correlating data to reduce “alert fatigue.” Candidates know how to execute security event triage, leveraging cyber threat intelligence and threat frameworks to understand various threat actors and their motivations. This ensures practitioners can distinguish between a routine automated block and a high-priority event requiring human intervention, whether during live Incident Response Plan (IRP) execution or during simulated Incident Response (IR) exercises such as tabletops.
The integration also introduces the “Security of the AI Workspace,” emphasizing data security and asset protection. Candidates are prepared to identify the risks of data leakage when employees interact with public AI services, applying proper data handling (classification, masking, and sanitization) and encryption—from symmetric to quantum-resistant cryptography—to protect the organization. Furthermore, practitioners support configuration and change management alongside formal asset lifecycle management, ensuring that AI tools and underlying devices are securely maintained until their End of Life (EOL).
Finally, subtasks within this domain ensure that candidates understand the role of continuous security testing in an automated world. Entry-level staff support security readiness testing (including blue, purple, and red teaming) and application testing (such as vulnerability scanning and threat modeling) to validate AI-integrated defenses. By also remaining vigilant against physical penetration testing tactics like phishing and tailgating, candidates serve as effective “human firewalls,” protecting the organization’s data integrity across all fronts.