How to prepare for the ISC2 CC exam: a study plan
Preparing for the ISC2 Certified in Cybersecurity (CC) means building solid conceptual understanding across its five foundational security domains — it is a beginner exam that rewards understanding core security principles rather than hands-on technical skill. That makes it approachable, but not trivial: the CC introduces genuine security vocabulary and models that a newcomer has never had reason to learn, and it expects you to reason about them, not just recognise the terms. This article covers the five domains, a sensible study approach, a realistic timeline, the traps that catch beginners, the exam mechanics — including the fee, which has changed — and the readiness signal to book on.
The five domains
The CC syllabus is organised into five domains: Security Principles; Business Continuity, Disaster Recovery and Incident Response concepts; Access Control concepts; Network Security; and Security Operations. None of them assume prior security experience, but together they cover a genuinely broad slice of the field — from the CIA triad and risk terminology, through how organisations plan for and recover from disruption, to the models that govern who can access what, the fundamentals of securing a network, and the day-to-day practices that keep an environment monitored and maintained.
Because it is an entry-level exam, depth matters less than breadth here. You are not expected to configure a firewall or write an incident response plan — you are expected to understand what these things are, why they exist, and how the concepts relate to each other. Study each domain deliberately rather than assuming general IT familiarity will carry you through; the access-control and network-security domains in particular introduce models and terminology that do not come up in everyday non-security work.
The study approach
You do not need an expensive bootcamp to prepare well. A sensible stack looks like this:
- ISC2’s own training — ISC2 has historically offered free, self-paced online training for the CC; check their site for the current offering, since programmes and pricing do shift.
- The official exam outline — ISC2 publishes the exact domain breakdown and weighting; treat it as your syllabus, not a course you happened to find.
- A structured study guide — a book or guide that follows the five domains in order keeps your revision aligned with what is actually examined.
- Practice questions — the fastest way to find which domain is weakest before you spend the exam fee finding out the hard way.
- Plain-language definitions — for each key term (least privilege, defence in depth, the CIA triad, RAID, incident response phases) be able to explain it in a sentence, not just recognise it in a list.
A realistic timeline
There is no single correct number of weeks — it depends entirely on how much of the material is new to you. Someone already working in IT with some exposure to security concepts might be ready after a few focused weeks; a genuine beginner to both IT and security should expect to spend meaningfully longer working through the five domains from scratch. Resist false precision here: judge your readiness by mock performance, not by a calendar date you picked in advance.
Our ISC2 CC certification guide covers what the certification is for and how it fits a beginner’s path into security in more depth — this article assumes you already know you want it and focuses on how to study.
What trips people up
The most common problem is underestimating the breadth. Five domains sounds manageable, but each one introduces its own vocabulary and models, and candidates who study intensively in one area — network security, say, because it feels the most technical — often arrive under-prepared in the others, particularly business continuity and access control concepts, which have no obvious analogue in general IT work.
The second trap is security-specific terminology used precisely. Terms like authentication versus authorisation, or the different access-control models, sound similar to everyday language but mean specific, distinct things on the exam, and distractor options are often built from that confusion. When you revise, write your own one-sentence definitions rather than relying on a vague sense of what a term means.
Exam mechanics, and the fee is no longer free
The CC is 100 multiple-choice questions in 2 hours, with a pass mark of 700 out of 1000, delivered at Pearson VUE test centres. It is important to be clear on one point that catches people out: the CC is not free anymore. ISC2’s earlier “One Million Certified” programme, which waived the exam fee, closed to new enrolments — a fee now applies, roughly $199 at the time of writing, though you should confirm the current figure on ISC2’s own site before budgeting, since it can change.
The certification is also not a one-off achievement: keeping it valid over its three-year cycle requires paying an annual maintenance fee (AMF) and earning continuing professional education (CPE) credits, so factor the ongoing commitment into your decision, not just the exam itself.
The readiness signal
Book the exam once you are consistently clearing the 700/1000 pass mark across full-length, timed mock exams — not once, but repeatedly, with no domain dragging noticeably behind the rest. A single strong mock can be luck; several in a row across different question sets is preparation. If one domain keeps pulling your score down, spend a few focused days there rather than repeating a general pass through everything you already know reasonably well. If you are weighing whether the CC is the right first step at all, our piece on starting a career in cybersecurity covers where this certification fits alongside other early options.
Original practice questions, timed mock exams and revision notes. No card, nothing to pay.
Questions, answered
Get the study material as it lands
Occasional email when we publish a new certification, guide or set of practice questions. No spam, unsubscribe in one click.