Entry-Level Cybersecurity Certification
Principles · BC/DR/IR · Access Control · Network · Operations · 100 questions
⚠️ Exam Rules
| Questions in this Techclick bank | 100 |
|---|---|
| Timer | 120 min |
| Techclick practice target | 70% |
| Official exam code | ISC2CC |
A hospital is selecting controls and wants to anchor every decision to the three core security objectives. Which set correctly names the CIA triad?
Correct: A. The CIA triad is Confidentiality, Integrity, and Availability, the foundational objectives every control supports. The other choices are incorrect because they swap in unrelated terms such as compliance, auditing, or cryptography, which are activities or tools rather than the three core security goals themselves.
A finance team stores customer account numbers and must keep them secret from anyone not authorized to view them. Which objective and control pair best supports this goal?
Correct: B. Keeping data secret from unauthorized parties is confidentiality, best enforced with encryption plus access controls. Availability and redundancy address uptime, not secrecy; integrity and hashing detect tampering rather than prevent disclosure; logging supports accountability but does not by itself keep data confidential, so those options are incorrect.
An auditor needs assurance that financial records have not been altered since they were approved. Which combination of mechanisms best provides integrity?
Correct: C. Integrity is verified using hashing, digital signatures, and version control, which detect unauthorized changes and prove a record matches its approved state. Load balancing and RAID support availability, not change detection, and encryption protects confidentiality, so they do not directly assure that data has remained unaltered.
An e-commerce site must stay reachable during a holiday traffic surge and a possible flood of malicious requests. Which approach best protects availability?
Correct: D. Availability ensures systems are accessible when needed, achieved through redundancy, fault tolerance, and DDoS protection. Encryption and password hashing protect confidentiality, while multifactor authentication strengthens access control; none of these keep a service reachable under load, so they are incorrect for an availability goal.
A user enters a username and a one-time code from a token before the system grants any access. This act of confirming the claimed identity is best described as which step?
Correct: A. Authentication verifies a claimed identity using one or more factors, such as a token code. Identification is only the initial claim (the username), authorization decides what an already-verified user may do, and accounting logs activity afterward, so those options describe different steps in the access process and are incorrect here.
Last updated:
Yes. You can start, finish and score it for free, and download the Techclick practice certificate.
This bank has 100 original scenario-based questions with a 120-minute timer and a 70% Techclick practice target.
The official exam code is ISC2CC (ISC2).
No. They are original practice questions written by Techclick. This is not the vendor's official exam and not leaked dumps.
Score 70% or higher to get a Techclick practice certificate and LinkedIn badge. It is not an official ISC2 certification.
Related practice tests: CISSP, ISC2 CCSP, ISC2 CGRC, ISC2 SSCP (linked below).

You earned it — let the world know!
