Professional Conduct and Reporting Obligations
CC tests judgement as well as knowledge. These questions have a consistent shape: act within authorisation, protect the public, and escalate rather than improvise.
Exam tip. Ethics answers reward restraint. Publishing a flaw publicly, or exploiting it to prove a point, is never correct.
Zero Trust and the Dissolving Perimeter
Perimeter-based security assumed that internal network location implied trust. Remote work, cloud services and insider threat broke that assumption, and zero trust is the response.
Exam tip. Zero trust is an architectural model, not a product. Answers offering a single appliance that delivers zero trust are wrong.
Policies, Standards, Procedures and Guidelines
These four document types form a hierarchy from high-level intent to step-by-step detail. Only one of them is optional, and that fact is tested directly.
Exam tip. Distinguish externally imposed law from contractual standards and from self-imposed internal policy.
Least Privilege, Separation of Duties and Defence in Depth
These three principles recur across every domain. Most scenario questions are really asking which of them a described arrangement implements.
Exam tip. Two people required to complete one process is always separation of duties, never least privilege.
The ISC2 Code of Ethics Canons
The four canons are ordered, and that order matters. When two duties conflict, the lower-numbered canon takes precedence over the higher-numbered one.
Exam tip. When an ethics question pits client interest against public safety, the public comes first.
The CIA Triad and Non-repudiation
Every security control ultimately serves confidentiality, integrity or availability. Most CC questions can be answered by identifying which of the three a described control protects, so learn the mapping rather than the definitions alone.
Exam tip. Read the control and ask which of the three goals it protects. Hashing never provides confidentiality, and encryption alone never provides non-repudiation.
Authentication Factors and Multifactor Authentication
Multifactor authentication requires factors from different categories. The exam repeatedly offers two items from the same category as a distractor, so check the category rather than counting the items.
Exam tip. Password plus PIN is the classic trap. Both are something you know, so it is single factor.
Risk Terminology and the Four Risk Treatments
Risk vocabulary is tested precisely. Learn the chain of threat, vulnerability, asset and impact, and be able to name which of the four treatments a described decision represents.
Exam tip. Insurance is always transference. If the activity still happens, it cannot be avoidance.
Control Types and Categories
Controls are classified two ways at once: by category (who or what implements them) and by function (what they do). Questions often give a control and ask for one classification or the other.
Exam tip. Cameras never prevent. If the question asks how to stop an event happening, a camera is wrong.
Privacy, PII and Regulatory Regimes
CC expects you to tell the major regulations apart by the data they govern, and to distinguish privacy from confidentiality. They are related but not the same thing.
Exam tip. PCI DSS is contractual, not law. Confusing statutory obligations with contractual ones is a common error.
Deterrent, Compensating and the Full Control Picture
Beyond preventive, detective and corrective there are two more functions that appear in CC questions. Knowing all five removes most ambiguity from control-classification items.
Exam tip. If a question says a required control is not feasible and something else was used instead, the answer is compensating.
Quantitative Risk Terms and Assessment Types
CC keeps risk mathematics light but expects the vocabulary. Know the difference between qualitative and quantitative assessment and what each term measures.
Exam tip. A control is worth deploying when it costs less than the ALE it removes. Residual risk always requires explicit acceptance.