Security Principles

Worth 26% of the ISC2 Certified in Cybersecurity (CC) exam. CertClue has 103 questions on this objective.

What this objective covers

Professional Conduct and Reporting Obligations

CC tests judgement as well as knowledge. These questions have a consistent shape: act within authorisation, protect the public, and escalate rather than improvise.

Exam tip. Ethics answers reward restraint. Publishing a flaw publicly, or exploiting it to prove a point, is never correct.

Zero Trust and the Dissolving Perimeter

Perimeter-based security assumed that internal network location implied trust. Remote work, cloud services and insider threat broke that assumption, and zero trust is the response.

Exam tip. Zero trust is an architectural model, not a product. Answers offering a single appliance that delivers zero trust are wrong.

Policies, Standards, Procedures and Guidelines

These four document types form a hierarchy from high-level intent to step-by-step detail. Only one of them is optional, and that fact is tested directly.

Exam tip. Distinguish externally imposed law from contractual standards and from self-imposed internal policy.

Least Privilege, Separation of Duties and Defence in Depth

These three principles recur across every domain. Most scenario questions are really asking which of them a described arrangement implements.

Exam tip. Two people required to complete one process is always separation of duties, never least privilege.

The ISC2 Code of Ethics Canons

The four canons are ordered, and that order matters. When two duties conflict, the lower-numbered canon takes precedence over the higher-numbered one.

Exam tip. When an ethics question pits client interest against public safety, the public comes first.

The CIA Triad and Non-repudiation

Every security control ultimately serves confidentiality, integrity or availability. Most CC questions can be answered by identifying which of the three a described control protects, so learn the mapping rather than the definitions alone.

Exam tip. Read the control and ask which of the three goals it protects. Hashing never provides confidentiality, and encryption alone never provides non-repudiation.

Authentication Factors and Multifactor Authentication

Multifactor authentication requires factors from different categories. The exam repeatedly offers two items from the same category as a distractor, so check the category rather than counting the items.

Exam tip. Password plus PIN is the classic trap. Both are something you know, so it is single factor.

Risk Terminology and the Four Risk Treatments

Risk vocabulary is tested precisely. Learn the chain of threat, vulnerability, asset and impact, and be able to name which of the four treatments a described decision represents.

Exam tip. Insurance is always transference. If the activity still happens, it cannot be avoidance.

Control Types and Categories

Controls are classified two ways at once: by category (who or what implements them) and by function (what they do). Questions often give a control and ask for one classification or the other.

Exam tip. Cameras never prevent. If the question asks how to stop an event happening, a camera is wrong.

Privacy, PII and Regulatory Regimes

CC expects you to tell the major regulations apart by the data they govern, and to distinguish privacy from confidentiality. They are related but not the same thing.

Exam tip. PCI DSS is contractual, not law. Confusing statutory obligations with contractual ones is a common error.

Deterrent, Compensating and the Full Control Picture

Beyond preventive, detective and corrective there are two more functions that appear in CC questions. Knowing all five removes most ambiguity from control-classification items.

Exam tip. If a question says a required control is not feasible and something else was used instead, the answer is compensating.

Quantitative Risk Terms and Assessment Types

CC keeps risk mathematics light but expects the vocabulary. Know the difference between qualitative and quantitative assessment and what each term measures.

Exam tip. A control is worth deploying when it costs less than the ALE it removes. Residual risk always requires explicit acceptance.

Practice questions

Free, with the answer and the reasoning. No account needed.

1. A security awareness training programme is best classified as which type of control?

  • A. Administrativecorrect
  • B. Technical
  • C. Physical
  • D. Compensating

Administrative controls are the policies, procedures, training and personnel practices that direct human behaviour. Technical controls are implemented in hardware or software, and physical controls act on the tangible environment such as locks, fences and guards.

2. An organisation uses a firewall, endpoint protection, network segmentation and user training together. Which principle is being applied?

  • A. Least privilege
  • B. Non-repudiation
  • C. Data minimisation
  • D. Defence in depthcorrect

Defence in depth layers multiple independent controls so that the failure of any one does not expose the organisation. No single control is assumed to be perfect.

3. An organisation encrypts a customer database so that only authorised staff can read it. Which element of the CIA triad does this primarily protect?

  • A. Confidentialitycorrect
  • B. Integrity
  • C. Availability
  • D. Authentication

Encryption prevents unauthorised parties from reading data, which is the definition of confidentiality. Integrity concerns whether data has been altered, availability concerns whether it is accessible when needed, and authentication is the act of proving identity.

Work the whole objective

The full ISC2 Certified in Cybersecurity bank, the study notes behind these summaries, and a readiness score that tells you which objective to revise next. Free, no paid tier.

Take the free ISC2 Certified in Cybersecurity practice test

The other ISC2 Certified in Cybersecurity objectives