All certifications / CC / Cheat sheet
CC 2026 outline cheat sheet
Domain 1: Security principles (24%)
Exam tips
- When a question asks which principle is affected, pick the one that was lost first and most directly. Ransomware that only encrypts files is primarily an availability problem; ransomware that also steals data adds a confidentiality loss.
- Do not confuse authentication (who are you?) with authorization (what may you do?). Also remember that shared or generic accounts break accountability and non-repudiation, a favorite exam scenario.
- Count factor types, not steps. Password plus security question is one factor used twice. Password plus fingerprint, or smart card plus PIN, is true multi-factor authentication.
- Exam scenarios often mix up threat and vulnerability. Ask: is this something that could cause harm (threat) or a weakness that lets harm happen (vulnerability)? A hacker is a threat; a missing patch is a vulnerability.
- Buying insurance is transference, not mitigation. Doing nothing because the cost of a control exceeds the ALE is acceptance, and it must be a documented decision by someone with authority.
- Always separate the two classification axes. 'Administrative, technical, physical' describes how a control is built; 'preventive, detective, corrective, deterrent' describes what it does. A question may ask for either one.
- Memorize the four canons in order: society, honorable and legal, principals, profession. When canons conflict, the one higher on the list usually wins.
- Map AI risks to the triad: poisoning and bias are integrity problems, data leakage through models or prompts is confidentiality, and overloaded or single-source AI services are availability.
Key terms
- Confidentiality
- Keeping information from being disclosed to unauthorized people, processes or devices.
- Integrity
- Assurance that data and systems are accurate, complete and changed only in authorized ways.
- Availability
- Timely and reliable access to information and systems for authorized users.
- Sensitivity
- A measure of how much harm would result from unauthorized disclosure of information.
- DAD triad
- Disclosure, alteration and destruction or denial: the attacker-side opposites of confidentiality, integrity and availability.
- Authentication
- Verifying that a claimed identity is genuine, for example with a password, token or biometric.
- Authorization
- Deciding what an authenticated identity is permitted to access or do.
- Accounting
- Recording the actions of authenticated users so they can be reviewed and traced; also called auditing.
- Non-repudiation
- Assurance that someone cannot credibly deny having performed an action, commonly provided by digital signatures and reliable logs.
- Privacy
- An individual's right to control the collection, use and sharing of information about them.
- PII
- Personally identifiable information: data that can identify a specific individual.
- Knowledge factor
- Something you know, such as a password or PIN.
- Possession factor
- Something you have, such as a smart card, hardware key or authenticator app.
- Inherence factor
- Something you are, meaning a biometric trait such as a fingerprint or face.
- Multi-factor authentication (MFA)
- Authentication that requires evidence from two or more different factor types.
- False acceptance rate
- How often a biometric system accepts an impostor; also called a Type II error.
- Crossover error rate
- The point where false acceptance and false rejection rates are equal, used to compare biometric systems.
- Asset
- Anything of value to an organization that needs protection, such as data, systems, people or reputation.
- Threat
- Any potential cause of harm to an asset, whether human, natural or technical.
- Vulnerability
- A weakness that a threat could exploit.
- Likelihood
- The probability that a threat will exploit a vulnerability in a given period.
- Impact
- The magnitude of harm that would result if a risk were realized.
- Risk register
- A document listing identified risks with their details, owners and treatments.
- Qualitative assessment
- Rating risks with descriptive scales such as low, medium and high, based on judgment.
- Quantitative assessment
- Rating risks in monetary terms using values such as SLE, ARO and ALE.
- Annualized loss expectancy (ALE)
- Expected yearly loss from a risk, calculated as SLE multiplied by ARO.
- Risk transference
- Shifting the financial impact of a risk to another party, for example through insurance.
- Residual risk
- The risk that remains after controls have been applied.
- Administrative control
- A policy, procedure or practice that directs people's behavior, such as training or background checks.
- Technical control
- A control implemented in hardware or software, such as a firewall or encryption.
- Physical control
- A control that protects facilities and equipment, such as locks, fences or guards.
- Preventive control
- A control that stops an incident from occurring.
- Detective control
- A control that identifies an incident during or after its occurrence.
- Compensating control
- An alternative control used when the primary control cannot be implemented.
- Preamble
- The introduction to the ISC2 Code of Ethics stating that members must adhere, and be seen to adhere, to the highest ethical standards as a condition of certification.
- Canon
- One of the four core principles of the ISC2 Code of Ethics, listed in priority order.
- Principal
- The employer, client or other party a professional serves.
- Ethics complaint
- A formal report to ISC2 alleging that a member violated the Code of Ethics.
- Data poisoning
- Deliberately corrupting a model's training data so it learns incorrect or malicious behavior.
- Data provenance
- Records of where data came from and how it has been changed, used to trust training data.
- Prompt injection
- Crafted input that manipulates a language model into ignoring its instructions or revealing data.
- Explainability
- The ability to describe in understandable terms how an AI system reached a particular output.
- Algorithmic bias
- Systematic unfairness in a model's outputs toward certain groups, often inherited from training data.
Domain 2: Security governance (17%)
Exam tips
- Senior management is always ultimately accountable for security, even when tasks are delegated. And remember: being compliant does not mean being secure.
- The only non-mandatory document in the hierarchy is the guideline. Policies are broad and set by leadership; procedures are the most detailed.
- PCI DSS is enforced by contract, not by law. GDPR applies based on whose data is processed, not where the company is headquartered.
- The security team advises on risk; the business owner accepts it. If an exam answer has the security analyst accepting risk for a business unit, it is usually wrong.
- Outsourcing transfers work, not accountability. Expect the exam to favor answers that put security requirements, breach notification and right to audit into the contract before the relationship begins.
- Awareness is general and for everyone; training is job-specific. A strong security culture encourages fast reporting of mistakes rather than punishing people who admit them.
- KPIs look back at performance; KRIs look ahead at rising risk. Reports to executives should use business terms and compare risk with appetite and tolerance, not list raw technical counts.
Key terms
- Governance
- The structures and processes by which leadership directs and controls the organization, including its security program.
- Compliance
- Meeting and being able to prove adherence to laws, regulations, contracts, standards and policies.
- Chief information security officer (CISO)
- The senior leader responsible for an organization's information security program.
- Due care
- Taking the reasonable protective actions a prudent person would take.
- Due diligence
- The ongoing investigation and verification that protections are appropriate and working.
- Data owner
- A business leader accountable for a set of data, including its classification and who may access it.
- Policy
- A high-level, mandatory statement of management intent approved by senior leadership.
- Standard
- A mandatory, specific requirement that supports a policy, often naming technologies or values.
- Procedure
- Detailed, step-by-step instructions for performing a task consistently.
- Baseline
- A mandatory minimum security configuration for a type of system.
- Guideline
- A non-mandatory recommendation or best-practice suggestion.
- Regulation
- A detailed rule issued by a government agency that has the force of law.
- GDPR
- The EU General Data Protection Regulation, protecting the personal data of people in the EU.
- HIPAA
- A US law that protects health information held by healthcare organizations and their business associates.
- PCI DSS
- The Payment Card Industry Data Security Standard, a contractual standard for protecting payment card data.
- Jurisdiction
- The legal authority that applies based on location of the organization, data or people involved.
- Risk appetite
- The overall amount and type of risk an organization is willing to pursue or retain to meet its objectives.
- Risk tolerance
- The acceptable, usually measurable, variation around risk appetite for a specific objective.
- Risk owner
- The person accountable for managing a particular risk, including accepting residual risk.
- Risk capacity
- The maximum amount of risk an organization can absorb before it can no longer meet its obligations.
- Risk exception
- A formally approved and documented deviation from a policy or control, with the risk accepted by its owner.
- Third-party risk
- Risk arising from vendors, suppliers, contractors and other external parties an organization relies on.
- Service level agreement (SLA)
- A contract section defining measurable service levels, such as uptime, and remedies if they are not met.
- Right to audit
- A contract clause allowing the customer to review or test the vendor's security controls.
- Supply chain attack
- An attack that compromises a trusted supplier's product or service to reach its customers.
- Non-disclosure agreement (NDA)
- A contract in which parties agree to protect each other's confidential information.
- Social engineering
- Manipulating people into revealing information or taking actions that weaken security.
- Spear phishing
- A phishing attack tailored to a specific individual or small group.
- Business email compromise
- Fraud in which attackers impersonate a trusted party by email to trick staff into sending money or data.
- Pretexting
- Creating a false scenario or identity to persuade a victim to share information or grant access.
- Security culture
- The shared values and behaviors that make secure practices normal throughout an organization.
- Metric
- A quantifiable measurement tracked over time to evaluate some aspect of security.
- Key performance indicator (KPI)
- A measure of how well a process or control is performing against a target.
- Key risk indicator (KRI)
- A forward-looking measure that warns when risk is rising toward or beyond tolerance.
- Dashboard
- A visual display summarizing key metrics and their status for quick review.
- Mean time to detect (MTTD)
- The average time between an incident starting and the organization detecting it.
Domain 3: Identity & access management concepts (20%)
Exam tips
- Identification is the claim; authentication is the proof. If a question describes typing a username only, that is identification, not authentication.
- Separation of duties counters fraud by one person but is defeated by collusion. Job rotation and mandatory vacations help detect collusion and hidden fraud.
- For an involuntary termination, disable access before or at the moment the person is informed. Role changes should remove old access, not just add new access.
- Ask who decides: the owner (DAC), the system using labels and clearances (MAC), the job role (RBAC) or global administrator rules (rule-based). MAC is the most restrictive; DAC is the most flexible.
- Administrators should never use their privileged account for daily tasks like email and web browsing. Separate accounts plus MFA and logging is the expected best answer.
- SSO improves security by centralizing strong authentication, but it is also a single point of failure and a high-value target. Federation means trust between different organizations; the passwords stay with the home organization.
- CCTV is primarily detective and deterrent, not preventive. Human safety always comes first, so emergency exits must be fail-safe even if that weakens security.
- Access reviews are a detective control, and the business owner or manager should approve access, not the IT administrator who granted it.
Key terms
- Identification
- Claiming an identity, for example by entering a username.
- Subject
- An active entity, such as a user or process, that requests access to a resource.
- Object
- A passive resource, such as a file or database, that a subject wants to access.
- Accountability
- The ability to trace actions to a specific individual, supported by unique IDs and logging.
- Account lockout
- Temporarily disabling an account after repeated failed authentication attempts.
- Least privilege
- Granting only the minimum access needed to perform a job, for only as long as it is needed.
- Need to know
- Restricting access to specific information to people whose current task requires it.
- Separation of duties
- Dividing a sensitive task among multiple people so no one person can complete it alone.
- Collusion
- Two or more people cooperating to bypass controls such as separation of duties.
- Job rotation
- Periodically moving staff between roles to reduce fraud risk and spread knowledge.
- Provisioning
- Creating an identity and granting approved initial access.
- Deprovisioning
- Disabling or removing an identity's access when it is no longer needed.
- Privilege creep
- The gradual accumulation of unnecessary access rights as a person changes roles.
- Orphaned account
- An active account with no current owner, such as one left behind by a former employee.
- Joiner, mover, leaver
- A common name for the lifecycle process covering new hires, role changes and departures.
- Discretionary access control (DAC)
- A model in which the resource owner decides who may access it.
- Mandatory access control (MAC)
- A model in which the system enforces access by comparing subject clearances with object labels; owners cannot override it.
- Role-based access control (RBAC)
- A model that grants permissions to job roles and assigns users to those roles.
- Rule-based access control
- A model that applies administrator-defined rules to all subjects, such as firewall rules or time-of-day limits.
- Access control list (ACL)
- A list attached to an object that specifies which subjects have which permissions.
- Privileged account
- An account with elevated rights, such as administrator, root or a powerful service account.
- Privileged access management (PAM)
- Practices and tools for controlling, limiting and monitoring privileged accounts.
- Just-in-time access
- Granting elevated privileges only when needed for a specific task and removing them afterward.
- Password vault
- A secure system that stores, rotates and controls check-out of privileged credentials.
- Break-glass account
- A tightly controlled emergency account used only when normal access methods fail.
- Single sign-on (SSO)
- Authenticating once to gain access to multiple applications without logging in again.
- Identity provider (IdP)
- The trusted service that authenticates users and issues assertions or tokens about them.
- Federation
- A trust relationship that lets identities from one organization be used to access another's resources.
- SAML
- Security Assertion Markup Language, an XML-based standard for exchanging signed authentication assertions.
- OAuth
- An authorization framework that lets users grant applications limited access to their resources without sharing passwords.
- Tailgating
- An unauthorized person following an authorized person through a secured entrance without their knowledge.
- Piggybacking
- An unauthorized person entering with the knowledge or consent of an authorized person.
- Access control vestibule
- A two-door entry space that admits one authenticated person at a time; formerly called a mantrap.
- CCTV
- Closed-circuit television cameras used to deter, monitor and record activity.
- Fail-safe
- A design that defaults to an open or safe state for people when a failure occurs, such as exit doors unlocking during a fire.
- Access review
- A periodic check by owners or managers to confirm that users' access is still appropriate.
- Recertification
- Formally re-approving a user's existing access as part of a review.
- Dormant account
- An account that has not been used for an extended period.
- Rubber-stamping
- Approving access in a review without genuinely evaluating it.
- Entitlement
- A specific permission or access right granted to an identity.
Domain 4: Networking & cloud security concepts (22%)
Exam tips
- Know the port numbers cold: 22 SSH, 25 SMTP, 53 DNS, 80 HTTP, 443 HTTPS, 3389 RDP. Routers and IP addresses live at layer 3; switches and MAC addresses at layer 2.
- Match each threat to the CIA element it mainly hits: DoS and DDoS to availability, MITM to confidentiality and integrity, spoofing to authentication and integrity, side-channel to confidentiality.
- IDS detects and alerts (passive, out of band); IPS blocks (active, inline). Signature-based detection misses new attacks; anomaly-based produces more false positives.
- Public-facing servers belong in the DMZ, never on the internal network. Segmentation's main security value is limiting lateral movement.
- In zero trust, network location grants nothing. Being inside the corporate network does not make a request trusted; every request is verified.
- Order the models by customer responsibility: IaaS (most), PaaS (middle), SaaS (least). In every model, the customer is responsible for its data and access management.
- Community cloud is the model for several organizations with shared concerns; hybrid means combining different models. Private does not always mean on-premises; a third party can host a private cloud.
- Whatever the service model, the customer is always responsible for its data and for access management. The provider is always responsible for physical security of its data centers.
Key terms
- OSI model
- A seven-layer reference model describing network communication from physical signals to applications.
- TCP
- Transmission Control Protocol, a connection-oriented, reliable transport protocol that uses a three-way handshake.
- UDP
- User Datagram Protocol, a connectionless transport protocol that is fast but does not guarantee delivery.
- Port
- A number that identifies a specific service or application on a host.
- Private IP address
- An address from reserved ranges used inside networks and not routed on the public internet.
- NAT
- Network address translation, which maps private internal addresses to public addresses.
- DDoS
- Distributed denial of service: an attack from many sources that overwhelms a target to make it unavailable.
- Botnet
- A network of compromised devices controlled by an attacker, often used for DDoS or spam.
- On-path (man-in-the-middle) attack
- An attack in which the attacker secretly intercepts and possibly alters communication between two parties.
- Worm
- Malware that replicates and spreads across networks without user action.
- Spoofing
- Falsifying an identity such as an IP address, email sender or MAC address to gain trust.
- Side-channel attack
- An attack that infers secrets from physical characteristics like timing, power use or emissions.
- Stateful firewall
- A firewall that tracks connections and allows return traffic for established sessions.
- Implicit deny
- A default rule that blocks any traffic not explicitly allowed.
- IDS
- Intrusion detection system: monitors for suspicious activity and generates alerts.
- IPS
- Intrusion prevention system: sits inline and can automatically block malicious traffic.
- False negative
- A failure to detect actual malicious activity.
- VPN
- Virtual private network: an encrypted tunnel that protects data crossing an untrusted network.
- Segmentation
- Dividing a network into zones with controlled traffic between them to limit the spread of attacks.
- VLAN
- Virtual local area network: a logical network created on switches to separate traffic at layer 2.
- DMZ (screened subnet)
- A network zone between the internet and the internal network that hosts public-facing services.
- Micro-segmentation
- Fine-grained, often software-defined, isolation of individual workloads with their own access policies.
- Lateral movement
- An attacker moving from one compromised system to others within a network.
- Defense in depth
- Using multiple overlapping layers of security controls so one failure does not cause a breach.
- Zero trust
- A security model that grants no implicit trust based on network location and verifies every access request.
- Assume breach
- A zero trust principle of designing defenses as if attackers are already inside the environment.
- Device posture
- The security state of a device, such as patch level and endpoint protection, used in access decisions.
- Policy enforcement point
- The component that allows or blocks a connection based on a policy decision.
- ZTNA
- Zero trust network access: granting verified users on verified devices access to specific applications rather than the whole network.
- Rapid elasticity
- The ability to scale cloud resources out or in quickly, often automatically, to match demand.
- Measured service
- Metering of cloud resource usage so customers pay for what they consume.
- Multi-tenancy
- Serving multiple customers from shared infrastructure while keeping them logically isolated.
- IaaS
- Infrastructure as a Service: virtual servers, storage and networks where the customer manages the OS and above.
- PaaS
- Platform as a Service: a managed runtime or platform where the customer manages applications and data.
- SaaS
- Software as a Service: a complete application managed by the provider; the customer manages data and access.
- Public cloud
- Cloud infrastructure owned by a provider and shared by many customers over the internet.
- Private cloud
- Cloud infrastructure dedicated to a single organization, hosted on-premises or by a third party.
- Community cloud
- Cloud infrastructure shared by several organizations with common requirements or missions.
- Hybrid cloud
- A combination of two or more deployment models connected so data and applications can move between them.
- Multi-cloud
- Using services from more than one public cloud provider.
- Shared responsibility model
- The division of security duties between a cloud provider and its customer, which varies by service model.
- Security of the cloud
- The provider's responsibility for physical facilities, hardware and the virtualization layer.
- Security in the cloud
- The customer's responsibility for its data, identities, access and configurations.
- UPS
- Uninterruptible power supply: a battery-based device that keeps equipment running during short power interruptions.
- HVAC
- Heating, ventilation and air conditioning, which keeps data center temperature and humidity within safe ranges.
Domain 5: Security operations & incident response (17%)
Exam tips
- The data owner, not IT, decides classification. Deleting or formatting does not remove data; for SSDs, degaussing does not work, so use cryptographic erase or physical destruction.
- Encryption is two-way and protects confidentiality; hashing is one-way and protects integrity. To encrypt a message for Bob, use Bob's public key; to sign a message, use your own private key.
- Not every event is an incident. Triage decides which alerts are real and how urgent they are. Central, protected log collection with synchronized time is essential for investigation.
- Test patches before production and always have a rollback plan. Emergency changes skip some steps but must still be documented and reviewed after the fact.
- A vulnerability scan finds weaknesses; a penetration test exploits them to prove impact. Penetration tests always require written authorization and a defined scope.
- Know the order: preparation, detection and analysis, containment, eradication, recovery, lessons learned. Contain before you eradicate, and prefer isolating a system over powering it off to preserve evidence.
- RTO is how fast you must recover; RPO is how much data you can lose. A lower RPO requires more frequent backups or replication. Hot sites are fastest and most expensive; cold sites are slowest and cheapest.
- The AUP is typically signed before access is granted and warns that activity may be monitored. Modern password guidance favors length, breached-password checks and MFA over forced periodic changes.
Key terms
- Data classification
- Assigning data to sensitivity levels that determine how it must be protected.
- Labeling
- Marking data or media with its classification so it is handled correctly.
- Retention policy
- Rules stating how long each type of data must be kept and how it is disposed of.
- Data remanence
- Residual data that remains on media after deletion or formatting.
- Degaussing
- Erasing magnetic media with a strong magnetic field; ineffective on solid-state drives.
- Cryptographic erase
- Sanitizing encrypted media by securely destroying its encryption keys.
- Symmetric encryption
- Encryption that uses the same secret key to encrypt and decrypt; fast and used for bulk data.
- Asymmetric encryption
- Encryption using a public and private key pair; slower, used for key exchange and digital signatures.
- Hashing
- A one-way function producing a fixed-size digest used to verify integrity.
- Digital signature
- A hash of data encrypted with the signer's private key, proving origin and integrity.
- Salt
- A random value added to a password before hashing so identical passwords yield different hashes.
- PKI
- Public key infrastructure: the certificate authorities, certificates and processes that bind public keys to identities.
- Log
- A record of events generated by a system, application or device.
- SIEM
- Security information and event management: a system that collects, normalizes, correlates and alerts on log data.
- Correlation
- Linking related events from different sources to identify patterns that suggest an attack.
- Event triage
- Rapidly assessing alerts to determine their validity, severity and priority for response.
- Alert fatigue
- Desensitization caused by excessive alerts, leading analysts to miss real threats.
- NTP
- Network Time Protocol, used to synchronize clocks so logs from different systems line up.
- Hardening
- Reducing a system's attack surface by removing unneeded components and applying secure settings.
- Attack surface
- All the points where an attacker could attempt to enter or extract data from a system.
- Configuration drift
- Gradual, unapproved divergence of a system's settings from its approved baseline.
- Patch management
- The process of identifying, testing, deploying and verifying software updates.
- Change advisory board (CAB)
- A group that reviews and approves significant changes to IT systems.
- Rollback plan
- Steps to restore the previous state if a change fails.
- Vulnerability scan
- An automated check that identifies known weaknesses without exploiting them.
- Penetration test
- An authorized, scoped attempt to exploit vulnerabilities to demonstrate real risk.
- CVE
- Common Vulnerabilities and Exposures: unique public identifiers for known vulnerabilities.
- CVSS
- Common Vulnerability Scoring System: a 0 to 10 scale describing a vulnerability's severity.
- Credentialed scan
- A scan that logs in to systems to inspect them in detail, producing more accurate results.
- Rules of engagement
- The written scope, timing and limits that authorize and govern a security test.
- Incident response plan
- A documented approach defining roles, procedures and communication for handling security incidents.
- CSIRT
- Computer security incident response team: the group responsible for responding to incidents.
- Containment
- Actions that limit the spread and impact of an incident.
- Eradication
- Removing the root cause of an incident, such as malware or an exploited vulnerability.
- Chain of custody
- Documentation of who collected, handled and stored evidence, and when, to preserve its integrity.
- Tabletop exercise
- A discussion-based walkthrough of a simulated incident used to test plans and roles.
- Business impact analysis (BIA)
- An analysis identifying critical functions and the impact of their disruption over time.
- Recovery time objective (RTO)
- The target time within which a system must be restored after a disruption.
- Recovery point objective (RPO)
- The maximum acceptable data loss, measured as time since the last good copy.
- Incremental backup
- A backup of data changed since the last backup of any type.
- Differential backup
- A backup of all data changed since the last full backup.
- Hot site
- A fully equipped alternate site with current data that can take over almost immediately.
- Acceptable use policy (AUP)
- A policy defining permitted and prohibited uses of organizational systems and data.
- BYOD
- Bring your own device: allowing personally owned devices to access organizational resources under set rules.
- Mobile device management (MDM)
- Software that enforces security settings on mobile devices and can remotely lock or wipe them.
- Passphrase
- A long password made of several words, easier to remember and harder to guess than a short complex password.
- Privacy notice
- A public statement explaining how an organization collects, uses, shares and protects personal data.
Study CC for free
Lessons, quizzes, exam simulations and hands-on labs.
Open the CC study planLessons, quizzes, exam simulations and hands-on labs.